Problem with residual conduit message

Status
Not open for further replies.
I didn't get all of it before. My apologies. :)

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-07-2014
Ran by SueB at 2014-07-04 13:30:49 Run:2
Running from C:\Users\SueB\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
*****************

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}' => Key deleted successfully.
'HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}'=> Key not found.

==== End of Fixlog ====
 
Here is the fresh FRST scan done about about 4:30pm est

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-07-2014
Ran by SueB (administrator) on SUEB-PC on 04-07-2014 16:27:42
Running from C:\Users\SueB\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(24im LLC) C:\Program Files (x86)\24im\24im Messenger\IMC.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Windows\System32\GManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Google Inc.) C:\Users\SueB\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\SueB\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\SueB\AppData\Local\Google\Chrome\Application\chrome.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\swriter.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.bin


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3890208 2014-06-24] (AVAST Software)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-3890881620-3642371930-2457045338-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
HKU\S-1-5-21-3890881620-3642371930-2457045338-1001\...\Run: [InbitIMC] => C:\Program Files (x86)\24im\24im Messenger\IMC.EXE [3423744 2013-11-30] (24im LLC)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {F675470B-C135-4DA8-A601-8A3F063FA64F} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {FBF428CE-6C57-4765-978A-D21EB5B3017C} URL = https://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 65.32.5.111 65.32.5.112

FireFox:
========
FF ProfilePath: C:\Users\SueB\AppData\Roaming\Mozilla\Firefox\Profiles\7s6elucx.default
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Keyword.URL: https://www.google.com/search
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @java.com/DTPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Users\SueB\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\SueB\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\SueB\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\SueB\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Extension: IE Tab 2 (FF 3.6+) - C:\Users\SueB\AppData\Roaming\Mozilla\Firefox\Profiles\7s6elucx.default\Extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB} [2013-12-31]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-11-21]

Chrome:
=======
CHR HomePage:
CHR StartupUrls: "https://www.google.com/"
CHR Extension: (Google Drive) - C:\Users\SueB\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-24]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\SueB\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-23]
CHR Extension: (YouTube) - C:\Users\SueB\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-24]
CHR Extension: (Google Search) - C:\Users\SueB\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-24]
CHR Extension: (avast! Online Security) - C:\Users\SueB\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-24]
CHR Extension: (Google Wallet) - C:\Users\SueB\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-05]
CHR Extension: (Gmail) - C:\Users\SueB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-24]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-02] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109048 2014-05-02] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 GManager; C:\Windows\system32\GManager.exe [313432 2012-08-28] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [398184 2012-12-14] (Malwarebytes Corporation) [File not signed]
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [682344 2012-12-14] (Malwarebytes Corporation) [File not signed]
R2 MCTDesktopSvr; C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe [199296 2011-05-03] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-02] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-04-03] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-02] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [447888 2014-05-15] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-02] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-02] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-02] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [24176 2012-12-14] (Malwarebytes Corporation) [File not signed]
R3 mctkmd; C:\Windows\system32\drivers\mctkmd64.sys [145840 2012-12-25] (Magic Control Technology Corporation)
R0 mctkmdldr; C:\Windows\System32\drivers\mctkmdldr64.sys [19584 2011-04-08] (Magic Control Technology Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-01-20] ()
R3 t2usb64; C:\Windows\System32\drivers\t2usb64.sys [410592 2012-09-21] (Magic Control Technology Corp.)
S3 tapoas; C:\Windows\System32\DRIVERS\tapoas.sys [30720 2010-10-06] (The OpenVPN Project)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-04 16:27 - 2014-07-04 16:27 - 00017997 _____ () C:\Users\SueB\Desktop\FRST.txt
2014-07-04 13:50 - 2014-07-04 13:50 - 00000000 ____D () C:\Users\SueB\AppData\Local\Software
2014-07-04 09:00 - 2014-07-04 09:00 - 00000000 ____D () C:\Users\SueB\AppData\Local\Apps\2.0
2014-07-04 08:28 - 2014-07-04 08:28 - 00000056 _____ () C:\Windows\setupact.log
2014-07-04 08:28 - 2014-07-04 08:28 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-04 02:09 - 2014-07-04 13:58 - 00000000 ___RD () C:\Users\SueB\Desktop\BUSINESS
2014-07-03 22:51 - 2014-07-03 22:51 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-03 18:36 - 2014-07-04 10:41 - 00000000 ___RD () C:\Users\SueB\Desktop\ENTERTAINMENT
2014-07-03 18:35 - 2014-07-04 10:38 - 00000000 ___RD () C:\Users\SueB\Desktop\OFFICE SOFTWARE
2014-07-03 18:33 - 2014-07-04 16:22 - 00000000 ___RD () C:\Users\SueB\Desktop\MY SECURITY SOFTWARE
2014-07-03 18:30 - 2014-07-04 16:27 - 00000000 ___RD () C:\Users\SueB\Desktop\SPECIAL SECURITY
2014-07-03 08:50 - 2014-07-03 08:50 - 00000000 ____D () C:\Windows\ERUNT
2014-07-03 08:27 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-03 08:26 - 2014-07-03 08:28 - 00000000 ____D () C:\AdwCleaner
2014-07-02 20:34 - 2014-07-02 20:34 - 14196266 _____ () C:\Users\SueB\Downloads\mbar-1.07.0.1012.zip
2014-07-02 20:31 - 2014-07-02 20:31 - 14349744 _____ (Malwarebytes Corp.) C:\Users\SueB\Downloads\mbar-1.07.0.1012.exe
2014-07-02 19:45 - 2014-07-02 20:49 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-07-02 19:44 - 2014-07-02 19:44 - 00000000 ____D () C:\Users\SueB\Downloads\mbar-1.07.0.1012 (1)
2014-07-02 19:35 - 2014-07-02 20:39 - 00000000 ____D () C:\Users\SueB\Downloads\mbar-1.07.0.1012
2014-07-02 19:29 - 2014-07-02 20:41 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-02 08:44 - 2014-07-02 08:45 - 00041611 _____ () C:\Users\SueB\Downloads\Addition.txt
2014-07-02 08:43 - 2014-07-04 16:27 - 00000000 ____D () C:\FRST
2014-07-02 08:43 - 2014-07-02 21:00 - 00002950 _____ () C:\Users\SueB\Downloads\FRST.txt
2014-07-02 08:41 - 2014-07-02 08:41 - 02083840 _____ (Farbar) C:\Users\SueB\Desktop\FRST64.exe
2014-07-02 08:27 - 2014-07-02 08:27 - 00000565 _____ () C:\Users\SueB\Documents\MBR.zip
2014-07-02 08:26 - 2014-07-02 08:24 - 00000512 _____ () C:\Users\SueB\Documents\MBR.dat
2014-07-02 08:14 - 2014-07-04 01:38 - 00000000 ____D () C:\Windows\Minidump
2014-07-02 07:56 - 2014-07-02 07:56 - 00854390 _____ () C:\Users\SueB\Downloads\SecurityCheck (2).exe
2014-07-02 07:55 - 2014-07-02 07:56 - 05185536 _____ (AVAST Software) C:\Users\SueB\Downloads\aswMBR.exe
2014-07-02 07:54 - 2014-07-02 07:55 - 00854390 _____ () C:\Users\SueB\Downloads\SecurityCheck (1).exe
2014-07-02 07:46 - 2014-07-02 07:46 - 00854390 _____ () C:\Users\SueB\Downloads\SecurityCheck.exe
2014-07-01 01:33 - 2014-07-01 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-01 01:33 - 2014-07-01 01:33 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-01 01:33 - 2014-07-01 01:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-01 01:32 - 2014-07-01 01:33 - 13084896 _____ (Microsoft Corporation) C:\Users\SueB\Downloads\Silverlight_x64.exe
2014-07-01 00:00 - 2014-07-01 00:00 - 00000600 _____ () C:\Users\SueB\AppData\Roaming\winscp.rnd
2014-07-01 00:00 - 2014-07-01 00:00 - 00000000 ____D () C:\CSV
2014-06-30 23:42 - 2014-06-30 23:42 - 00000000 ____D () C:\Diag-Advisor
2014-06-30 11:35 - 2014-06-30 11:35 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-06-30 11:35 - 2014-06-30 11:35 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-06-30 11:35 - 2014-06-30 11:35 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-06-30 11:35 - 2014-06-30 11:35 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-06-30 11:34 - 2014-06-30 11:34 - 30984104 _____ (Oracle Corporation) C:\Users\SueB\Downloads\jre-7u60-windows-x64 (1).exe
2014-06-30 11:29 - 2014-06-30 11:29 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-06-30 11:29 - 2014-06-30 11:29 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-06-30 11:29 - 2014-06-30 11:29 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-06-30 11:29 - 2014-06-30 11:29 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-06-30 11:29 - 2014-06-30 11:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-30 11:28 - 2014-06-30 11:28 - 00918952 _____ (Oracle Corporation) C:\Users\SueB\Downloads\JavaSetup7u60 (2).exe
2014-06-30 08:34 - 2014-06-30 21:40 - 00000000 __SHD () C:\Jumpshot
2014-06-30 08:31 - 2014-07-01 01:42 - 00000000 ____D () C:\Windows\jumpshot.com
2014-06-28 18:04 - 2014-06-28 18:04 - 30984104 _____ (Oracle Corporation) C:\Users\SueB\Downloads\jre-7u60-windows-x64.exe
2014-06-26 21:10 - 2014-06-08 05:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-26 21:10 - 2014-06-08 05:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-24 07:32 - 2014-06-24 07:32 - 00123910 _____ () C:\Users\SueB\Documents\Current Schedules.odt
2014-06-20 22:26 - 2014-06-20 22:26 - 00918952 _____ (Oracle Corporation) C:\Users\SueB\Downloads\JavaSetup7u60 (1).exe
2014-06-20 21:17 - 2014-06-20 21:17 - 31112616 _____ (Oracle Corporation) C:\Users\SueB\Downloads\jre-8u5-windows-i586.exe
2014-06-20 21:14 - 2014-06-20 21:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-20 21:13 - 2014-06-20 21:14 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-20 21:13 - 2014-06-20 21:14 - 00000000 ____D () C:\Program Files\iTunes
2014-06-20 21:13 - 2014-06-20 21:14 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-20 21:13 - 2014-06-20 21:13 - 00000000 ____D () C:\Program Files\iPod
2014-06-20 21:10 - 2014-06-20 21:10 - 00000000 ____D () C:\Program Files\Bonjour
2014-06-20 21:10 - 2014-06-20 21:10 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-06-20 20:58 - 2014-06-30 11:35 - 00000000 ____D () C:\Program Files\Java
2014-06-20 20:57 - 2014-06-20 20:58 - 34131368 _____ (Oracle Corporation) C:\Users\SueB\Downloads\jre-8u5-windows-x64.exe
2014-06-20 20:47 - 2014-06-20 20:47 - 00918952 _____ (Oracle Corporation) C:\Users\SueB\Downloads\JavaSetup7u60.exe
2014-06-12 10:09 - 2014-06-12 10:09 - 00011287 _____ () C:\Users\SueB\Documents\shifts off.odt
2014-06-12 07:45 - 2014-06-12 10:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-06-11 06:09 - 2014-05-23 22:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-11 06:09 - 2014-05-23 22:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 06:09 - 2014-05-23 22:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 06:09 - 2014-05-23 22:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-11 06:09 - 2014-05-23 22:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 06:09 - 2014-05-23 22:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 06:09 - 2014-05-23 22:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 06:09 - 2014-05-23 21:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-11 06:09 - 2014-05-23 21:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-11 06:09 - 2014-05-23 21:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-11 06:09 - 2014-05-23 21:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-11 06:09 - 2014-05-23 21:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-11 06:09 - 2014-05-23 21:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-11 06:09 - 2014-05-23 21:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-11 06:09 - 2014-05-23 21:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-11 06:09 - 2014-05-23 21:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 06:09 - 2014-05-23 21:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-11 06:09 - 2014-05-23 20:13 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-06-11 06:09 - 2014-05-23 20:06 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-06-11 06:09 - 2014-05-08 05:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-11 06:09 - 2014-05-08 05:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-11 06:09 - 2014-04-24 22:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 06:09 - 2014-04-24 22:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 06:09 - 2014-04-04 22:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 06:09 - 2014-04-04 22:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 06:09 - 2014-03-26 10:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 06:09 - 2014-03-26 10:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 06:09 - 2014-03-26 10:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 06:09 - 2014-03-26 10:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-11 06:09 - 2014-03-26 10:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 06:09 - 2014-03-26 10:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 06:09 - 2014-03-26 10:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 06:09 - 2014-03-26 10:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-05 16:41 - 2014-06-05 16:41 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-06-05 10:21 - 2014-06-05 10:23 - 140910890 _____ () C:\Users\SueB\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_en-US.exe
2014-06-04 22:59 - 2014-06-04 22:59 - 00012442 _____ () C:\Users\SueB\Downloads\apa6th_template.zip
2014-06-04 22:46 - 2014-06-04 22:46 - 00010298 _____ () C:\Users\SueB\Downloads\mla_with_second_page_header.zip
2014-06-04 06:20 - 2014-06-04 06:20 - 00013139 _____ () C:\Users\SueB\Documents\June 03 2014 goof card.odt

==================== One Month Modified Files and Folders =======

2014-07-04 16:27 - 2014-07-04 16:27 - 00017997 _____ () C:\Users\SueB\Desktop\FRST.txt
2014-07-04 16:27 - 2014-07-03 18:30 - 00000000 ___RD () C:\Users\SueB\Desktop\SPECIAL SECURITY
2014-07-04 16:27 - 2014-07-02 08:43 - 00000000 ____D () C:\FRST
2014-07-04 16:27 - 2014-02-27 22:00 - 00000536 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3890881620-3642371930-2457045338-1001.job
2014-07-04 16:22 - 2014-07-03 18:33 - 00000000 ___RD () C:\Users\SueB\Desktop\MY SECURITY SOFTWARE
2014-07-04 16:10 - 2013-11-24 14:54 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-04 16:10 - 2012-11-23 04:03 - 00000000 ____D () C:\Users\SueB\AppData\Roaming\Skype
2014-07-04 15:52 - 2013-12-02 17:17 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-04 15:33 - 2013-09-05 20:49 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3890881620-3642371930-2457045338-1001UA.job
2014-07-04 13:58 - 2014-07-04 02:09 - 00000000 ___RD () C:\Users\SueB\Desktop\BUSINESS
2014-07-04 13:50 - 2014-07-04 13:50 - 00000000 ____D () C:\Users\SueB\AppData\Local\Software
2014-07-04 10:50 - 2014-02-19 09:57 - 01547281 _____ () C:\Windows\WindowsUpdate.log
2014-07-04 10:41 - 2014-07-03 18:36 - 00000000 ___RD () C:\Users\SueB\Desktop\ENTERTAINMENT
2014-07-04 10:38 - 2014-07-03 18:35 - 00000000 ___RD () C:\Users\SueB\Desktop\OFFICE SOFTWARE
2014-07-04 09:00 - 2014-07-04 09:00 - 00000000 ____D () C:\Users\SueB\AppData\Local\Apps\2.0
2014-07-04 08:35 - 2009-07-14 00:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-04 08:35 - 2009-07-14 00:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-04 08:33 - 2009-07-14 01:13 - 00783400 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-04 08:28 - 2014-07-04 08:28 - 00000056 _____ () C:\Windows\setupact.log
2014-07-04 08:28 - 2014-07-04 08:28 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-04 08:28 - 2013-12-02 17:17 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-04 08:28 - 2013-08-30 20:14 - 00002812 _____ () C:\Windows\system32\GManager.ini
2014-07-04 08:28 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-04 02:14 - 2012-12-09 14:16 - 00000000 ____D () C:\Users\SueB\Documents\Youcam
2014-07-04 01:38 - 2014-07-02 08:14 - 00000000 ____D () C:\Windows\Minidump
2014-07-03 22:51 - 2014-07-03 22:51 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-03 18:33 - 2013-09-05 20:49 - 00000852 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3890881620-3642371930-2457045338-1001Core.job
2014-07-03 08:50 - 2014-07-03 08:50 - 00000000 ____D () C:\Windows\ERUNT
2014-07-03 08:28 - 2014-07-03 08:26 - 00000000 ____D () C:\AdwCleaner
2014-07-03 08:28 - 2012-11-21 17:54 - 00000000 ____D () C:\Users\SueB
2014-07-02 21:00 - 2014-07-02 08:43 - 00002950 _____ () C:\Users\SueB\Downloads\FRST.txt
2014-07-02 20:49 - 2014-07-02 19:45 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-07-02 20:41 - 2014-07-02 19:29 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-02 20:39 - 2014-07-02 19:35 - 00000000 ____D () C:\Users\SueB\Downloads\mbar-1.07.0.1012
2014-07-02 20:34 - 2014-07-02 20:34 - 14196266 _____ () C:\Users\SueB\Downloads\mbar-1.07.0.1012.zip
2014-07-02 20:31 - 2014-07-02 20:31 - 14349744 _____ (Malwarebytes Corp.) C:\Users\SueB\Downloads\mbar-1.07.0.1012.exe
2014-07-02 19:44 - 2014-07-02 19:44 - 00000000 ____D () C:\Users\SueB\Downloads\mbar-1.07.0.1012 (1)
2014-07-02 08:45 - 2014-07-02 08:44 - 00041611 _____ () C:\Users\SueB\Downloads\Addition.txt
2014-07-02 08:41 - 2014-07-02 08:41 - 02083840 _____ (Farbar) C:\Users\SueB\Desktop\FRST64.exe
2014-07-02 08:27 - 2014-07-02 08:27 - 00000565 _____ () C:\Users\SueB\Documents\MBR.zip
2014-07-02 08:24 - 2014-07-02 08:26 - 00000512 _____ () C:\Users\SueB\Documents\MBR.dat
2014-07-02 07:56 - 2014-07-02 07:56 - 00854390 _____ () C:\Users\SueB\Downloads\SecurityCheck (2).exe
2014-07-02 07:56 - 2014-07-02 07:55 - 05185536 _____ (AVAST Software) C:\Users\SueB\Downloads\aswMBR.exe
2014-07-02 07:55 - 2014-07-02 07:54 - 00854390 _____ () C:\Users\SueB\Downloads\SecurityCheck (1).exe
2014-07-02 07:46 - 2014-07-02 07:46 - 00854390 _____ () C:\Users\SueB\Downloads\SecurityCheck.exe
2014-07-01 22:51 - 2012-11-21 19:36 - 00000000 ____D () C:\Users\SueB\AppData\Roaming\SoftGrid Client
2014-07-01 14:25 - 2014-02-27 22:00 - 00003562 _____ () C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-3890881620-3642371930-2457045338-1001
2014-07-01 01:42 - 2014-06-30 08:31 - 00000000 ____D () C:\Windows\jumpshot.com
2014-07-01 01:42 - 2012-04-12 23:09 - 00000000 ____D () C:\Windows\System32\Tasks\Recovery Management
2014-07-01 01:36 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-01 01:33 - 2014-07-01 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-01 01:33 - 2014-07-01 01:33 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-01 01:33 - 2014-07-01 01:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-01 01:33 - 2014-07-01 01:32 - 13084896 _____ (Microsoft Corporation) C:\Users\SueB\Downloads\Silverlight_x64.exe
2014-07-01 00:00 - 2014-07-01 00:00 - 00000600 _____ () C:\Users\SueB\AppData\Roaming\winscp.rnd
2014-07-01 00:00 - 2014-07-01 00:00 - 00000000 ____D () C:\CSV
2014-06-30 23:42 - 2014-06-30 23:42 - 00000000 ____D () C:\Diag-Advisor
2014-06-30 23:24 - 2013-01-05 22:08 - 00000000 ____D () C:\Users\SueB\Downloads\D2000AZNEWGB_Training(1)
2014-06-30 21:40 - 2014-06-30 08:34 - 00000000 __SHD () C:\Jumpshot
2014-06-30 14:14 - 2013-05-21 09:04 - 00003918 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{B4B6C508-3456-47A0-9DC4-7C361428BA62}
2014-06-30 12:51 - 2014-04-08 17:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-30 11:35 - 2014-06-30 11:35 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-06-30 11:35 - 2014-06-30 11:35 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-06-30 11:35 - 2014-06-30 11:35 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-06-30 11:35 - 2014-06-30 11:35 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-06-30 11:35 - 2014-06-20 20:58 - 00000000 ____D () C:\Program Files\Java
2014-06-30 11:34 - 2014-06-30 11:34 - 30984104 _____ (Oracle Corporation) C:\Users\SueB\Downloads\jre-7u60-windows-x64 (1).exe
2014-06-30 11:30 - 2013-10-17 00:21 - 00000000 ____D () C:\ProgramData\Oracle
2014-06-30 11:29 - 2014-06-30 11:29 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-06-30 11:29 - 2014-06-30 11:29 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-06-30 11:29 - 2014-06-30 11:29 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-06-30 11:29 - 2014-06-30 11:29 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-06-30 11:29 - 2014-06-30 11:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-30 11:29 - 2012-11-27 18:28 - 00000000 ____D () C:\Program Files (x86)\Java
2014-06-30 11:28 - 2014-06-30 11:28 - 00918952 _____ (Oracle Corporation) C:\Users\SueB\Downloads\JavaSetup7u60 (2).exe
2014-06-30 09:22 - 2012-11-21 18:13 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-30 08:34 - 2012-11-21 17:55 - 07864320 ___SH () C:\Users\SueB\.ghost-ntfs-3g-00000000000000000009
2014-06-30 08:34 - 2009-07-13 22:34 - 77332480 _____ () C:\Windows\system32\config\.ghost-ntfs-3g-00000000000000000001
2014-06-30 08:34 - 2009-07-13 22:34 - 22806528 _____ () C:\Windows\system32\config\.ghost-ntfs-3g-00000000000000000003
2014-06-28 18:04 - 2014-06-28 18:04 - 30984104 _____ (Oracle Corporation) C:\Users\SueB\Downloads\jre-7u60-windows-x64.exe
2014-06-26 21:10 - 2014-04-30 23:31 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-24 07:32 - 2014-06-24 07:32 - 00123910 _____ () C:\Users\SueB\Documents\Current Schedules.odt
2014-06-22 20:32 - 2012-11-21 17:55 - 00064416 _____ () C:\Users\SueB\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-21 03:47 - 2013-12-02 17:17 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-21 03:47 - 2013-12-02 17:17 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-20 22:26 - 2014-06-20 22:26 - 00918952 _____ (Oracle Corporation) C:\Users\SueB\Downloads\JavaSetup7u60 (1).exe
2014-06-20 21:17 - 2014-06-20 21:17 - 31112616 _____ (Oracle Corporation) C:\Users\SueB\Downloads\jre-8u5-windows-i586.exe
2014-06-20 21:14 - 2014-06-20 21:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-20 21:14 - 2014-06-20 21:13 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-20 21:14 - 2014-06-20 21:13 - 00000000 ____D () C:\Program Files\iTunes
2014-06-20 21:14 - 2014-06-20 21:13 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-20 21:13 - 2014-06-20 21:13 - 00000000 ____D () C:\Program Files\iPod
2014-06-20 21:10 - 2014-06-20 21:10 - 00000000 ____D () C:\Program Files\Bonjour
2014-06-20 21:10 - 2014-06-20 21:10 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-06-20 21:09 - 2012-12-06 08:04 - 00000000 ____D () C:\ProgramData\Apple
2014-06-20 21:07 - 2013-11-24 14:54 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-20 21:07 - 2013-11-24 14:54 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-20 21:07 - 2013-11-24 14:54 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-20 20:58 - 2014-06-20 20:57 - 34131368 _____ (Oracle Corporation) C:\Users\SueB\Downloads\jre-8u5-windows-x64.exe
2014-06-20 20:47 - 2014-06-20 20:47 - 00918952 _____ (Oracle Corporation) C:\Users\SueB\Downloads\JavaSetup7u60.exe
2014-06-20 20:45 - 2014-05-17 21:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-20 20:39 - 2014-04-06 23:12 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-19 07:51 - 2013-12-02 17:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-06-18 19:26 - 2014-03-15 17:24 - 00000000 ____D () C:\ProgramData\webex
2014-06-16 18:28 - 2013-09-05 20:49 - 00003876 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3890881620-3642371930-2457045338-1001UA
2014-06-16 18:28 - 2013-09-05 20:49 - 00003480 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3890881620-3642371930-2457045338-1001Core
2014-06-13 07:02 - 2012-11-21 18:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-12 10:09 - 2014-06-12 10:09 - 00011287 _____ () C:\Users\SueB\Documents\shifts off.odt
2014-06-12 10:07 - 2014-06-12 07:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-06-12 08:42 - 2007-07-11 21:49 - 00000000 ____D () C:\Windows\Panther
2014-06-11 10:03 - 2013-08-15 00:22 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 10:01 - 2012-11-23 13:34 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-08 05:13 - 2014-06-26 21:10 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 05:08 - 2014-06-26 21:10 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-07 08:12 - 2012-11-21 18:55 - 00001143 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-07 08:12 - 2012-11-21 17:57 - 00001409 _____ () C:\Users\SueB\Desktop\Internet Explorer.lnk
2014-06-06 02:52 - 2009-07-14 00:45 - 00295288 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-05 16:41 - 2014-06-05 16:41 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-06-05 16:41 - 2013-08-04 13:41 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-06-05 10:23 - 2014-06-05 10:21 - 140910890 _____ () C:\Users\SueB\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_en-US.exe
2014-06-04 22:59 - 2014-06-04 22:59 - 00012442 _____ () C:\Users\SueB\Downloads\apa6th_template.zip
2014-06-04 22:46 - 2014-06-04 22:46 - 00010298 _____ () C:\Users\SueB\Downloads\mla_with_second_page_header.zip
2014-06-04 06:20 - 2014-06-04 06:20 - 00013139 _____ () C:\Users\SueB\Documents\June 03 2014 goof card.odt

Some content of TEMP:
====================
C:\Users\SueB\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-28 08:14

==================== End Of Log ============================
 
You must have been replying while I took a second scan. Everything seems to be running smoothly now. :)

Thank you ever so much. :2thumb:
 
Hi Suemarie,

Your log appears to be clean. :bigthumb:
We have a few items to take care of before we get to the All Clean Speech.

= = = = = = = = = = = = = = = = = = = =

Remove Disinfection Tools

  • Download Delfix
  • Tick the following boxes:
    • Remove disinfection tools
    • Create registry backup
    • Purge system restore



  • Click Run
  • Any other tools and files found can simply be deleted or uninstall via the Control Panel.
= = = = = = = = = = = = = = = = = = = =


With the above items taken care of let's move on to the All Clean part of the process.

The following procedures are recommendations for helping to keep your system running smoothly. If you are currently satisfied with how your system is running some or all of these may not pertain to you. Implement what you need.

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:
Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

Free Anti-Virus
Free Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here.
= = = = = = = = = = = = = = = = = = = =

Be prepared for CryptoLocker:

Cryptolocker Ransomware: What You Need To Know
CryptoLocker Ransomware Information Guide and FAQ

to help protect your computer in the future I recommend that you get the following free program:

CryptoPrevent install this program to lock down and prevent crypto-ransomeware



= = = = = = = = = = = = = = = = = = = =

COMPUTER SECURITY - a short guide to staying safer online

= = = = = = = = = = = = = = = = = = = =

WOT Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites - green to go, yellow for caution and red to stop, helping you avoid the dangerous sites. WOT has an addon available for both Firefox and IE.
  • Green should be good to go
  • Yellow for caution
  • Red to stop
= = = = = = = = = = = = = = = = = = = =

P2P may be a great way to get lots of stuffs, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well.

Please read these short reports on the dangers of peer-2-peer programs and file sharing.

= = = = = = = = = = = = = = = = = = = =

Make sure you keep your Windows OS current.
  • Windows XP:
    Microsoft will no longer offer support for Windows XP beginning on April 8, 2014
    If you are running Windows XP, please take the time to read the information provided at these links.
  • Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems.
  • Window 8 Open Windows Update by swiping in from the right edge of the screen (or, if you're using a mouse, pointing to the lower-right corner of the screen and moving the mouse pointer up), tapping or clicking Settings, tapping or clicking Change PC settings, and then tapping or clicking Update and recovery.
Without these you are leaving the back door open.

= = = = = = = = = = = = = = = = = = = =

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

= = = = = = = = = = = = = = = = = = = =

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
 
# DelFix v10.7 - Logfile created 04/07/2014 at 16:53:36
# Updated 27/04/2014 by Xplode
# Username : SueB - SUEB-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\SueB\Downloads\Addition.txt
Deleted : C:\Users\SueB\Downloads\aswMBR.exe
Deleted : C:\Users\SueB\Downloads\FRST.txt
Deleted : C:\Users\SueB\Downloads\SecurityCheck (1).exe
Deleted : C:\Users\SueB\Downloads\SecurityCheck (2).exe
Deleted : C:\Users\SueB\Downloads\SecurityCheck.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #345 [Windows Update | 06/27/2014 01:10:12]
Deleted : RP #346 [Removed Java 8 Update 5 (64-bit) | 06/28/2014 21:58:52]
Deleted : RP #347 [Installed Java 7 Update 60 (64-bit) | 06/28/2014 22:04:23]
Deleted : RP #348 [Windows Backup | 06/29/2014 23:00:08]
Deleted : RP #349 [Removed Java 7 Update 60 | 06/30/2014 15:11:11]
Deleted : RP #350 [Removed Java 7 Update 60 (64-bit) | 06/30/2014 15:12:01]
Deleted : RP #351 [Installed Java 7 Update 60 | 06/30/2014 15:29:01]
Deleted : RP #352 [Installed Java 7 Update 60 (64-bit) | 06/30/2014 15:34:55]
Deleted : RP #353 [Removed Microsoft Silverlight | 07/01/2014 05:30:35]
Deleted : RP #354 [Removed Microsoft Silverlight | 07/01/2014 05:31:03]
Deleted : RP #355 [Restore Operation | 07/01/2014 05:37:51]
Deleted : RP #349 [Windows Update | 07/01/2014 06:10:25]
Deleted : RP #350 [Windows Update | 07/04/2014 14:49:53]

New restore point created !

########## - EOF - ##########



Please tell me that this did not remove my Silverlight. I need that for Netflix.
 
OK. It's ok. Netflix works. :)

I will have to check about the NoScript and the AdBlockPlus. I am not supposed to have pop up blockers when I am working. I work for two companies, LiveOps and ACD direct. Both have special software that allows calls to be routed to my phone and the scripts to my computer.

I will read the articles. They look like they have some great advice.

Thank you once again,
Sue
 
I will have to check about the NoScript and the AdBlockPlus. I am not supposed to have pop up blockers when I am working. I work for two companies, LiveOps and ACD direct. Both have special software that allows calls to be routed to my phone and the scripts to my computer.
As stated previously:
The following procedures are recommendations for helping to keep your system running smoothly. If you are currently satisfied with how your system is running some or all of these may not pertain to you. Implement what you need.
 
Hi Suemarie,

You're very welcome. Glad I was able to help. :bigthumb: Have a great day.

Since this issue appears to be resolved ... this Topic will be closed.
 
Status
Not open for further replies.
Back
Top