[FONT=Courier New]DDS (Ver_2011-08-26.01) - NTFSx86 [/FONT]
[FONT=Courier New]Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.4.1[/FONT]
[FONT=Courier New]Run by Peter at 19:26:30 on 2012-05-26[/FONT]
[FONT=Courier New]Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2814.1061 [GMT -4:00][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]AV: Kaspersky Anti-Virus *Enabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}[/FONT]
[FONT=Courier New]SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}[/FONT]
[FONT=Courier New]SP: Kaspersky Anti-Virus *Enabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]============== Running Processes ===============[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]C:\Windows\system32\wininit.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\lsm.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k DcomLaunch[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k RPCSS[/FONT]
[FONT=Courier New]C:\Windows\system32\atiesrxx.exe[/FONT]
[FONT=Courier New]C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted[/FONT]
[FONT=Courier New]C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k netsvcs[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k LocalService[/FONT]
[FONT=Courier New]C:\Windows\system32\atieclxx.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k NetworkService[/FONT]
[FONT=Courier New]C:\Program Files\Common Files\SPBA\upeksvr.exe[/FONT]
[FONT=Courier New]c:\Program Files\Acer Bio Protection\CompPtcVUI.exe[/FONT]
[FONT=Courier New]C:\Windows\System32\spoolsv.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork[/FONT]
[FONT=Courier New]C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[/FONT]
[FONT=Courier New]C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[/FONT]
[FONT=Courier New]C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k HsfXAudioService[/FONT]
[FONT=Courier New]C:\Windows\System32\svchost.exe -k HPZ12[/FONT]
[FONT=Courier New]C:\Windows\System32\svchost.exe -k HPZ12[/FONT]
[FONT=Courier New]c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[/FONT]
[FONT=Courier New]c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k imgsvc[/FONT]
[FONT=Courier New]C:\Windows\system32\taskhost.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\Dwm.exe[/FONT]
[FONT=Courier New]C:\Windows\System32\svchost.exe -k secsvcs[/FONT]
[FONT=Courier New]C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[/FONT]
[FONT=Courier New]C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[/FONT]
[FONT=Courier New]C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[/FONT]
[FONT=Courier New]C:\Program Files\Acer Bio Protection\PdtWzd.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\SearchIndexer.exe[/FONT]
[FONT=Courier New]C:\Windows\System32\alg.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted[/FONT]
[FONT=Courier New]C:\Program Files\Launch Manager\LManager.exe[/FONT]
[FONT=Courier New]C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[/FONT]
[FONT=Courier New]C:\Program Files\Windows Media Player\wmpnetwk.exe[/FONT]
[FONT=Courier New]C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe[/FONT]
[FONT=Courier New]C:\Program Files\TechSmith\Jing\Jing.exe[/FONT]
[FONT=Courier New]C:\Users\Peter\Documents\AP_Rewards_AutoEARN\aanpt.exe[/FONT]
[FONT=Courier New]C:\Windows\System32\svchost.exe -k LocalServicePeerNet[/FONT]
[FONT=Courier New]C:\Users\Peter\Documents\AP_Rewards_AutoEARN\aanpp.exe[/FONT]
[FONT=Courier New]C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[/FONT]
[FONT=Courier New]C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\DllHost.exe[/FONT]
[FONT=Courier New]C:\Program Files\NoMoreTime\mbamservice.exe[/FONT]
[FONT=Courier New]C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[/FONT]
[FONT=Courier New]C:\Windows\Explorer.exe[/FONT]
[FONT=Courier New]C:\Program Files\Mozilla Firefox\firefox.exe[/FONT]
[FONT=Courier New]C:\Program Files\Mozilla Firefox\plugin-container.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\ctfmon.exe[/FONT]
[FONT=Courier New]C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe[/FONT]
[FONT=Courier New]C:\Program Files\Java\jre6\bin\java.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\conhost.exe[/FONT]
[FONT=Courier New]C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe[/FONT]
[FONT=Courier New]C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe[/FONT]
[FONT=Courier New]C:\Program Files\Mozilla Firefox\plugin-container.exe[/FONT]
[FONT=Courier New]C:\PROGRA~1\IZArc\IZArc.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\SearchProtocolHost.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\SearchFilterHost.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\DllHost.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\conhost.exe[/FONT]
[FONT=Courier New]C:\Windows\system32\wbem\wmiprvse.exe[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]============== Pseudo HJT Report ===============[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]uStart Page = hxxp://mls.gsmls.com/member/index.jsp[/FONT]
[FONT=Courier New]mStart Page = hxxp://
www.comcast.net/[/FONT]
[FONT=Courier New]mWindow Title = Windows Internet Explorer provided by Comcast[/FONT]
[FONT=Courier New]uInternet Settings,ProxyOverride = *.local[/FONT]
[FONT=Courier New]uURLSearchHooks: HiGames Toolbar: {64d23501-5195-4224-9446-e2b0fb64e859} - c:\program files\higames\tbHiGa.dll[/FONT]
[FONT=Courier New]mURLSearchHooks: HiGames Toolbar: {64d23501-5195-4224-9446-e2b0fb64e859} - c:\program files\higames\tbHiGa.dll[/FONT]
[FONT=Courier New]BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File[/FONT]
[FONT=Courier New]BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll[/FONT]
[FONT=Courier New]BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll[/FONT]
[FONT=Courier New]BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll[/FONT]
[FONT=Courier New]BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\ievkbd.dll[/FONT]
[FONT=Courier New]BHO: HiGames Toolbar: {64d23501-5195-4224-9446-e2b0fb64e859} - c:\program files\higames\tbHiGa.dll[/FONT]
[FONT=Courier New]BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll[/FONT]
[FONT=Courier New]BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll[/FONT]
[FONT=Courier New]BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll[/FONT]
[FONT=Courier New]BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll[/FONT]
[FONT=Courier New]BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL[/FONT]
[FONT=Courier New]BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll[/FONT]
[FONT=Courier New]BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\klwtbbho.dll[/FONT]
[FONT=Courier New]BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll[/FONT]
[FONT=Courier New]TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll[/FONT]
[FONT=Courier New]TB: HiGames Toolbar: {64d23501-5195-4224-9446-e2b0fb64e859} - c:\program files\higames\tbHiGa.dll[/FONT]
[FONT=Courier New]TB: A&P Rewards AutoEARN v1.0: {583f8e79-0a89-4eba-9de2-479e57f64506} - c:\users\peter\documents\ap_rewards_autoearn\aanpb.dll[/FONT]
[FONT=Courier New]uRun: [Jing] c:\program files\techsmith\jing\Jing.exe[/FONT]
[FONT=Courier New]uRun: [aanpm] "c:\users\peter\documents\ap_rewards_autoearn\aanpt.exe"[/FONT]
[FONT=Courier New]uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED[/FONT]
[FONT=Courier New]mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun[/FONT]
[FONT=Courier New]mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s[/FONT]
[FONT=Courier New]mRun: [VitaKeyPdtWzd] "c:\program files\acer bio protection\PdtWzd.exe"[/FONT]
[FONT=Courier New]mRun: [LManager] c:\program files\launch manager\LManager.exe[/FONT]
[FONT=Courier New]mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe[/FONT]
[FONT=Courier New]mRun: [Acer Assist Launcher] c:\program files\acer\acer assist\launcher.exe[/FONT]
[FONT=Courier New]mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"[/FONT]
[FONT=Courier New]mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2010\avp.exe"[/FONT]
[FONT=Courier New]mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"[/FONT]
[FONT=Courier New]mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"[/FONT]
[FONT=Courier New]mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"[/FONT]
[FONT=Courier New]mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices[/FONT]
[FONT=Courier New]mRun: [Malwarebytes' Anti-Malware] "c:\program files\nomoretime\mbamgui.exe" /starttray[/FONT]
[FONT=Courier New]mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"[/FONT]
[FONT=Courier New]mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)[/FONT]
[FONT=Courier New]mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)[/FONT]
[FONT=Courier New]mPolicies-system: EnableUIADesktopToggle = 0 (0x0)[/FONT]
[FONT=Courier New]mPolicies-system: DisableCAD = 1 (0x1)[/FONT]
[FONT=Courier New]IE: Append to existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html[/FONT]
[FONT=Courier New]IE: Convert link target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html[/FONT]
[FONT=Courier New]IE: Convert link target to existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html[/FONT]
[FONT=Courier New]IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html[/FONT]
[FONT=Courier New]IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000[/FONT]
[FONT=Courier New]IE: Free YouTube to Mp3 Converter - c:\users\peter\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm[/FONT]
[FONT=Courier New]IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html[/FONT]
[FONT=Courier New]IE: {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\program files\acer bio protection\PwdBank.exe[/FONT]
[FONT=Courier New]IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm[/FONT]
[FONT=Courier New]IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll[/FONT]
[FONT=Courier New]IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll[/FONT]
[FONT=Courier New]IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\klwtbbho.dll[/FONT]
[FONT=Courier New]IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL[/FONT]
[FONT=Courier New]IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\klwtbbho.dll[/FONT]
[FONT=Courier New]IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll[/FONT]
[FONT=Courier New]Trusted Zone: realtytools.com[/FONT]
[FONT=Courier New]Trusted Zone: toolkitcma.com[/FONT]
[FONT=Courier New]Trusted Zone: toolkitcma2.com[/FONT]
[FONT=Courier New]DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} - hxxp://www2.stlu.com/plugins/Plugin0501.0125/streetnoagent7.cab[/FONT]
[FONT=Courier New]DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab[/FONT]
[FONT=Courier New]DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} - hxxp://msx.mlxchange.com/5.5.07.24643/Control/IRCSharc.cab[/FONT]
[FONT=Courier New]DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab[/FONT]
[FONT=Courier New]DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://
www.superadblocker.com/activex/sabspx.cab[/FONT]
[FONT=Courier New]DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx[/FONT]
[FONT=Courier New]DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab[/FONT]
[FONT=Courier New]DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab[/FONT]
[FONT=Courier New]DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab[/FONT]
[FONT=Courier New]DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://sirva.webex.com/client/wbs27-vzbprodcn/nbr/ieatgpc1.cab[/FONT]
[FONT=Courier New]TCP: DhcpNameServer = 75.75.75.75 75.75.76.76[/FONT]
[FONT=Courier New]TCP: Interfaces\{CA7B98B4-C4D7-4F55-B82D-B7BDC61C4E3F} : DhcpNameServer = 75.75.75.75 75.75.76.76[/FONT]
[FONT=Courier New]TCP: Interfaces\{CA7B98B4-C4D7-4F55-B82D-B7BDC61C4E3F}\05E4A405 : DhcpNameServer = 192.168.126.1[/FONT]
[FONT=Courier New]TCP: Interfaces\{CA7B98B4-C4D7-4F55-B82D-B7BDC61C4E3F}\07E6A607 : DhcpNameServer = 192.168.126.1[/FONT]
[FONT=Courier New]TCP: Interfaces\{CA7B98B4-C4D7-4F55-B82D-B7BDC61C4E3F}\876696E696479777966696 : DhcpNameServer = 75.75.75.75 75.75.76.76[/FONT]
[FONT=Courier New]TCP: Interfaces\{E8231A03-DFF0-4AB2-A7B4-7FC36769BFC9} : DhcpNameServer = 75.75.75.75 75.75.76.76[/FONT]
[FONT=Courier New]Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll[/FONT]
[FONT=Courier New]Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\acer\acer vcm\Skype4COM.dll[/FONT]
[FONT=Courier New]Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll[/FONT]
[FONT=Courier New]Notify: klogon - c:\windows\system32\klogon.dll[/FONT]
[FONT=Courier New]Notify: spba - c:\program files\common files\spba\homefus2.dll[/FONT]
[FONT=Courier New]AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll c:\windows\system32\acaptuser32.dll[/FONT]
[FONT=Courier New]SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]================= FIREFOX ===================[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]FF - ProfilePath - c:\users\peter\appdata\roaming\mozilla\firefox\profiles\m4fqy7os.default\[/FONT]
[FONT=Courier New]FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=[/FONT]
[FONT=Courier New]FF - prefs.js: browser.startup.homepage - hxxp://
www.yahoo.com/[/FONT]
[FONT=Courier New]FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL[/FONT]
[FONT=Courier New]FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\adobe\acrobat 9.0\acrobat\air\nppdf32.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\mozilla firefox\plugins\npstm32.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\users\peter\appdata\roaming\mozilla\plugins\npatgpc.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\windows\system32\npDeployJava1.dll[/FONT]
[FONT=Courier New]FF - plugin: c:\windows\system32\npmproxy.dll[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]============= SERVICES / DRIVERS ===============[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880][/FONT]
[FONT=Courier New]R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2009-9-14 21520][/FONT]
[FONT=Courier New]R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872][/FONT]
[FONT=Courier New]R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656][/FONT]
[FONT=Courier New]R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128][/FONT]
[FONT=Courier New]R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928][/FONT]
[FONT=Courier New]R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-10-23 176128][/FONT]
[FONT=Courier New]R2 AVP;Kaspersky Anti-Virus;c:\program files\kaspersky lab\kaspersky anti-virus 2010\avp.exe [2009-10-20 340520][/FONT]
[FONT=Courier New]R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032][/FONT]
[FONT=Courier New]R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-5-31 260648][/FONT]
[FONT=Courier New]R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472][/FONT]
[FONT=Courier New]R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-12-3 22344][/FONT]
[FONT=Courier New]R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2009-5-7 52128][/FONT]
[FONT=Courier New]R3 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2009-5-7 42144][/FONT]
[FONT=Courier New]R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-10-23 27320][/FONT]
[FONT=Courier New]R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336][/FONT]
[FONT=Courier New]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384][/FONT]
[FONT=Courier New]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-29 257696][/FONT]
[FONT=Courier New]S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2009-10-23 29472][/FONT]
[FONT=Courier New]S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360][/FONT]
[FONT=Courier New]S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992][/FONT]
[FONT=Courier New]S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504][/FONT]
[FONT=Courier New]S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-20 52224][/FONT]
[FONT=Courier New]S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2009-7-13 17920][/FONT]
[FONT=Courier New]S4 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2009-10-6 24576][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]=============== Created Last 30 ================[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]2012-05-26 22:29:48 -------- d-----w- c:\program files\Oracle[/FONT]
[FONT=Courier New]2012-05-26 22:28:28 772504 ----a-w- c:\windows\system32\npDeployJava1.dll[/FONT]
[FONT=Courier New]2012-05-26 19:04:09 56200----a-w- c:\programdata\microsoft\windows defender\definition updates\{a98b41e2-3cd0-436e-857d-6c3f85b85985}\offreg.dll[/FONT]
[FONT=Courier New]2012-05-26 14:21:59 -------- d-s---w- C:\ComboFix29460C[/FONT]
[FONT=Courier New]2012-05-26 12:30:46 -------- d-----w- c:\program files\ESET[/FONT]
[FONT=Courier New]2012-05-26 12:29:08 25276----a-w- c:\windows\system32\1229858041.dll[/FONT]
[FONT=Courier New]2012-05-26 11:58:18 -------- d-sh--w- C:\$RECYCLE.BIN[/FONT]
[FONT=Courier New]2012-05-26 11:58:12 -------- d-----w- c:\users\peter\appdata\local\temp[/FONT]
[FONT=Courier New]2012-05-26 11:40:37 -------- d-----w- C:\ComboFix29482C[/FONT]
[FONT=Courier New]2012-05-26 11:34:12 -------- d-----w- C:\ComboFix231802C[/FONT]
[FONT=Courier New]2012-05-26 10:47:26 -------- d-----w- C:\ComboFix21380C[/FONT]
[FONT=Courier New]2012-05-25 12:00:58 -------- d-----w- C:\ComboFix2[/FONT]
[FONT=Courier New]2012-05-25 11:16:01 6737808 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{a98b41e2-3cd0-436e-857d-6c3f85b85985}\mpengine.dll[/FONT]
[FONT=Courier New]2012-05-17 11:42:16 -------- d-----w- c:\programdata\RemoteAutomator[/FONT]
[FONT=Courier New]2012-05-17 11:42:16 -------- d-----w- c:\program files\RemoteAutomator[/FONT]
[FONT=Courier New]2012-05-09 21:01:25 1291632 ----a-w- c:\windows\system32\drivers\tcpip.sys[/FONT]
[FONT=Courier New]2012-05-09 21:01:19 936960 ----a-w- c:\program files\common files\microsoft shared\ink\journal.dll[/FONT]
[FONT=Courier New]2012-05-09 21:01:18 1221632 ----a-w- c:\program files\windows journal\NBDoc.DLL[/FONT]
[FONT=Courier New]2012-05-09 21:01:17 989184 ----a-w- c:\program files\windows journal\JNTFiltr.dll[/FONT]
[FONT=Courier New]2012-05-09 21:01:17 969216 ----a-w- c:\program files\windows journal\JNWDRV.dll[/FONT]
[FONT=Courier New]2012-05-09 21:01:09 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe[/FONT]
[FONT=Courier New]2012-05-09 21:01:08 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe[/FONT]
[FONT=Courier New]2012-05-09 21:01:08 2343424 ----a-w- c:\windows\system32\win32k.sys[/FONT]
[FONT=Courier New]2012-05-09 21:01:00 56176----a-w- c:\windows\system32\drivers\partmgr.sys[/FONT]
[FONT=Courier New]2012-05-09 21:00:59 1077248 ----a-w- c:\windows\system32\DWrite.dll[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]==================== Find3M ====================[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]2012-05-05 10:39:09 70304----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl[/FONT]
[FONT=Courier New]2012-05-05 10:39:09 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe[/FONT]
[FONT=Courier New]2012-04-04 22:47:02 687504 ----a-w- c:\windows\system32\deployJava1.dll[/FONT]
[FONT=Courier New]2012-04-04 19:56:40 22344----a-w- c:\windows\system32\drivers\mbam.sys[/FONT]
[FONT=Courier New]2012-03-26 14:00:41 112056 ----a-w- c:\windows\system32\acaptuser32.dll[/FONT]
[FONT=Courier New]2012-03-01 05:46:57 19824----a-w- c:\windows\system32\drivers\fs_rec.sys[/FONT]
[FONT=Courier New]2012-03-01 05:37:41 172544 ----a-w- c:\windows\system32\wintrust.dll[/FONT]
[FONT=Courier New]2012-03-01 05:33:23 159232 ----a-w- c:\windows\system32\imagehlp.dll[/FONT]
[FONT=Courier New]2012-03-01 05:29:16 5120----a-w- c:\windows\system32\wmi.dll[/FONT]
[FONT=Courier New]2012-02-28 01:18:55 1799168 ----a-w- c:\windows\system32\jscript9.dll[/FONT]
[FONT=Courier New]2012-02-28 01:11:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl[/FONT]
[FONT=Courier New]2012-02-28 01:11:07 1127424 ----a-w- c:\windows\system32\wininet.dll[/FONT]
[FONT=Courier New]2012-02-28 01:03:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb[/FONT]
[FONT=Courier New]2011-02-27 00:14:39 7808600 ----a-w- c:\program files\PowerPack3.exe[/FONT]
[FONT=Courier New]2011-02-27 00:13:20 5404768 ----a-w- c:\program files\RegCleaner603.exe[/FONT]
[FONT=Courier New]2010-08-19 16:59:19 197632 ----a-w- c:\program files\common files\OnlineFilesManager.dll[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]============= FINISH: 19:28:23.83 ===============[/FONT]
[FONT=Courier New] [/FONT]