Problem Chrome selaimeen hyppii spämmejä HTJ ja OTL logi mukana

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by VisitorQ, Mar 31, 2015.

  1. VisitorQ

    VisitorQ Member

    Joined:
    Mar 31, 2015
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    6
    Toivottavasti saisin apua, kun selaimeen hyppii spämmi sivuja koko ajan. Kaikki mahdolliset cleanerit on koitettu:

    Alla Hijack logi

    Logfile of Trend[​IMG] Micro HijackThis v2.0.4
    Scan saved at 20:57:55, on 31.3.2015
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v11.0 (11.00.9600.17689)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Microsoft Office[​IMG]\Office12\GrooveMonitor.exe
    C:\Program Files\Microsoft Security Client\msseces.exe
    C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
    C:\Windows\explorer.exe
    C:\Program Files\Google\Chrome\Application[​IMG]\chrome.exe
    C:\Program Files\Google\Chrome\Application[​IMG]\chrome.exe
    C:\Program Files\Google\Chrome\Application[​IMG]\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Windows\notepad.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Trend[​IMG] Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows[​IMG]\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program[​IMG] Files[​IMG]\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program[​IMG] Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
    O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office[​IMG]\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security[​IMG] Client\msseces.exe" -hide -runkey
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    O23 - Service: Bonjour-palvelu (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Päivitä-palvelu (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Päivitä-palvelu (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
    O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
    O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
    O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

    --
    End of file[​IMG] - 5764 bytes
     
  2. VisitorQ

    VisitorQ Member

    Joined:
    Mar 31, 2015
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    6
    OTL logfile created on: 31.3.2015 21:12:01 - Run 2
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Olohuone\Desktop
    Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.11.9600.17691)
    Locale: 0000040b | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

    3,24 Gb Total Physical Memory | 1,97 Gb Available Physical Memory | 60,73% Memory free
    6,48 Gb Paging File | 5,04 Gb Available in Paging File | 77,79% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 232,73 Gb Total Space | 156,50 Gb Free Space | 67,25% Space Free | Partition Type: NTFS

    Computer Name: OLOHUONE-745 | User Name: Olohuone | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2015.03.31 20:48:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Olohuone\Desktop\OTL.exe
    PRC - [2015.03.14 13:12:39 | 000,809,288 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
    PRC - [2015.01.30 02:59:44 | 000,284,472 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\NisSrv.exe
    PRC - [2015.01.30 02:59:44 | 000,022,184 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
    PRC - [2015.01.30 02:53:04 | 000,978,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
    PRC - [2014.09.12 12:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2014.06.27 11:52:26 | 002,088,408 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
    PRC - [2014.06.24 10:42:12 | 004,101,576 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
    PRC - [2014.06.24 10:41:42 | 001,738,168 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
    PRC - [2014.04.25 14:12:20 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
    PRC - [2012.11.23 05:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
    PRC - [2010.11.21 00:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe


    ========== Modules (No Company Name) ==========

    MOD - [2015.03.14 13:12:37 | 014,974,280 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\41.0.2272.101\PepperFlash\pepflashplayer.dll
    MOD - [2015.03.14 13:12:35 | 009,278,792 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\41.0.2272.101\pdf.dll
    MOD - [2014.05.13 12:04:48 | 000,167,768 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    MOD - [2014.05.13 12:04:46 | 000,109,400 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    MOD - [2014.05.13 12:04:42 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
    MOD - [2014.02.10 13:44:24 | 004,592,128 | ---- | M] () -- C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libGLESv2.dll
    MOD - [2014.02.10 13:44:24 | 000,112,128 | ---- | M] () -- C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libEGL.dll


    ========== Services (SafeList) ==========

    SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService)
    SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService)
    SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService)
    SRV - [2015.02.20 04:56:53 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
    SRV - [2015.02.05 21:01:10 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2015.01.30 02:59:44 | 000,284,472 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
    SRV - [2015.01.30 02:59:44 | 000,022,184 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
    SRV - [2014.09.12 12:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2013.05.27 07:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV - [2010.02.19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
    SRV - [2009.07.14 04:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
    SRV - [2009.07.14 04:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
    SRV - [2009.07.14 04:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\taphss6.sys -- (taphss6)
    DRV - [2014.11.15 15:46:08 | 000,095,408 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
    DRV - [2010.11.21 00:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV - [2010.11.21 00:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
    DRV - [2010.11.21 00:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
    DRV - [2010.11.21 00:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
    DRV - [2010.11.21 00:29:03 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
    DRV - [2010.11.21 00:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
    DRV - [2010.11.21 00:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows[​IMG]\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
    DRV - [2010.11.21 00:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
    DRV - [2010.11.21 00:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
    DRV - [2010.11.09 15:35:30 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\cpuz135_x32.sys -- (cpuz135)
    DRV - [2007.11.22 12:06:08 | 000,893,440 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athrusb.sys -- (athrusb)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www[​IMG].bing.com/search?q={searchTerms}&FORM=IE8SRC

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start[​IMG] Page = http://www.google.com
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start[​IMG] Page Redirect Cache = http://fi.msn.com/?ocid=iehp
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start[​IMG] Page Redirect Cache AcceptLangs = fi-FI
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B4 94 79 4E 2C 42 CD 01 [binary[​IMG] data]
    IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
     
  3. VisitorQ

    VisitorQ Member

    Joined:
    Mar 31, 2015
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    6
    FF - prefs.js..network.proxy.no_proxies_on: ""
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.31.2: C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2: C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 36.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.06.14 14:46:21 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 36.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

    [2013.04.06 11:45:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Olohuone\AppData\Roaming\Mozilla\Extensions
    [2015.03.31 20:38:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Olohuone\AppData\Roaming\Mozilla\Firefox\Profiles\p4ddnnv2.default\extensions
    [2015.03.06 18:31:32 | 000,000,000 | ---D | M] (YouTube Unblocker) -- C:\Users\Olohuone\AppData\Roaming\Mozilla\Firefox\Profiles\p4ddnnv2.default\extensions\youtubeunblocker@unblocker.yt
    [2015.03.06 18:53:15 | 000,105,346 | ---- | M] () (No name found) -- C:\Users\Olohuone\AppData\Roaming\Mozilla\Firefox\Profiles\p4ddnnv2.default\extensions\ich@maltegoetz.de.xpi
    [2015.03.22 21:50:26 | 000,067,642 | ---- | M] () (No name found) -- C:\Users\Olohuone\AppData\Roaming\Mozilla\Firefox\Profiles\p4ddnnv2.default\extensions\{e48ea998-df28-46fa-81b7-9621784a3d44}.xpi
    [2015.03.13 10:39:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
    [2015.03.06 18:28:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

    ========== Chrome ==========

    CHR - plugin: Error reading preferences file
    CHR - Extension: No name found = C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
    CHR - Extension: No name found = C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
    CHR - Extension: No name found = C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\
    CHR - Extension: No name found = C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
    CHR - Extension: No name found = C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
    CHR - Extension: No name found = C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
    CHR - Extension: No name found = C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\
    CHR - Extension: No name found = C:\Users\Olohuone\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\

    O1 HOSTS File: ([2011.11.18 23:55:22 | 000,000,854 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 activate.adobe.com
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
    O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
    O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
    O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
    O4 - HKCU..\Run: [AdobeBridge] File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O13 - gopher Prefix: missing
    O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab (SysInfo Class)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{99A4B894-476A-4782-8209-D4ACFB98E862}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B9906E84-1E75-40E6-975A-7267E61DA27C}: DhcpNameServer = 10.0.0.2
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009.06.11 00:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O33 - MountPoints2\{9f852784-0173-11e1-bbbc-001aa05e61f1}\Shell - "" = AutoRun
    O33 - MountPoints2\{9f852784-0173-11e1-bbbc-001aa05e61f1}\Shell\AutoRun\command - "" = E:\application\Setup.exe
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2015.03.31 20:48:23 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Olohuone\Desktop\OTL.exe
    [2015.03.31 20:36:59 | 000,000,000 | ---D | C] -- C:\AdwCleaner
    [2015.03.31 20:32:56 | 000,000,000 | ---D | C] -- C:\escan
    [2015.03.31 20:10:23 | 000,000,000 | ---D | C] -- C:\VundoFix Backups
    [2015.03.31 20:10:06 | 000,107,008 | ---- | C] (Atribune.org) -- C:\Users\Olohuone\Desktop\VundoFix.exe
    [2015.03.31 20:06:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    [2015.03.31 20:06:49 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
    [2015.03.31 19:59:19 | 000,000,000 | ---D | C] -- C:\Users\Olohuone\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
    [2015.03.31 19:59:18 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
    [2015.03.31 19:22:19 | 000,018,968 | ---- | C] (Safer Networking Limited) -- C:\Windows\System32\sdnclean.exe
    [2015.03.31 19:22:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
    [2015.03.31 19:22:10 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy 2
    [2015.03.31 18:40:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    [2015.03.31 18:40:01 | 000,114,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
    [2015.03.31 18:39:42 | 000,075,480 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamchameleon.sys
    [2015.03.31 18:39:42 | 000,051,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mwac.sys
    [2015.03.31 18:39:42 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
    [2015.03.31 18:39:42 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
    [2015.03.30 20:13:34 | 000,000,000 | ---D | C] -- C:\ProgramData\5218352102202084072
    [2015.03.28 18:09:18 | 000,000,000 | ---D | C] -- C:\Users\Olohuone\AppData\Roaming\Google
    [2015.03.28 18:03:25 | 000,000,000 | ---D | C] -- C:\Users\Olohuone\AppData\Local\NikLicenseFiles
    [2015.03.28 18:03:24 | 000,000,000 | ---D | C] -- C:\Users\Olohuone\AppData\Local\Software
    [2015.03.28 17:43:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
    [2015.03.28 17:42:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
    [2015.03.28 14:36:43 | 000,000,000 | ---D | C] -- C:\Users\Olohuone\Desktop\Photoshop
    [2015.03.23 18:16:25 | 000,000,000 | ---D | C] -- C:\Windows\Fonts\AdvUninstal
    [2015.03.13 10:52:14 | 000,744,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\blackbox.dll
    [2015.03.13 10:52:13 | 000,988,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmv2clt.dll
    [2015.03.13 10:52:12 | 003,209,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
    [2015.03.13 10:52:12 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmsdk.dll
    [2015.03.13 10:52:08 | 000,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmmgrtn.dll
    [2015.03.13 10:52:05 | 003,973,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
    [2015.03.13 10:52:04 | 003,917,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
    [2015.03.13 10:52:04 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\evr.dll
    [2015.03.13 10:52:03 | 001,329,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
    [2015.03.13 10:52:02 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
    [2015.03.13 10:52:00 | 000,455,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
    [2015.03.13 10:52:00 | 000,354,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
    [2015.03.13 10:51:58 | 000,409,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ci.dll
    [2015.03.13 10:51:57 | 000,521,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
    [2015.03.13 10:51:57 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
    [2015.03.13 10:51:55 | 000,262,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rstrui.exe
    [2015.03.13 10:51:54 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscp.dll
    [2015.03.13 10:51:52 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msnetobj.dll
    [2015.03.13 10:51:52 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
    [2015.03.13 10:51:51 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
    [2015.03.13 10:51:51 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rrinstaller.exe
    [2015.03.13 10:51:50 | 000,374,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AudioEng.dll
    [2015.03.13 10:51:50 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appidpolicyconverter.exe
    [2015.03.13 10:51:49 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AUDIOKSE.dll
    [2015.03.13 10:51:49 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pcadm.dll
    [2015.03.13 10:51:48 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appidapi.dll
    [2015.03.13 10:51:48 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfpmp.exe
    [2015.03.13 10:51:46 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AudioSes.dll
    [2015.03.13 10:51:46 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pcawrk.exe
    [2015.03.13 10:51:45 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setbcdlocale.dll
    [2015.03.13 10:51:45 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
    [2015.03.13 10:51:44 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDump.dll
    [2015.03.13 10:51:44 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appidcertstorecheck.exe
    [2015.03.13 10:51:44 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msmmsp.dll
    [2015.03.13 10:51:44 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pcalua.exe
    [2015.03.13 10:51:41 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pcaevts.dll
    [2015.03.13 10:51:41 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwmp.dll
    [2015.03.13 10:51:41 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\apisetschema.dll
    [2015.03.13 10:51:41 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx
    [2015.03.13 10:51:41 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxmasf.dll
    [2015.03.13 10:51:41 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mferror.dll
    [2015.03.13 10:51:40 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
    [2015.03.12 20:09:36 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ubpm.dll
    [2015.03.12 20:09:23 | 002,381,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
    [2015.03.12 20:09:21 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\JavaScriptCollectionAgent.dll
    [2015.03.12 20:09:20 | 000,684,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2015.03.12 20:09:20 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
    [2015.03.12 20:09:20 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
    [2015.03.12 20:09:20 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
    [2015.03.12 20:09:20 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2015.03.12 20:09:19 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2015.03.12 20:09:19 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
    [2015.03.12 20:09:19 | 000,418,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2015.03.12 20:09:19 | 000,342,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2015.03.12 20:09:19 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2015.03.12 20:09:19 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2015.03.12 20:09:18 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
    [2015.03.12 20:09:18 | 000,689,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2015.03.12 20:09:17 | 002,052,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2015.03.12 20:09:17 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2015.03.12 20:09:16 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2015.03.12 20:09:16 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
    [2015.03.12 20:09:15 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2015.03.12 20:09:15 | 000,285,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2015.03.12 20:09:13 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
    [2015.03.12 20:09:12 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MshtmlDac.dll
    [2015.03.12 20:09:10 | 004,300,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2015.03.12 20:07:38 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
    [2015.03.12 20:07:37 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\auditpol.exe
    [2015.03.12 20:07:37 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
    [2015.03.12 20:07:36 | 000,686,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adtschema.dll
    [2015.03.12 20:07:36 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msaudite.dll
    [2015.03.12 20:07:36 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msobjs.dll
    [2015.03.12 20:07:09 | 000,299,008 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
    [2015.03.12 20:07:09 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
    [2015.03.12 20:07:09 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
    [2015.03.12 20:07:09 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dciman32.dll
    [2015.03.12 20:07:05 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
    [2015.03.11 18:49:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\Hotspot Shield
    [2015.03.06 20:37:50 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
    [2015.03.04 23:09:34 | 000,000,000 | ---D | C] -- C:\Users\Olohuone\AppData\Roaming\LavasoftStatistics
    [2015.03.04 23:09:14 | 000,325,944 | ---- | C] (Lavasoft Limited) -- C:\Windows\System32\LavasoftTcpService.dll

    ========== Files[​IMG] - Modified Within 30 Days ==========

    [2015.03.31 21:01:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2015.03.31 20:48:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Olohuone\Desktop\OTL.exe
    [2015.03.31 20:46:56 | 000,021,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2015.03.31 20:46:56 | 000,021,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2015.03.31 20:46:40 | 000,651,938 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2015.03.31 20:46:40 | 000,120,870 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2015.03.31 20:45:00 | 000,000,996 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2015.03.31 20:39:29 | 000,000,992 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2015.03.31 20:39:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2015.03.31 20:39:12 | 2609,074,176 | -HS- | M] () -- C:\hiberfil.sys
    [2015.03.31 20:05:33 | 000,094,862 | ---- | M] () -- C:\Users\Olohuone\Desktop\VundoFix_v6.5.0.zip
    [2015.03.31 19:59:19 | 000,002,979 | ---- | M] () -- C:\Users\Olohuone\Desktop\HiJackThis.lnk
    [2015.03.31 19:22:32 | 000,002,123 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start[​IMG] Center.lnk
    [2015.03.31 19:19:06 | 000,114,904 | ---- | M] (Malwarebytes[​IMG] Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
    [2015.03.31 18:40:36 | 000,001,064 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2015.03.31 17:12:39 | 000,020,508 | ---- | M] () -- C:\Users\Olohuone\Documents\cc_20150331_171234.reg
    [2015.03.30 18:31:16 | 000,000,020 | ---- | M] () -- C:\Users\Olohuone\AppData\Roaming\appdataFr3.bin
    [2015.03.23 20:34:12 | 000,002,223 | ---- | M] () -- C:\Users\Olohuone\Application[​IMG] Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome[​IMG].lnk
    [2015.03.23 20:34:00 | 000,002,199 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2015.03.23 18:07:41 | 000,001,128 | ---- | M] () -- C:\Users\Olohuone\Documents\cc_20150323_170737.reg
    [2015.03.13 11:01:42 | 003,762,560 | ---- | M] () -- C:\Windows[​IMG]\System32\FNTCACHE.DAT
    [2015.03.06 18:28:44 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
    [2015.03.06 08:10:29 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
    [2015.03.06 08:10:22 | 000,221,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
    [2015.03.06 08:09:31 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\auditpol.exe
    [2015.03.06 08:07:50 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msobjs.dll
    [2015.03.06 08:07:43 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msaudite.dll
    [2015.03.06 08:06:20 | 000,686,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\adtschema.dll
    [2015.03.05 09:45:15 | 000,033,958 | ---- | M] () -- C:\Users\Olohuone\Documents\cc_20150305_084510.reg
    [2015.03.03 16:16:52 | 000,246,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
    [2015.03.02 19:02:20 | 000,325,944 | ---- | M] (Lavasoft Limited) -- C:\Windows\System32\LavasoftTcpService.dll

    ========== Files Created - No Company Name ==========

    [2015.03.31 20:05:31 | 000,094,862 | ---- | C] () -- C:\Users\Olohuone\Desktop\VundoFix_v6.5.0.zip
    [2015.03.31 19:59:19 | 000,002,979 | ---- | C] () -- C:\Users\Olohuone\Desktop\HiJackThis.lnk
    [2015.03.31 19:22:32 | 000,002,135 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu[​IMG]\Programs\Spybot-S&D Start Center.lnk
    [2015.03.31 19:22:32 | 000,002,123 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    [2015.03.31 18:39:51 | 000,001,064 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes[​IMG] Anti-Malware.lnk
    [2015.03.31 17:12:35 | 000,020,508 | ---- | C] () -- C:\Users\Olohuone\Documents\cc_20150331_171234.reg
    [2015.03.28 17:13:02 | 000,000,020 | ---- | C] () -- C:\Users\Olohuone\AppData\Roaming\appdataFr3.bin
    [2015.03.23 20:34:00 | 000,002,223 | ---- | C] () -- C:\Users\Olohuone\Application[​IMG] Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome[​IMG].lnk
    [2015.03.23 20:34:00 | 000,002,199 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2015.03.23 18:07:39 | 000,001,128 | ---- | C] () -- C:\Users\Olohuone\Documents\cc_20150323_170737.reg
    [2015.03.05 09:45:12 | 000,033,958 | ---- | C] () -- C:\Users\Olohuone\Documents\cc_20150305_084510.reg
    [2011.11.17 23:19:52 | 000,003,331 | ---- | C] () -- C:\Users\Olohuone\AppData\Local\recently-used.xbel
    [2011.10.28 20:21:32 | 000,000,564 | ---- | C] () -- C:\Users\Olohuone\AppData\Local\FSCache.dat

    ========== ZeroAccess Check ==========

    [2009.07.14 07:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2015.02.13 08:26:18 | 012,875,264 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 00:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
    "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 04:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    < End of report >
     
  4. VisitorQ

    VisitorQ Member

    Joined:
    Mar 31, 2015
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    6
    Tossa OTL login välissä oli vielä hirvee määrä jotain tavaraa jota en saannu tänne mahtumaan, otsikkona oli FireFox ja sit tavaraa kauhee määrä.
     

Share This Page