Thank you very much for your help, I downloaded the two bits software and did teh scans.
This was the report RogueKiller gave:
mail : tigzyRK<at>gmail<dot>com
Feedback :
RogueKiller - Geeks to Go Forums
Website :
Download RogueKiller (Official website)
Blog :
tigzy-RK
Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : David P [Admin rights]
Mode : Scan -- Date : 02/23/2013 17:18:45
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 13 ¤¤¤
[SHELL][SUSP PATH] HKLM\[...]\Winlogon : Userinit (C:\Windows\system32\userinit.exe,C:\Windows\system32\config\systemprofile\AppData\Local\rmfrgnmv\asweqqvm.exe,) [x] -> FOUND
[TASK][SUSP PATH] Funmoods : C:\Users\DAVIDP~1\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.EXE /Check [x] -> FOUND
[TASK][SUSP PATH] Hoolapp For Android : C:\Users\DAVIDP~1\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE /Check [x] -> FOUND
[TASK][SUSP PATH] Hoolapp Init : C:\Users\DAVIDP~1\AppData\Roaming\HOOLAP~1\Hoolapp.exe /Minimized [x] -> FOUND
[TASK][SUSP PATH] {7621D280-7FF8-4553-ADA3-136B0267AEA4} : C:\Users\Owner\Desktop\medieval2.exe [x] -> FOUND
[TASK][SUSP PATH] {76FD6E1C-F586-4BE5-8D99-62DE24B363C8} : C:\Users\Owner\Desktop\medieval2.exe [x] -> FOUND
[TASK][SUSP PATH] {78544985-76BA-4B4B-8DE0-B9AE390B216F} : C:\Users\David P\Desktop\wmpfirefoxplugin.exe [7] -> FOUND
[TASK][SUSP PATH] {9B93C97B-5D4F-4B20-BA93-E2F0727DF4EA} : C:\Users\Owner\Desktop\medieval2.exe [x] -> FOUND
[TASK][SUSP PATH] {C23C23E7-6DBE-4D7F-B587-A256D4083C8F} : C:\Users\David P\Desktop\wmpfirefoxplugin.exe [7] -> FOUND
[STARTUP][SUSP PATH] GameRanger.lnk @David : C:\Users\David P\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe [7] -> FOUND
[STARTUP][SUSP PATH] GameRanger.lnk @David P : C:\Users\David P\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe [7] -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: STM3250318AS ATA Device +++++
--- User ---
[MBR] 414b2dd44670912d08085945d08314cb
[BSP] d2bdd07840f6ee8bea85f8a37fa53a33 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 238372 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1]_S_02232013_02d1718.txt >>
RKreport[1]_S_02232013_02d1718.txt
I was suprised that my gaming software GameRanger had an issue because I use it to play games online with friends.
Finally the Fss.txt from Farbar Service Scanner showed this:
Farbar Service Scanner Version: 20-02-2013
Ran by David P (administrator) on 23-02-2013 at 17:21:11
Running from "C:\Users\David P\Downloads"
Windows 7 Home Premium Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to retrieve start type of wscsvc. The value does not exist.
Checking ImagePath: ATTENTION!=====> Unable to retrieve ImagePath of wscsvc. The value does not exist.
Unable to retrieve ServiceDll of wscsvc. The value does not exist.
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to retrieve start type of WinDefend. The value does not exist.
Checking ImagePath: ATTENTION!=====> Unable to retrieve ImagePath of WinDefend. The value does not exist.
Unable to retrieve ServiceDll of WinDefend. The value does not exist.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
Other Services:
==============
File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\ipnathlp.dll => MD5 is legit
C:\Windows\system32\iphlpsvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
**** End of log ****
Hope these two texts help.