ok apparently I deleted the stupid roguekiller log so will get that to you later as it took quite a while to run...heres frst 1 and 2 though:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01
Ran by Gloria (administrator) on GLORIA-PC on 16-07-2014 21:13:50
Running from C:\Users\Gloria\Desktop
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Apple, Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Solid Oak Software, Inc.) C:\Windows\CComSvc.exe
(IDT, Inc.) C:\Windows\System32\stacsv.exe
(Solid Oak Software, Inc.) C:\Windows\WVCSWD.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
(Solid Oak Software, Inc.) C:\Windows\Cyb10.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
() C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
(Weather Warnings LLC) C:\Users\Gloria\AppData\Local\StormAlerts\StormAlerts.exe
() C:\Users\Gloria\AppData\Local\StormAlerts\StormAlertsApp.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Avira Operations GmbH & Co. KG) C:\Users\Gloria\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MOVPM1P6\avira_en_av___ws2.exe
(Avira Operations GmbH & Co. KG) C:\Users\Gloria\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MOVPM1P6\avira_en_av___ws2.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [Adobe Photo Downloader] => C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [63712 2007-03-09] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [413696 2008-05-27] (Apple Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [348664 2012-08-14] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [C2K] => C:\Windows\Cyb10.exe [5010728 2007-11-19] (Solid Oak Software, Inc.)
HKLM\...\Run: [Coupon Alert Search Scope Monitor] => "C:\PROGRA~1\COUPON~2\bar\1.bin\2psrchmn.exe" /m=2 /w /h
HKLM\...\Run: [] => [X]
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254896 2012-09-17] (Sun Microsystems, Inc.)
HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-2959302338-3947095310-1867549206-1001\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-2959302338-3947095310-1867549206-1001\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-2959302338-3947095310-1867549206-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2959302338-3947095310-1867549206-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2959302338-3947095310-1867549206-1001\...\MountPoints2: {57e3b99a-bd8b-11e1-badf-0019d1a08d5e} - E:\VZAccess_Manager.exe /z detect
HKU\S-1-5-21-2959302338-3947095310-1867549206-1001\...\MountPoints2: {8288ee37-ee55-11dd-9344-0019d1a08d5e} - setupSNK.exe
HKU\S-1-5-21-2959302338-3947095310-1867549206-1001\...\MountPoints2: {89030d4a-ec5c-11e0-9861-806e6f6e6963} - C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe
HKU\S-1-5-21-2959302338-3947095310-1867549206-1001\...\MountPoints2: {98e6aec6-9705-11dc-94e9-d932578c2835} - G:\LaunchU3.exe -a
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG311T Smart Wizard.lnk
ShortcutTarget: NETGEAR WG311T Smart Wizard.lnk -> C:\Program Files\NETGEAR\WG311T\wlancfg5.exe ()
Startup: C:\Users\Gloria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Storm Alerts.lnk
ShortcutTarget: Storm Alerts.lnk -> C:\Users\Gloria\AppData\Local\StormAlerts\StormAlerts.exe (Weather Warnings LLC)
Startup: C:\Users\Gloria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormAlerts.lnk
ShortcutTarget: StormAlerts.lnk -> C:\Users\Gloria\AppData\Local\StormAlerts\StormAlertsApp.exe ()
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
GroupPolicyUsers\S-1-5-21-2959302338-3947095310-1867549206-1003\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyServer: http=127.0.0.1:13828
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
URLSearchHook: HKCU - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {92109306-D2EE-4C0E-8CC2-2BC73E8DC799} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {92109306-D2EE-4C0E-8CC2-2BC73E8DC799} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - ÛŸÆîZ§'2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×-(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: &Yahoo! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
BHO: HP Print Clips -> {053F9267-DC04-4294-A72C-58F732D338C0} -> C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
BHO: Accelerator Plugin -> {656EC4B7-072B-4698-B504-2A414C1F0037} -> C:\PROGRA~1\PEOPLE~1\PRPL_I~1.DLL No File
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
Toolbar: HKCU - No Name - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - No File
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB}
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [147456] (Apple Inc.)
Winsock: Catalog9 01 C:\Windows\system32\lspcs.dll [159744] (Solid Oak)
Winsock: Catalog9 02 C:\Windows\system32\lspcs.dll [159744] (Solid Oak)
Winsock: Catalog9 03 C:\Windows\system32\lspcs.dll [159744] (Solid Oak)
Winsock: Catalog9 04 C:\Windows\system32\lspcs.dll [159744] (Solid Oak)
Winsock: Catalog9 05 C:\Windows\system32\lspcs.dll [159744] (Solid Oak)
Winsock: Catalog9 38 C:\Windows\system32\lspcs.dll [159744] (Solid Oak)
Tcpip\Parameters: [DhcpNameServer] 192.168.3.130
FireFox:
========
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=1.6.0_39 - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-07-15]
FF HKCU\...\Firefox\Extensions: [{860ACD79-2F77-EEE2-3D92-149C8347B912}] - C:\Program Files\Buzz-it-soft\158.xpi
========================== Services (Whitelisted) =================
S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-02] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [110592 2007-10-31] (Apple, Inc.) [File not signed]
R2 Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [229376 2007-07-24] (Apple Inc.) [File not signed]
R2 CCOMSVC; C:\Windows\CComSvc.exe [2401576 2007-11-19] (Solid Oak Software, Inc.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-03-11] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-11] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 STacSV; C:\Windows\system32\STacSV.exe [98304 2007-06-27] (IDT, Inc.) [File not signed]
U2 WVCSWDSVC; C:\Windows\WVCSWD.exe [1153320 2007-11-19] (Solid Oak Software, Inc.)
S2 htfmboczez32; C:\Program Files\003\htfmboczez32.exe run options=01110010030000000000000000000000 sourceguid=0866B8A9-2E46-422F-947B-2C563F566A0E [X]
==================== Drivers (Whitelisted) ====================
S3 AR5211; C:\Windows\System32\DRIVERS\WG311T13.sys [456768 2005-09-20] (Atheros Communications, Inc.) [File not signed]
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [83392 2012-04-25] (Avira GmbH)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137928 2012-04-27] (Avira GmbH)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36000 2012-04-16] (Avira GmbH)
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [9216 2010-12-03] (MBB Incorporated)
S3 PTDMBus; C:\Windows\System32\DRIVERS\PTDMBus.sys [29952 2007-08-17] (DEVGURU Co,LTD.)
S3 PTDMMdm; C:\Windows\System32\DRIVERS\PTDMMdm.sys [41856 2007-08-17] (DEVGURU Co,LTD.)
S3 PTDMVsp; C:\Windows\System32\DRIVERS\PTDMVsp.sys [39936 2007-08-17] (DEVGURU Co,LTD.)
S3 PTDMWWAN; C:\Windows\System32\DRIVERS\PTDMWWAN.sys [59520 2007-08-17] (DEVGURU Co,LTD.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH)
S3 ZTEusbgps; C:\Windows\System32\DRIVERS\ZTEusbgps.sys [105856 2010-12-03] (ZTE Incorporated)
S3 ZTEusbnmeaext; C:\Windows\System32\DRIVERS\ZTEusbnmeaext.sys [105856 2010-12-03] (ZTE Incorporated)
S4 blbdrive; No ImagePath
S3 IpInIp; No ImagePath
S1 kkcysuwk; \??\C:\Windows\system32\drivers\kkcysuwk.sys [X]
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-16 21:13 - 2014-07-16 21:14 - 00013068 _____ () C:\Users\Gloria\Desktop\FRST.txt
2014-07-16 21:13 - 2014-07-16 21:13 - 01077248 _____ (Farbar) C:\Users\Gloria\Desktop\FRST.exe
2014-07-16 21:13 - 2014-07-16 21:13 - 00000000 ____D () C:\FRST
2014-07-16 21:05 - 2014-07-16 21:08 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-16 21:05 - 2014-07-16 21:05 - 00000909 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-16 21:05 - 2014-07-16 21:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-16 21:05 - 2014-07-16 21:05 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-16 21:05 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-16 21:05 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-16 21:04 - 2014-07-16 21:04 - 00000000 ____D () C:\Users\Gloria\Desktop\mbam-chameleon-3.1.4.0
2014-07-16 21:03 - 2014-07-16 21:03 - 00002221 _____ () C:\Users\Gloria\Desktop\JRT.txt
2014-07-16 20:56 - 2014-07-16 20:56 - 00000000 ____D () C:\Windows\ERUNT
2014-07-16 20:39 - 2014-07-16 20:51 - 00000000 ____D () C:\AdwCleaner
2014-07-16 20:39 - 2014-07-16 20:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-16 20:38 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-16 20:34 - 2014-07-16 20:34 - 01016261 _____ (Thisisu) C:\Users\Gloria\Desktop\JRT.exe
2014-07-16 20:32 - 2014-07-16 20:33 - 01348263 _____ () C:\Users\Gloria\Desktop\AdwCleaner.exe
==================== One Month Modified Files and Folders =======
2014-07-16 21:14 - 2014-07-16 21:13 - 00013068 _____ () C:\Users\Gloria\Desktop\FRST.txt
2014-07-16 21:13 - 2014-07-16 21:13 - 01077248 _____ (Farbar) C:\Users\Gloria\Desktop\FRST.exe
2014-07-16 21:13 - 2014-07-16 21:13 - 00000000 ____D () C:\FRST
2014-07-16 21:13 - 2014-04-19 18:00 - 00000000 ____D () C:\Users\Gloria\AppData\Local\StormAlerts
2014-07-16 21:08 - 2014-07-16 21:05 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-16 21:05 - 2014-07-16 21:05 - 00000909 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-16 21:05 - 2014-07-16 21:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-16 21:05 - 2014-07-16 21:05 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-16 21:05 - 2006-11-02 07:52 - 01984909 _____ () C:\Windows\WindowsUpdate.log
2014-07-16 21:04 - 2014-07-16 21:04 - 00000000 ____D () C:\Users\Gloria\Desktop\mbam-chameleon-3.1.4.0
2014-07-16 21:03 - 2014-07-16 21:03 - 00002221 _____ () C:\Users\Gloria\Desktop\JRT.txt
2014-07-16 21:03 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-07-16 20:56 - 2014-07-16 20:56 - 00000000 ____D () C:\Windows\ERUNT
2014-07-16 20:53 - 2006-11-02 05:33 - 00703388 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-16 20:51 - 2014-07-16 20:39 - 00000000 ____D () C:\AdwCleaner
2014-07-16 20:46 - 2013-08-02 19:13 - 00095532 _____ () C:\Windows\WVCSWD_Dbg.txt
2014-07-16 20:46 - 2008-01-02 11:05 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-07-16 20:46 - 2006-11-02 08:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-16 20:46 - 2006-11-02 07:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-16 20:46 - 2006-11-02 07:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-16 20:45 - 2007-11-06 18:46 - 00410764 _____ () C:\Windows\PFRO.log
2014-07-16 20:44 - 2006-11-02 08:01 - 00032606 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-16 20:43 - 2006-11-02 06:18 - 00000000 ___RD () C:\Users\Public
2014-07-16 20:39 - 2014-07-16 20:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-16 20:34 - 2014-07-16 20:34 - 01016261 _____ (Thisisu) C:\Users\Gloria\Desktop\JRT.exe
2014-07-16 20:33 - 2014-07-16 20:32 - 01348263 _____ () C:\Users\Gloria\Desktop\AdwCleaner.exe
2014-07-16 20:15 - 2006-11-02 07:52 - 00143857 _____ () C:\Windows\setupact.log
2014-07-16 20:13 - 2013-07-21 13:53 - 00000000 ____D () C:\Windows\system32\MRT
Some content of TEMP:
====================
C:\Users\aiden\AppData\Local\Temp\AskSLib.dll
C:\Users\aiden\AppData\Local\Temp\symlcsv1.exe
C:\Users\Gloria\AppData\Local\Temp\1056_HiDefMedia-1.1.12-win32B-276.exe
C:\Users\Gloria\AppData\Local\Temp\781D_install_flashplayer11x32_mssd_aih.exe
C:\Users\Gloria\AppData\Local\Temp\air1055.exe
C:\Users\Gloria\AppData\Local\Temp\air1195.exe
C:\Users\Gloria\AppData\Local\Temp\air18E.exe
C:\Users\Gloria\AppData\Local\Temp\air2F0B.exe
C:\Users\Gloria\AppData\Local\Temp\air32E9.exe
C:\Users\Gloria\AppData\Local\Temp\air3C7F.exe
C:\Users\Gloria\AppData\Local\Temp\air550D.exe
C:\Users\Gloria\AppData\Local\Temp\air6E.exe
C:\Users\Gloria\AppData\Local\Temp\air71A0.exe
C:\Users\Gloria\AppData\Local\Temp\air741A.exe
C:\Users\Gloria\AppData\Local\Temp\air781E.exe
C:\Users\Gloria\AppData\Local\Temp\air88F8.exe
C:\Users\Gloria\AppData\Local\Temp\air93F7.exe
C:\Users\Gloria\AppData\Local\Temp\air9B29.exe
C:\Users\Gloria\AppData\Local\Temp\airB14C.exe
C:\Users\Gloria\AppData\Local\Temp\airE2CA.exe
C:\Users\Gloria\AppData\Local\Temp\airFD1.exe
C:\Users\Gloria\AppData\Local\Temp\airFD5C.exe
C:\Users\Gloria\AppData\Local\Temp\ApnStub.exe
C:\Users\Gloria\AppData\Local\Temp\AskSLib.dll
C:\Users\Gloria\AppData\Local\Temp\BackupSetup.exe
C:\Users\Gloria\AppData\Local\Temp\comver.dll
C:\Users\Gloria\AppData\Local\Temp\contentDATs.exe
C:\Users\Gloria\AppData\Local\Temp\Couponscom.exe
C:\Users\Gloria\AppData\Local\Temp\eject.exe
C:\Users\Gloria\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Gloria\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe
C:\Users\Gloria\AppData\Local\Temp\ICReinstall_Adobe_Reader_setup.exe
C:\Users\Gloria\AppData\Local\Temp\installer.exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih.exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aih.exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aih_1.exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aih_2.exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aih_3.exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer11x32ax_gtbd_chrd_dn_aih[1].exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer12x32ax_gtbd_chrd_dn_aaa_aih.exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer12x32ax_gtbd_chrd_dn_aaa_aih_1.exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer12x32ax_gtbd_chrd_dn_aaa_aih_2.exe
C:\Users\Gloria\AppData\Local\Temp\install_flashplayer12x32ax_gtbd_chrd_dn_aaa_aih_3.exe
C:\Users\Gloria\AppData\Local\Temp\install_reader10_en_chra_awa_aih.exe
C:\Users\Gloria\AppData\Local\Temp\jre-6u3-windows-i586-p-iftw_2cd32978.exe
C:\Users\Gloria\AppData\Local\Temp\jre-6u33-windows-i586-iftw_137b7395.exe
C:\Users\Gloria\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
C:\Users\Gloria\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe
C:\Users\Gloria\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe
C:\Users\Gloria\AppData\Local\Temp\jre-6u5-windows-i586-p-iftw_1b121abb.exe
C:\Users\Gloria\AppData\Local\Temp\jre-6u7-windows-i586-p-iftw_bdb28397.exe
C:\Users\Gloria\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Gloria\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Gloria\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Gloria\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Gloria\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Gloria\AppData\Local\Temp\mssinstaller.exe
C:\Users\Gloria\AppData\Local\Temp\nsdC1C1.exe
C:\Users\Gloria\AppData\Local\Temp\nsr8EA5.exe
C:\Users\Gloria\AppData\Local\Temp\nsuFAA0.exe
C:\Users\Gloria\AppData\Local\Temp\oi_{E039652B-9993-4B01-8850-DA0703C38969}.exe
C:\Users\Gloria\AppData\Local\Temp\PPCToolbar.dll
C:\Users\Gloria\AppData\Local\Temp\safeguard.exe
C:\Users\Gloria\AppData\Local\Temp\ScamGrd.dll
C:\Users\Gloria\AppData\Local\Temp\SecurityScan_Release.exe
C:\Users\Gloria\AppData\Local\Temp\SendMsg.dll
C:\Users\Gloria\AppData\Local\Temp\setup.exe
C:\Users\Gloria\AppData\Local\Temp\SPSetup.exe
C:\Users\Gloria\AppData\Local\Temp\vbmz6.exe
C:\Users\Gloria\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Gloria\AppData\Local\Temp\VistaUtils.exe
C:\Users\Gloria\AppData\Local\Temp\VisualBeeSilent.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_1.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_10.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_11.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_12.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_2.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_3.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_4.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_5.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_6.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_7.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_8.exe
C:\Users\Gloria\AppData\Local\Temp\ytb_7.0.9.0_1.4.1_ysp_1.2_pub_us_setup_9.exe
C:\Users\Gloria\AppData\Local\Temp\{37329191-3EA5-4EFE-B8A8-D6A773D141F8}-32.0.1700.107_chrome_installer.exe
C:\Users\Gloria\AppData\Local\Temp\{743EF21C-F810-4398-9FD7-A982EC678915}-32.0.1700.107_chrome_installer.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-16 20:53
==================== End Of Log ============================