Hello SuperDave. thanks for the quick response and your help.
Had quite a scare a few minutes ago. I ran the jrt and then ran the combofix. the combo fix restarted the computer and processed the log. I went to open IE to send you the reports and all the sudden got a message saying "Illegal operation attempted on a registry key marked for deletion" I tried to open the reports to take to another computer to send to you and was getting the same saying on any program I tried to open. started having a panic attack..
Anyhow I decided to restart computer again and everything seems to be working now.
Figured I should let you know.
Oh and I knew there was two antiviruses and I have the zone alarm disabled or think I do, pretty sure I do. I couldn't find a place to just get the zonealarm firewall by itself? I value your guy's opinions and if you think Zone alarm virus protection is just as good as avg I will just uninstall avg.
Thanks for the help!
Ok here are the reports. will wait for further instructions.
JRT log:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.2.2 (07.22.2013:2)
OS: Windows 7 Home Premium x64
Ran by Carol Lee on Thu 07/25/2013 at 13:55:54.18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{17662709-9A30-4ABF-9460-14DDBDC77084}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{AE3D60B2-482E-4778-9FA2-8984E5A64262}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}
~~~ Files
Successfully deleted: [File] "C:\Windows\couponprinter.ocx"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Carol Lee\appdata\local\visi_coupon"
Successfully deleted: [Folder] "C:\Users\Carol Lee\appdata\locallow\totalrecipesearch_14"
Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"
~~~ FireFox
Emptied folder: C:\Users\Carol Lee\AppData\Roaming\mozilla\firefox\profiles\vfbcj3gf.default\minidumps [48 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 07/25/2013 at 14:02:00.74
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Combofix log:
ComboFix 13-07-25.02 - Carol Lee 07/25/2013 14:08:21.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2531 [GMT -6:00]
Running from: c:\users\Carol Lee\Desktop\ComboFix.exe
AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: ZoneAlarm Free Firewall Antivirus *Disabled/Outdated* {DE038A5B-9EDD-18A9-2361-FF7D98D43730}
FW: ZoneAlarm Free Firewall Firewall *Disabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: ZoneAlarm Free Firewall Anti-Spyware *Disabled/Outdated* {65626BBF-B8E7-1727-19D1-C40FE3537D8D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\data
c:\data\0p_20hhejjef_o\us_sres.data
c:\data\default\us_sres.data
c:\program files (x86)\MyWebFace_5aEI
c:\program files (x86)\MyWebFace_5aEI\Installr\1.bin\5aEZSETP.dll
c:\users\Carol Lee\WINDOWS
c:\windows\SysWow64\Cache
c:\windows\SysWow64\Cache\272512937d9e61a4.fb
c:\windows\SysWow64\Cache\287204568329e189.fb
c:\windows\SysWow64\Cache\28bc8f716fd76a47.fb
c:\windows\SysWow64\Cache\2c53092c95605355.fb
c:\windows\SysWow64\Cache\3917078cb68ec657.fb
c:\windows\SysWow64\Cache\425f96eab34a884d.fb
c:\windows\SysWow64\Cache\590ba23ce359fd0c.fb
c:\windows\SysWow64\Cache\610289e025a3ee9a.fb
c:\windows\SysWow64\Cache\651c5d3cdbfb8bd1.fb
c:\windows\SysWow64\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\SysWow64\Cache\a8556537add6dfc5.fb
c:\windows\SysWow64\Cache\ad10a52aff5e038d.fb
c:\windows\SysWow64\Cache\b1575de33224ecfa.fb
c:\windows\SysWow64\Cache\c4d28dca2e7648be.fb
c:\windows\SysWow64\Cache\d201ef9910cd39de.fb
c:\windows\SysWow64\Cache\d2e94710a5708128.fb
c:\windows\SysWow64\Cache\d79b9dfe81484ec4.fb
c:\windows\SysWow64\Cache\e0de16f883bea794.fb
.
.
((((((((((((((((((((((((( Files Created from 2013-06-25 to 2013-07-25 )))))))))))))))))))))))))))))))
.
.
2013-07-25 20:15 . 2013-07-25 20:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-25 19:55 . 2013-07-25 19:55 -------- d-----w- c:\windows\ERUNT
2013-07-24 19:02 . 2013-04-04 20:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-07-24 19:02 . 2013-07-24 19:02 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-07-24 18:03 . 2013-07-24 18:03 -------- d-----w- c:\program files\CCleaner
2013-07-24 12:39 . 2013-07-24 12:39 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-07-24 11:45 . 2013-05-23 00:49 32600 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2013-07-24 11:45 . 2013-05-23 00:49 17720 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2013-07-24 11:07 . 2013-07-24 11:07 -------- d-----w- c:\users\Carol Lee\AppData\Roaming\AVG2013
2013-07-24 11:07 . 2013-07-24 11:07 -------- d-----w- c:\programdata\AVG2013
2013-07-24 11:07 . 2013-07-24 11:07 -------- d-----w- C:\$AVG
2013-07-24 11:06 . 2013-07-24 11:09 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Avg2013
2013-07-24 11:06 . 2013-07-24 11:06 -------- d-----w- c:\program files (x86)\AVG
2013-07-24 11:01 . 2013-07-25 14:41 -------- d-----w- c:\programdata\MFAData
2013-07-24 11:01 . 2013-07-24 13:26 -------- d-----w- c:\users\Carol Lee\AppData\Local\Avg2013
2013-07-24 11:01 . 2013-07-24 11:01 -------- d-----w- c:\users\Carol Lee\AppData\Local\MFAData
2013-07-24 10:35 . 2013-07-24 10:35 -------- d-----w- C:\AVGTemp
2013-07-23 22:32 . 2013-07-23 22:32 -------- d-----w- c:\users\Carol Lee\AppData\Roaming\PC-FAX TX
2013-07-23 22:04 . 2013-07-23 22:04 -------- d-----w- C:\Brother
2013-07-23 22:04 . 2013-07-23 22:04 -------- d-----w- c:\program files (x86)\Browny02
2013-07-23 22:04 . 2010-02-09 23:11 217088 ------w- c:\windows\SysWow64\NSSearch.dll
2013-07-23 22:04 . 2010-01-22 21:34 3072 ------w- c:\windows\SysWow64\BrDctF2S.dll
2013-07-23 22:04 . 2007-12-14 04:16 73728 ------w- c:\windows\SysWow64\BrDctF2.dll
2013-07-23 22:04 . 2007-12-14 04:16 5120 ------w- c:\windows\SysWow64\BrDctF2L.dll
2013-07-23 22:04 . 2010-02-05 17:42 180224 ------w- c:\windows\SysWow64\BroSNMP.dll
2013-07-23 21:59 . 2013-07-23 21:59 -------- d-----w- c:\users\Carol Lee\AppData\Roaming\InstallShield
2013-07-23 18:25 . 2013-07-23 18:25 9216 ----a-w- c:\program files (x86)\Windows Defender\MpAsDesc.dll
2013-07-23 18:25 . 2013-07-23 18:25 571904 ----a-w- c:\program files\Windows Defender\MpClient.dll
2013-07-23 18:25 . 2013-07-23 18:25 54784 ----a-w- c:\program files (x86)\Windows Defender\MpOAV.dll
2013-07-23 18:25 . 2013-07-23 18:25 4608 ----a-w- c:\program files (x86)\Windows Defender\MsMpLics.dll
2013-07-23 18:25 . 2013-07-23 18:25 392704 ----a-w- c:\program files (x86)\Windows Defender\MpClient.dll
2013-07-23 18:25 . 2013-07-23 18:25 314880 ----a-w- c:\program files\Windows Defender\MpCommu.dll
2013-07-23 18:25 . 2013-07-23 18:25 1011712 ----a-w- c:\program files\Windows Defender\MpSvc.dll
2013-07-23 18:24 . 2013-07-23 18:24 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-07-23 18:23 . 2013-07-23 18:23 624128 ----a-w- c:\windows\system32\qedit.dll
2013-07-23 18:23 . 2013-07-23 18:23 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2013-07-23 18:23 . 2013-07-23 18:23 1732608 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2013-07-23 18:23 . 2013-07-23 18:23 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2013-07-23 18:22 . 2013-07-23 18:22 1887744 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-23 18:22 . 2013-07-23 18:22 1620480 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-23 18:22 . 2013-07-23 18:22 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-07-23 18:22 . 2013-07-23 18:22 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-07-21 23:14 . 2013-07-23 22:18 -------- d-----w- c:\program files (x86)\Cisco Systems
2013-07-21 23:01 . 2013-07-21 23:01 -------- d-----w- c:\programdata\Cisco Systems
2013-07-20 19:19 . 2013-07-20 19:19 -------- d-----w- c:\programdata\Pure Networks
2013-07-18 16:10 . 2013-07-18 16:10 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\IObit
2013-07-17 16:07 . 2013-07-24 09:33 -------- d-----w- c:\windows\system32\MRT
2013-07-11 20:38 . 2013-07-11 20:38 1393152 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2013-07-11 20:38 . 2013-07-11 20:38 936448 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 20:38 . 2013-07-11 20:38 1367040 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 20:23 . 2013-07-11 20:23 -------- d-----w- c:\programdata\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-24 11:59 . 2012-11-19 02:19 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-24 11:59 . 2012-11-19 02:19 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-07-24 10:48 . 2011-02-27 00:33 2876528 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2013-07-24 10:47 . 2011-02-04 21:09 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2013-06-24 06:57 . 2010-12-25 18:07 78277128 ----a-w- c:\windows\system32\MRT.exe
2013-06-13 22:34 . 2011-05-08 00:51 451096 ----a-w- c:\windows\system32\drivers\vsdatant.sys
2013-06-13 03:48 . 2012-08-24 01:23 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-06-13 03:48 . 2011-11-05 23:38 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-06-13 03:47 . 2013-06-18 23:20 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-05-18 20:28 . 2013-05-18 20:28 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-05-18 20:28 . 2013-05-18 20:28 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-05-18 20:28 . 2013-05-18 20:28 144384 ----a-w- c:\windows\system32\cdd.dll
2013-05-18 20:20 . 2013-05-18 20:20 197120 ----a-w- c:\windows\system32\shdocvw.dll
2013-05-18 20:20 . 2013-05-18 20:20 1930752 ----a-w- c:\windows\system32\authui.dll
2013-05-18 20:20 . 2013-05-18 20:20 1796096 ----a-w- c:\windows\SysWow64\authui.dll
2013-05-18 20:20 . 2013-05-18 20:20 14172672 ----a-w- c:\windows\system32\shell32.dll
2013-05-18 20:20 . 2013-05-18 20:20 70144 ----a-w- c:\windows\system32\appinfo.dll
2013-05-18 20:20 . 2013-05-18 20:20 111448 ----a-w- c:\windows\system32\consent.exe
2013-05-18 20:20 . 2013-05-18 20:20 48640 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-05-18 20:20 . 2013-05-18 20:20 230400 ----a-w- c:\windows\system32\wwansvc.dll
2013-05-18 20:19 . 2013-05-18 20:19 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-05-18 20:19 . 2013-05-18 20:19 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-05-18 20:19 . 2013-05-18 20:19 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-05-18 20:19 . 2013-05-18 20:19 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-05-18 20:19 . 2013-05-18 20:19 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-05-18 20:19 . 2013-05-18 20:19 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-05-13 05:51 . 2013-06-12 01:49 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-05-13 05:51 . 2013-06-12 01:49 1464320 ----a-w- c:\windows\system32\crypt32.dll
2013-05-13 05:51 . 2013-06-12 01:49 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-05-13 05:50 . 2013-06-12 01:49 52224 ----a-w- c:\windows\system32\certenc.dll
2013-05-13 04:45 . 2013-06-12 01:49 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-05-13 04:45 . 2013-06-12 01:49 1160192 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-05-13 04:45 . 2013-06-12 01:49 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-05-13 03:43 . 2013-06-12 01:49 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-05-13 03:08 . 2013-06-12 01:49 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-05-13 03:08 . 2013-06-12 01:49 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-05-10 05:49 . 2013-06-12 01:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-05-10 03:20 . 2013-06-12 01:49 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-05-08 06:39 . 2013-06-12 01:48 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-05-03 17:02 . 2013-05-03 17:02 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-04-22 05:50 . 2011-04-22 05:50 495 ----a-w- c:\program files (x86)\0421201123504043.bat
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll" [2012-11-26 1525088]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 6"="c:\program files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe" [2013-04-19 491840]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"ZoneAlarm"="c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2013-06-20 73832]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-13 343168]
"SSBkgdUpdate"="c:\program files (x86)\common files\scansoft shared\ssbkgdupdate\ssbkgdupdate.exe" [2006-10-25 210472]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"IObit Malware Fighter"="c:\program files (x86)\IObit\IObit Malware Fighter\IMF.exe" [2013-06-07 1514816]
"ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440]
"AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2013-04-29 4408368]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
R2 RaMediaServer;Ralink UPnP Media Server;c:\program files (x86)\Ralink\Common\RaMediaServer.exe;c:\program files (x86)\Ralink\Common\RaMediaServer.exe
R3 AODDriver4.0;AODDriver4.0;
R3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe;c:\program files (x86)\Browny02\BrYNSvc.exe
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys
S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys;c:\windows\SYSNATIVE\Drivers\RapportKE64.sys
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys
S1 RapportCerberus_43926;RapportCerberus_43926;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys
S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys
S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe
S2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe
S2 RalinkRegistryWriter64;RalinkRegistryWriter64;c:\program files (x86)\Ralink\Common\RaRegistry64.exe;c:\program files (x86)\Ralink\Common\RaRegistry64.exe
S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
S2 ZAPrivacyService;ZoneAlarm Privacy Service;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2013-07-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-19 11:59]
.
2013-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-12 05:54]
.
2013-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-12 05:54]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"SmartMenu"="c:\program files\hewlett-packard\hp mediasmart\smartmenu.exe" [2010-01-18 568888]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.pogo.com/
mLocal Page = c:\windows\SYSTEM32\blank.htm
TCP: DhcpNameServer = 67.142.180.10 67.142.180.11 192.168.1.1
FF - ProfilePath - c:\users\Carol Lee\AppData\Roaming\Mozilla\Firefox\Profiles\vfbcj3gf.default\
FF - prefs.js: browser.search.selectedEngine - Search By ZoneAlarm
FF - prefs.js: browser.startup.homepage - hxxp://www.pogo.com/
FF - prefs.js: keyword.URL - hxxp://search.zonealarm.com/search?src=sp&tbid=goughDev3&Lan=en&gu=8120184c7e0a43f480a62b7b96572463&tu=10G9y009C2B0CO0&sku=&tstsId=&ver=&&q=
FF - ExtSQL: 2013-07-24 00:08;
[email protected]; c:\users\Carol Lee\AppData\Roaming\Mozilla\Firefox\Profiles\vfbcj3gf.default\extensions\
[email protected].
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
WebBrowser-{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - (no file)
AddRemove-Coupon Printer for Windows5.0.0.2 - c:\program files (x86)\Coupons\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\windows\SysWOW64\HPZipm12.exe
c:\program files (x86)\Ralink\Common\RaRegistry.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
.
**************************************************************************
.
Completion time: 2013-07-25 14:22:45 - machine was rebooted
ComboFix-quarantined-files.txt 2013-07-25 20:22
.
Pre-Run: 629,215,375,360 bytes free
Post-Run: 629,044,285,440 bytes free
.
- - End Of File - - 77127E231134045AC2E5B599DF464584
4A7C4350715967A19385746440037F6D