Solved Google Redirection, BSODs on some full system scans

Status
Not open for further replies.

AlexG2490

Posts: 18   +0
Hey there everyone! Boy am I getting tired of these insidious viruses. Remember when virus removal was as simple as running Norton or McAfee? Now it seems like everything you get requires expert help. Fortunately, there are indeed experts, like all of you! Consider this my thanks in advance for whoever can help me get rid of this one.

I've run an AVG antivirus scan, MBAM scan, and an AdAware scan on my machine prior to coming here for help. That cleaned up a lot of sludge - about 18 infections that MBAM found over the past 3 scans - but I'm still having redirection from Google. When I tried to run full system scans, 3 out of 4 times the scan would complete halfway, then result in a BSOD - either "MEMORY_MANAGEMENT" or "IRQL_NOT_LESS_OR_EQUAL". This has occurred in both normal mode and Safe mode. The full MBAM scan was finally completed in safe mode; I have not been able to successfully complete a full AdAware scan, only a quick scan. The AVG scan does not even complete a "Scan specific files or folders" scan, so I do not have an antivirus log. Seems like this little bug will go to some extreme lengths to keep itself from being found.

Anyway, before I post the logs, here's the checklist I followed from the stickied thread - I did have one question to clear up meaning I may have done one of the scans wrong.

  1. 1. Antivirus Software - Check!*
  2. 2. TFC - Check!
  3. 3. MBAM - Check!**
  4. 4. GMER - ????
  5. 5. DDS - Check!

*I'm using AVG but can switch to Avira or Avast if those are more highly recommended. Cannot complete a scan but have tried in normal and safe modes.
**My log since starting the 8-step process on this forum had nothing in it. However, I had run MBAM previously the last couple of days in order to try to clear this up on my own, so I will attach those logs at the end of this post.
***I disabled protection from AdAware, and followed these instructions to disable AVG: http://www.ehow.com/how_5052104_disable-avg-antivirus.html. However, my log is quite short and references AVG, so I may have done this incorrectly. My apologies if that is the case.

Here are the requested logs.
MBAM:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5557

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18865

1/20/2011 8:17:36 PM
mbam-log-2011-01-20 (20-17-36).txt

Scan type: Quick scan
Objects scanned: 175706
Time elapsed: 10 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

GMER:
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-01-20 20:25:35
Windows 6.0.6001 Service Pack 1 Harddisk0\DR0 -> \Device\00000032 WDC_WD16 rev.08.0
Running: 90gplgzd.exe; Driver: C:\Users\Alex\AppData\Local\Temp\kxldrpog.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\tdx \Device\Ip avgtdix.sys (AVG Network connection

watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection

watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection

watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection

watcher/AVG Technologies CZ, s.r.o.)

Device \Device\00000061 -> \??\SCSI#Disk&Ven_WDC_WD16&Prod_00JB-00GVC0#4&3bad3e4&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

---- EOF - GMER 1.0.15 ----

DDS Attach:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-12-12.02)

Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 8/15/2009 10:18:34 PM
System Uptime: 1/20/2011 8:27:17 PM (0 hours ago)

Motherboard: ECS-USA | | GeForce6100PM-M2
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ | Socket AM2 | 2600/201mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 30.673 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 466 GiB total, 291.381 GiB free.
G: is FIXED (NTFS) - 466 GiB total, 274.972 GiB free.
I: is FIXED (NTFS) - 1863 GiB total, 918.367 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Belkin Wireless G Desktop Card
Device ID: PCI\VEN_1799&DEV_700F&SUBSYS_700F1799&REV_20\4&2CF26B65&0&3020
Manufacturer: Belkin Corporation
Name: Belkin Wireless G Desktop Card
PNP Device ID: PCI\VEN_1799&DEV_700F&SUBSYS_700F1799&REV_20\4&2CF26B65&0&3020
Service: BLKWGDv8

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

TWiT TV
"Champetre" template for ConvertXToDVD 3
"Christmas" template for ConvertXToDVD 3
"Film" template for ConvertXToDVD 3
Über Jedi Mod Manager
ABC Amber LIT Converter
Ad-Aware
Add or Remove Adobe Creative Suite 3 Master Collection
Adobe Acrobat 8 Professional
Adobe Acrobat 8.1.3 Professional
Adobe After Effects CS3
Adobe After Effects CS3 Presets
Adobe After Effects CS3 Third Party Content
Adobe AIR
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe BridgeTalk Plugin CS3
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Contribute CS3
Adobe Creative Suite 3 Master Collection
Adobe Default Language CS3
Adobe Device Central CS3
Adobe Dreamweaver CS3
Adobe Encore CS3
Adobe Encore CS3 Codecs
Adobe ExtendScript Toolkit 2
Adobe Extension Manager CS3
Adobe Fireworks CS3
Adobe Flash CS3
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Flash Video Encoder
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe InDesign CS3
Adobe InDesign CS3 Icon Handler
Adobe Linguistics CS3
Adobe MotionPicture Color Files
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Premiere Pro CS3
Adobe Premiere Pro CS3 Functional Content
Adobe Premiere Pro CS3 Third Party Content
Adobe Setup
Adobe Shockwave Player 11.5
Adobe SING CS3
Adobe Soundbooth CS3
Adobe Soundbooth CS3 Codecs
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe Version Cue CS3 Server
Adobe Video Profiles
Adobe WAS CS3
Adobe WinSoft Linguistics Plugin
Adobe XMP DVA Panels CS3
Adobe XMP Panels CS3
AHV content for Acrobat and Flash
AIM 7
Aimersoft Video Studio Express(Build 1.2.0.25)
Air Video Server 2.4.1
AJScreensaver
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Audacity 1.2.6
AudibleManager
AudioShell 1.3.5
Audiosurf
Auto Gordian Knot 2.55
AVG Free 9.0
AviSynth 2.5
Barnes & Noble Desktop Reader
Battlefield 2 Complete Collection
Battlefield 2142
Beyond the Red Line
BIMP Lite 1.62
BioShock 2
BitTorrent
Black and White
BlockCAD 3.19
Bonjour
Call of Duty 4: Modern Warfare
CamStudio
Camtasia Studio 6
Celestia 1.6.0
Comparator
Convert Doc
ConvertXtoDVD 3.8.0.193f
CPUID CPU-Z 1.55
Crysis(R)
dBpowerAMP Music Converter
Descent and Descent 2
Descent Manager Tools
Doctor Who - The Adventure Games 3.0
Download Manager 2.3.9
Download Updater (AOL LLC)
DVD Decrypter (Remove Only)
DVD Shrink 3.2
EA Download Manager
Easy Video Splitter 1.28
Enemy Territory - Quake Wars(TM)
ESET Online Scanner v3
Evernote
Far Cry
FeedForAll v2.0
FileZilla Client 3.3.4.1
Flash Slideshow Maker Pro 5.00
Fraps (remove only)
Free M4a to MP3 Converter 6.1
FreeSpace 2
GameShadow
GameSpy Arcade
GameSpy Comrade
Garry's Mod
GOG.com Downloader
GoldWave v5.22
GoldWave v5.52
Google Chrome
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
Graphing Calculator 3D 3.1
Half-Life
Half-Life: Blue Shift
HandBrake 0.9.3
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hoyle Casino
ImgBurn
iPhone Configuration Utility
iTunes
Java(TM) 6 Update 17
Jeopardy! 2003
Knight
LAME v3.98.2 for Audacity
Left 4 Dead
Left 4 Dead 2
Logitech QuickCam
Logitech QuickCam Driver Package
LucasArts' Jedi Knight
LucasArts' X-Wing Alliance
Malwarebytes' Anti-Malware
MechWarrior 3
MechWarrior 3 Pirate's Moon
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 3.5 SP1
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Visio MUI (English) 2007
Microsoft Office Visio Professional 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Mozilla Firefox (3.5.11)
NET Installation Assistance for VB6 App (Runtime Only)
Notepad++
NVIDIA Drivers
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
OpenAL
Opposing Force
PageNest
Pamela Pro 4.6
PDF Settings
Peggle Deluxe 1.0
Photo Story 3 for Windows
Poker Night at the Inventory
Portal
PowerISO
Pradis 6: Understanding the Bible Library 6.0
Prey
Psychonauts
PunkBuster Services
QuickTime
Realtek High Definition Audio Driver
Safari
Scrabble 2
Scrivener for Windows Beta
SecondLife (remove only)
SecondLifeViewer2 (remove only)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Silent Hunter III
Silent Hunter Wolves of the Pacific
Skype Toolbars
Skype™ 5.0
Space Quest Collection(TM)
SpaceBattle ScreenSaver 3.1
SpeedFan (remove only)
Spybot - Search & Destroy
Star Trek Elite Force II
Star Trek Legacy
Star Trek: Armada
Star Wars Battlefront
Star Wars Empire at War
Star Wars Empire at War Forces of Corruption
Star Wars Jedi Knight: Mysteries of the Sith
Star Wars JK II Jedi Outcast
Star Wars Knights of the Old Republic
Star Wars Republic Commando
Star Wars Starfighter
Starcraft
Steam
Subtitle Workshop 2.51
SUPERAntiSpyware Free Edition
System Requirements Lab
Tag - IGF Professional 2008
TalkShoe Live! 2.0
Tardis Screensaver- Widescreen
The Sims Complete Collection
TightVNC 2.0.2
TortoiseSVN 1.6.7.18415 (32 bit)
TweetDeck
TWiT Live Desktop
Ultimate Extras sounds from Microsoft® Tinker™
UltraLott Powerball and Mega Millions 1.2.6
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb976884)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 1.0.1
VobSub v2.23 (Remove Only)
WAV to MP3 Encoder
Winamp
Winamp Detector Plug-in
WinDirStat 1.1.2
Windows Sound Schemes
WinHTTrack Website Copier 3.43-9C
WinPatrol
WinRAR archiver
WordWeb
Xfire (remove only)
XfireXO Toolbar
XviD MPEG4 Video Codec (remove only)
Yahoo! Messenger

==== Event Viewer Messages From Past Week ========

1/20/2011 8:28:18 PM, Error: EventLog [6008] - The previous system shutdown at 8:22:19 PM on 1/20/2011 was unexpected.
1/20/2011 7:58:34 PM, Error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
1/20/2011 7:58:34 PM, Error: Service Control Manager [7031] - The TightVNC Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action

will be taken in 5000 milliseconds: Restart the service.
1/20/2011 7:41:57 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
1/20/2011 7:35:52 PM, Error: EventLog [6008] - The previous system shutdown at 7:16:08 PM on 1/20/2011 was unexpected.
1/20/2011 1:08:00 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service winmgmt with arguments "" in order to run the

server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
1/19/2011 8:52:20 PM, Error: EventLog [6008] - The previous system shutdown at 8:47:24 PM on 1/19/2011 was unexpected.
1/19/2011 8:14:37 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the

server: {9E175B6D-F52A-11D8-B9A5-505054503030}
1/19/2011 8:13:56 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the

server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
1/19/2011 8:13:56 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the

server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
1/19/2011 8:13:56 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the

server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
1/19/2011 8:13:48 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the

server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
1/19/2011 8:13:37 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run

the server: {DD522ACC-F821-461A-A407-50B198B896DC}
1/19/2011 8:13:34 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX CSC DfsC

i8042prt NetBIOS netbt nsiproxy PSched RasAcd rdbss SASDIFSV SASKUTIL SCDEmu Smb spldr tdx Wanarpv6
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of

the following error: The dependency service or group failed to start.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed

to start because of the following error: A device attached to the system is not functioning.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the

following error: The dependency service or group failed to start.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to

start because of the following error: A device attached to the system is not functioning.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which

failed to start because of the following error: A device attached to the system is not functioning.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to

start because of the following error: The dependency service or group failed to start.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to

start because of the following error: The dependency service or group failed to start.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because

of the following error: A device attached to the system is not functioning.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to

start because of the following error: The dependency service or group failed to start.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because

of the following error: The dependency service or group failed to start.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The Network Connections service depends on the Network Store Interface Service service which failed to start

because of the following error: The dependency service or group failed to start.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the

following error: The dependency service or group failed to start.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the

following error: A device attached to the system is not functioning.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start

because of the following error: A device attached to the system is not functioning.
1/19/2011 8:13:34 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error:

The dependency service or group failed to start.
1/19/2011 8:13:29 PM, Error: Microsoft-Windows-TerminalServices-LocalSessionManager [1048] - Terminal Service start failed. The relevant status code was This service cannot be

started in Safe Mode .
1/19/2011 8:13:29 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TermService with arguments "" in order to run the

server: {F9A874B6-F8A8-4D73-B5A8-AB610816828B}
1/19/2011 8:13:19 PM, Error: EventLog [6008] - The previous system shutdown at 8:09:18 PM on 1/19/2011 was unexpected.
1/19/2011 8:11:47 PM, Error: Service Control Manager [7034] - The LVCOMSer service terminated unexpectedly. It has done this 1 time(s).
1/19/2011 8:11:30 PM, Error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s).

The following corrective action will be taken in 30000 milliseconds: Restart the service.
1/19/2011 8:08:11 PM, Error: Service Control Manager [7001] - The SBSD Security Center Service service depends on the Security Center service which failed to start because of

the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
1/19/2011 8:07:32 PM, Error: EventLog [6008] - The previous system shutdown at 7:40:08 PM on 1/19/2011 was unexpected.
1/19/2011 12:09:34 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected

termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
1/19/2011 12:09:33 AM, Error: Service Control Manager [7022] - The Server service hung on starting.
1/19/2011 12:09:33 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error:

After starting, the service hung in a start-pending state.
1/19/2011 12:06:44 AM, Error: Service Control Manager [7023] - The Server service terminated with the following error: Not enough server storage is available to process this

command.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action

will be taken in 60000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The

following corrective action will be taken in 120000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective

action will be taken in 120000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be

taken in 60000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Terminal Services Configuration service terminated unexpectedly. It has done this 1 time(s). The following

corrective action will be taken in 60000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action

will be taken in 60000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The

following corrective action will be taken in 120000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following

corrective action will be taken in 60000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be

taken in 60000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Secondary Logon service terminated unexpectedly. It has done this 1 time(s). The following corrective

action will be taken in 120000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Remote Access Connection Manager service terminated unexpectedly. It has done this 1 time(s). The following

corrective action will be taken in 120000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following

corrective action will be taken in 120000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will

be taken in 120000 milliseconds: Restart the service.
1/19/2011 12:06:05 AM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The

following corrective action will be taken in 120000 milliseconds: Restart the service.
1/19/2011 11:19:22 PM, Error: EventLog [6008] - The previous system shutdown at 11:16:22 PM on 1/19/2011 was unexpected.
1/19/2011 1:26:22 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected

termination of the Remote Access Connection Manager service, but this action failed with the following error: An instance of the service is already running.
1/19/2011 1:23:22 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected

termination of the Background Intelligent Transfer Service service, but this action failed with the following error: An instance of the service is already running.
1/15/2011 8:58:18 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
1/15/2011 8:58:18 PM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the

start or control request in a timely fashion.
1/15/2011 8:48:56 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt
1/15/2011 8:44:25 PM, Error: nvstor32 [5] - A parity error was detected on \Device\RaidPort1.

==== End Of File ===========================

DDS:
DDS (Ver_10-12-12.02) - NTFSx86
Run by Alex at 20:36:28.75 on Thu 01/20/2011
Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.2046.796 [GMT -7:00]

AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {DAAC1C79-1A96-9DFE-FC4C-6940214C33E6}
AV: AVG Anti-Virus Free *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TightVNC\tvnserver.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\TightVNC\tvnserver.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\AirVideoServer\AirVideoServer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Alex\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - c:\program files\xfirexo\tbXfir.dll
mURLSearchHooks: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - c:\program files\xfirexo\tbXfir.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - c:\program files\xfirexo\tbXfir.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
TB: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - c:\program files\xfirexo\tbXfir.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [AirVideoServer] c:\program files\airvideoserver\AirVideoServer.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [<NO NAME>]
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [tvncontrol] "c:\program files\tightvnc\tvnserver.exe" -controlservice -slave
StartupFolder: c:\users\alex\appdata\roaming\micros~1\windows\startm~1\programs\startup\wordweb.lnk - c:\program files\wordweb\wweb32.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: SoftwareSASGeneration = 1 (0x1)
IE: Add to Evernote - e:\program files\evernote\evernote3\enbar.dll/2000
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {E0B8C461-F8FB-49b4-8373-FE32E9252800} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEE1} - e:\program files\evernote\evernote3\enbar.dll
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
TCP: {45B82F13-8CAA-44B2-A0BF-232ABD77AF8C} = 68.87.85.102,68.87.69.150
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
AppInit_DLLs: c:\windows\system32\avgrsstx.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
mASetup: {7070D8E0-650A-46b3-B03C-9497582E6A74} - %SystemRoot%\system32\soundschemes.exe /AddRegistration
mASetup: {B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24} - %SystemRoot%\system32\soundschemes2.exe /AddRegistration

================= FIREFOX ===================

FF - ProfilePath - c:\users\alex\appdata\roaming\mozilla\firefox\profiles\14mmi5nt.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&q=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\14mmi5nt.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\14mmi5nt.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: e:\program files\download manager\npfpdlm.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npwachk.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - e:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - e:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - e:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Multi Links: multilinks@plugin - %profile%\extensions\multilinks@plugin
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - %profile%\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation

foundation\DotNetAssistantExtension
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg9\Firefox

---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-7-26 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-12-19 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-12-19 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-12-19 243024]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-12-16 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-12-16 74480]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-15 308136]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-9-25 20328]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-7-12 1402272]
R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-7-14 239648]
R2 tvnserver;TightVNC Server;c:\program files\tightvnc\tvnserver.exe [2010-7-8 815704]
S2 gupdate1ca1ebe79c66296;Google Update Service (gupdate1ca1ebe79c66296);c:\program files\google\update\GoogleUpdate.exe [2009-8-16 133104]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-12-21 1153368]
S3 BLKWGDv8;Belkin Wireless G Desktop Card Service v8;c:\windows\system32\drivers\BLKWGDv8.sys [2006-11-18 312832]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-12-16 7408]

=============== Created Last 30 ================

2011-01-19 04:55:54 98304 --sha-r- c:\windows\system32\FXSCOVERS.dll
2011-01-19 04:55:30 -------- d-----w- c:\users\alex\appdata\roaming\0AA35AA340E408D76C950D7A0C838F79
2011-01-19 04:35:59 -------- d-----w- c:\program files\Aimersoft
2011-01-19 04:06:28 -------- d-----w- c:\program files\Easy Video Splitter
2011-01-18 03:33:43 -------- d-----w- c:\program files\SpaceBattle ScreenSaver
2011-01-12 04:15:40 -------- d-----w- C:\wav2voc
2011-01-09 08:09:21 -------- d-----w- C:\bmpdf
2011-01-08 21:53:13 -------- d-----w- c:\windows\system32\Adobe
2011-01-08 18:14:34 -------- d-----w- C:\WDFUSE
2010-12-29 05:37:59 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-12-25 04:23:44 -------- d--h--w- c:\windows\PIF

==================== Find3M ====================

2010-11-28 05:12:15 4252 ----a-w- c:\windows\warp1px.drv
2010-11-18 04:56:10 234536 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-11-18 04:36:14 234536 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-10-29 05:35:43 139152 ----a-w- c:\users\alex\appdata\roaming\PnkBstrK.sys

=================== ROOTKIT ====================

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6001 Disk: WDC_WD16 rev.08.0 -> Harddisk0\DR0 -> \Device\00000061

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x8698D555]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x869937b0]; MOV EAX, [0x8699382c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI;

JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x820FDF6F] -> \Device\Harddisk0\DR0[0x864F7AC8]
3 CLASSPNP[0x883C8745] -> ntkrnlpa!IofCallDriver[0x820FDF6F] -> [0x85657700]
5 acpi[0x8260E6A0] -> ntkrnlpa!IofCallDriver[0x820FDF6F] -> [0x84876030]
\Driver\nvstor32[0x866FD1D8] -> IRP_MJ_CREATE -> 0x8698D555
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX,

0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
detected disk devices:
\Device\00000060 -> \??\SCSI#Disk&Ven_WDC_WD16&Prod_00JB-00GVC0#4&3bad3e4&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 312581806 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.

============= FINISH: 20:37:21.02 ===============

And as promised, my MBAM logs that actually removed things.

Earlier today:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5557

Windows 6.0.6001 Service Pack 1 (Safe Mode)
Internet Explorer 8.0.6001.18865

1/20/2011 6:28:37 PM
mbam-log-2011-01-20 (18-28-37).txt

Scan type: Full scan (C:\|E:\|G:\|I:\|)
Objects scanned: 706072
Time elapsed: 1 hour(s), 44 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Alex\AppData\Roaming\0aa35aa340e408d76c950d7a0c838f79\bootmdlink700sys.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Alex\AppData\Roaming\bc3fc61ebd2390be003660698b68eba6\releaseversion70700.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
g:\!!!Final\installers\convertxtodvd 3\convertxtodvd.v3.x-keygen_brd\Keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
g:\!!!Final\installers\feedforall\feedforall.v2.0.2.9.patch.by.foff\nfo viewer.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\Windows\temp\0.3673486574633026.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\temp\0.9723782123328527.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
 
And two MBAM logs from yesterday:

Yesterday night:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5557

Windows 6.0.6001 Service Pack 1 (Safe Mode)
Internet Explorer 8.0.6001.18865

1/19/2011 9:37:32 PM
mbam-log-2011-01-19 (21-37-32).txt

Scan type: Quick scan
Objects scanned: 173471
Time elapsed: 3 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Alex\AppData\Local\temp\erasmwnxoc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Alex\AppData\Local\temp\oracwsnmxe.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Alex\AppData\Local\temp\rcsewonxam.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Users\Alex\AppData\Local\temp\rsnmxcwoea.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Alex\AppData\Local\temp\wnroxamecs.exe (Rootkit.Dropper) -> Quarantined and deleted successfully.
c:\Windows\temp\pohe\setup.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Yesterday Morning:
Malwarebytes' Anti-Malware 1.42
Database version: 3405
Windows 6.0.6001 Service Pack 1 (Safe Mode)
Internet Explorer 8.0.6001.18865

1/19/2011 8:21:20 PM
mbam-log-2011-01-19 (20-21-20).txt

Scan type: Quick Scan
Objects scanned: 111132
Time elapsed: 5 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Alex\AppData\Local\temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\temp\0.4679953916275831.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\temp\0.8070519814915187.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
 
Welcome aboard
yahooo.gif


Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running tools or applying updates other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

=======================================================================

You're infected with a rootkit, to start with....

Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
 
I did the scan twice. The first time it found an infection but the computer bluescreened when I clicked the "Restart Now" button. This was not an issue the second time. Both logs are below. Google is still redirecting.

EDIT: I meant to ask... your instructions say to avoid running any tools or updates other than those you suggest; does that mean I need to disable automatic Windows Updates for now? Do I need to go a step further still and cease use of my computer until we have it cleaned? Should it be disconnected from the network when not in use?

First Scan
2011/01/21 21:13:17.0977 TDSS rootkit removing tool 2.4.14.0 Jan 18 2011 09:33:51
2011/01/21 21:13:17.0977 ================================================================================
2011/01/21 21:13:17.0977 SystemInfo:
2011/01/21 21:13:17.0977
2011/01/21 21:13:17.0977 OS Version: 6.0.6001 ServicePack: 1.0
2011/01/21 21:13:17.0977 Product type: Workstation
2011/01/21 21:13:17.0977 ComputerName: ALEX-PC
2011/01/21 21:13:17.0977 UserName: Alex
2011/01/21 21:13:17.0977 Windows directory: C:\Windows
2011/01/21 21:13:17.0977 System windows directory: C:\Windows
2011/01/21 21:13:17.0977 Processor architecture: Intel x86
2011/01/21 21:13:17.0978 Number of processors: 2
2011/01/21 21:13:17.0978 Page size: 0x1000
2011/01/21 21:13:17.0978 Boot type: Normal boot
2011/01/21 21:13:17.0978 ================================================================================
2011/01/21 21:13:36.0830 Initialize success
2011/01/21 21:13:46.0929 ================================================================================
2011/01/21 21:13:46.0929 Scan started
2011/01/21 21:13:46.0929 Mode: Manual;
2011/01/21 21:13:46.0929 ================================================================================
2011/01/21 21:13:47.0378 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
2011/01/21 21:13:47.0461 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/01/21 21:13:47.0539 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/01/21 21:13:47.0688 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/01/21 21:13:47.0740 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/01/21 21:13:47.0807 AFD (763e172a55177e478cb419f88fd0ba03) C:\Windows\system32\drivers\afd.sys
2011/01/21 21:13:47.0868 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/01/21 21:13:47.0917 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/01/21 21:13:47.0976 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/01/21 21:13:48.0016 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/01/21 21:13:48.0067 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/01/21 21:13:48.0119 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/01/21 21:13:48.0160 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2011/01/21 21:13:48.0238 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/01/21 21:13:48.0308 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/01/21 21:13:48.0385 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/01/21 21:13:48.0438 atapi (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys
2011/01/21 21:13:48.0580 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\Windows\System32\Drivers\avgldx86.sys
2011/01/21 21:13:48.0629 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\Windows\System32\Drivers\avgmfx86.sys
2011/01/21 21:13:48.0705 AvgTdiX (22e3b793c3e61720f03d3a22351af410) C:\Windows\System32\Drivers\avgtdix.sys
2011/01/21 21:13:48.0770 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/01/21 21:13:48.0850 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/01/21 21:13:48.0965 BLKWGDv8 (e4074a8efc2693d5541633529ef6beeb) C:\Windows\system32\DRIVERS\BLKWGDv8.sys
2011/01/21 21:13:49.0016 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2011/01/21 21:13:49.0066 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/01/21 21:13:49.0116 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/01/21 21:13:49.0189 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/01/21 21:13:49.0243 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/01/21 21:13:49.0296 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/01/21 21:13:49.0348 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/01/21 21:13:49.0425 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/01/21 21:13:49.0517 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/01/21 21:13:49.0625 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys
2011/01/21 21:13:49.0675 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/01/21 21:13:49.0732 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys
2011/01/21 21:13:49.0787 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/01/21 21:13:49.0814 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
2011/01/21 21:13:49.0877 cpuz134 (75fa19142531cbf490770c2988a7db64) C:\Windows\system32\drivers\cpuz134_x32.sys
2011/01/21 21:13:49.0904 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/01/21 21:13:49.0951 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/01/21 21:13:50.0026 CSC (9a5434125c3dfe42393de4bbb791bd19) C:\Windows\system32\drivers\csc.sys
2011/01/21 21:13:50.0103 DfsC (9e635ae5e8ad93e2b5989e2e23679f97) C:\Windows\system32\Drivers\dfsc.sys
2011/01/21 21:13:50.0149 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys
2011/01/21 21:13:50.0227 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/01/21 21:13:50.0303 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys
2011/01/21 21:13:50.0353 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/01/21 21:13:50.0419 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys
2011/01/21 21:13:50.0494 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/01/21 21:13:50.0613 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/01/21 21:13:50.0668 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys
2011/01/21 21:13:50.0715 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys
2011/01/21 21:13:50.0772 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/01/21 21:13:50.0811 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/01/21 21:13:50.0846 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/01/21 21:13:50.0925 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/01/21 21:13:50.0955 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys
2011/01/21 21:13:50.0998 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/01/21 21:13:51.0021 fvevol (1400c747e2b73966b100fdce5426b7b2) C:\Windows\system32\DRIVERS\fvevol.sys
2011/01/21 21:13:51.0061 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/01/21 21:13:51.0149 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/01/21 21:13:51.0201 giveio (77ebf3e9386daa51551af429052d88d0) C:\Windows\system32\giveio.sys
2011/01/21 21:13:51.0283 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
2011/01/21 21:13:51.0359 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/01/21 21:13:51.0423 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/01/21 21:13:51.0470 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/01/21 21:13:51.0508 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/01/21 21:13:51.0561 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys
2011/01/21 21:13:51.0614 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/01/21 21:13:51.0671 HTTP (33b02459e86d0a2b86a6b9fe19139390) C:\Windows\system32\drivers\HTTP.sys
2011/01/21 21:13:51.0728 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/01/21 21:13:51.0775 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/01/21 21:13:51.0825 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/01/21 21:13:51.0889 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/01/21 21:13:52.0039 IntcAzAudAddService (4de88b49c891f45cd9ea6d83a341d3e3) C:\Windows\system32\drivers\RTKVHDA.sys
2011/01/21 21:13:52.0208 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/01/21 21:13:52.0244 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/01/21 21:13:52.0300 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/01/21 21:13:52.0382 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/01/21 21:13:52.0418 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/01/21 21:13:52.0480 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/01/21 21:13:52.0516 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/01/21 21:13:52.0626 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/01/21 21:13:52.0659 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/01/21 21:13:52.0689 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/01/21 21:13:52.0723 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/01/21 21:13:52.0758 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/01/21 21:13:52.0838 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys
2011/01/21 21:13:52.0927 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys
2011/01/21 21:13:52.0970 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/01/21 21:13:53.0103 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/01/21 21:13:53.0155 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/01/21 21:13:53.0205 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/01/21 21:13:53.0244 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/01/21 21:13:53.0365 LVcKap (8113133ec42dd6c566908008ce913edd) C:\Windows\system32\DRIVERS\LVcKap.sys
2011/01/21 21:13:53.0525 LVMVDrv (0dd5b8af4917a2821047450195c511b3) C:\Windows\system32\DRIVERS\LVMVDrv.sys
2011/01/21 21:13:53.0678 LVPr2Mon (406b1d186f75b4b4832d6237859e1b00) C:\Windows\system32\DRIVERS\LVPr2Mon.sys
2011/01/21 21:13:53.0732 LVUSBSta (be5e104be263921d6842c555db6a5c23) C:\Windows\system32\drivers\LVUSBSta.sys
2011/01/21 21:13:53.0793 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/01/21 21:13:53.0842 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/01/21 21:13:53.0919 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/01/21 21:13:53.0969 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/01/21 21:13:53.0999 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/01/21 21:13:54.0031 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/01/21 21:13:54.0062 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/01/21 21:13:54.0107 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/01/21 21:13:54.0147 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/01/21 21:13:54.0202 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/01/21 21:13:54.0230 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys
2011/01/21 21:13:54.0274 mrxsmb (c4ad205530888404e2b5fc8d9319b119) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/01/21 21:13:54.0329 mrxsmb10 (0a986b34f1678a2697574d7b1664e2dd) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/01/21 21:13:54.0356 mrxsmb20 (3268b8c3fa92bfc086355c39b45e9cc9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/01/21 21:13:54.0392 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/01/21 21:13:54.0433 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/01/21 21:13:54.0479 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/01/21 21:13:54.0509 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/01/21 21:13:54.0630 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/01/21 21:13:54.0668 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/01/21 21:13:54.0716 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/01/21 21:13:54.0755 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys
2011/01/21 21:13:54.0795 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/01/21 21:13:54.0840 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/01/21 21:13:54.0882 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys
2011/01/21 21:13:54.0956 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys
2011/01/21 21:13:55.0014 NDIS (9bdc71790fa08f0a0b5f10462b1bd0b1) C:\Windows\system32\drivers\ndis.sys
2011/01/21 21:13:55.0053 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/01/21 21:13:55.0089 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/01/21 21:13:55.0129 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/01/21 21:13:55.0160 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/01/21 21:13:55.0191 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/01/21 21:13:55.0226 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys
2011/01/21 21:13:55.0294 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/01/21 21:13:55.0333 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys
2011/01/21 21:13:55.0360 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/01/21 21:13:55.0421 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys
2011/01/21 21:13:55.0487 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/01/21 21:13:55.0525 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/01/21 21:13:55.0699 NVENETFD (d958a2b5f6ad5c3b8ccdc4d7da62466c) C:\Windows\system32\DRIVERS\nvmfdx32.sys
2011/01/21 21:13:56.0017 nvlddmkm (e572ebf0a86a76e7cfcaab00648f0f83) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/01/21 21:13:56.0284 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/01/21 21:13:56.0307 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/01/21 21:13:56.0360 nvstor32 (8ee374b6fb3cb2bb8d70395218b464a5) C:\Windows\system32\DRIVERS\nvstor32.sys
2011/01/21 21:13:56.0412 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/01/21 21:13:56.0515 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
2011/01/21 21:13:56.0677 Parport (8a79fdf04a73428597e2caf9d0d67850) C:\Windows\system32\DRIVERS\parport.sys
2011/01/21 21:13:56.0709 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys
2011/01/21 21:13:56.0738 Parvdm (6c580025c81caf3ae9e3617c22cad00e) C:\Windows\system32\DRIVERS\parvdm.sys
2011/01/21 21:13:56.0775 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys
2011/01/21 21:13:56.0817 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/01/21 21:13:56.0853 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/01/21 21:13:56.0919 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys
2011/01/21 21:13:56.0990 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/01/21 21:13:57.0143 PID_PEPI (0da6c5e0c8da6cebe52daacfe7ae9de6) C:\Windows\system32\DRIVERS\LV302V32.SYS
2011/01/21 21:13:57.0284 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/01/21 21:13:57.0321 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/01/21 21:13:57.0382 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys
2011/01/21 21:13:57.0466 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/01/21 21:13:57.0624 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/01/21 21:13:57.0669 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/01/21 21:13:57.0694 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/01/21 21:13:57.0732 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/01/21 21:13:57.0769 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/01/21 21:13:57.0795 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys
2011/01/21 21:13:57.0830 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys
2011/01/21 21:13:57.0855 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/01/21 21:13:57.0902 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\DRIVERS\rdpdr.sys
2011/01/21 21:13:57.0934 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/01/21 21:13:57.0979 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys
2011/01/21 21:13:58.0055 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/01/21 21:13:58.0145 SASDIFSV (5bf35c4ea3f00fa8d3f1e5bf03d24584) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/01/21 21:13:58.0200 SASENUM (a22f08c98ac2f44587bf3a1fb52bf8cd) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
2011/01/21 21:13:58.0252 SASKUTIL (c7d81c10d3befeee41f3408714637438) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
2011/01/21 21:13:58.0315 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/01/21 21:13:58.0384 SCDEmu (612a3d69e603dbbe5c3c1079186a0393) C:\Windows\system32\drivers\SCDEmu.sys
2011/01/21 21:13:58.0443 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/01/21 21:13:58.0493 Serenum (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys
2011/01/21 21:13:58.0530 Serial (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys
2011/01/21 21:13:58.0630 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/01/21 21:13:58.0706 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/01/21 21:13:58.0745 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/01/21 21:13:58.0783 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/01/21 21:13:58.0820 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/01/21 21:13:58.0883 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/01/21 21:13:58.0922 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/01/21 21:13:58.0978 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/01/21 21:13:59.0033 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys
2011/01/21 21:13:59.0122 speedfan (5d6401db90ec81b71f8e2c5c8f0fef23) C:\Windows\system32\speedfan.sys
2011/01/21 21:13:59.0167 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/01/21 21:13:59.0269 sptd (7f1b7c4d446cd3f926af45b8c48bd593) C:\Windows\system32\Drivers\sptd.sys
2011/01/21 21:13:59.0361 srv (73dddbeec61e78568082916a27aadaee) C:\Windows\system32\DRIVERS\srv.sys
2011/01/21 21:13:59.0414 srv2 (4ceeb95e0b79e48b81f2da0a6c24c64b) C:\Windows\system32\DRIVERS\srv2.sys
2011/01/21 21:13:59.0445 srvnet (f63a0a58aafe34d7a1a0a74abccdd9c0) C:\Windows\system32\DRIVERS\srvnet.sys
2011/01/21 21:13:59.0511 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/01/21 21:13:59.0621 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/01/21 21:13:59.0666 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/01/21 21:13:59.0717 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/01/21 21:13:59.0832 Tcpip (8a7ad2a214233f684242f289ed83ebc3) C:\Windows\system32\drivers\tcpip.sys
2011/01/21 21:13:59.0898 Tcpip6 (8a7ad2a214233f684242f289ed83ebc3) C:\Windows\system32\DRIVERS\tcpip.sys
2011/01/21 21:13:59.0930 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys
2011/01/21 21:13:59.0965 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/01/21 21:14:00.0009 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/01/21 21:14:00.0040 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys
2011/01/21 21:14:00.0068 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys
2011/01/21 21:14:00.0142 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/01/21 21:14:00.0180 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/01/21 21:14:00.0221 tunnel (119b8184e106baedc83fce5ddf3950da) C:\Windows\system32\DRIVERS\tunnel.sys
2011/01/21 21:14:00.0280 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/01/21 21:14:00.0322 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys
2011/01/21 21:14:00.0394 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/01/21 21:14:00.0434 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/01/21 21:14:00.0501 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/01/21 21:14:00.0556 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/01/21 21:14:00.0586 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/01/21 21:14:00.0651 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\Windows\system32\Drivers\usbaapl.sys
2011/01/21 21:14:00.0705 usbaudio (292a25bb75a568ae2c67169ba2c6365a) C:\Windows\system32\drivers\usbaudio.sys
2011/01/21 21:14:00.0758 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/01/21 21:14:00.0808 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/01/21 21:14:00.0855 usbehci (cebe90821810e76320155beba722fcf9) C:\Windows\system32\DRIVERS\usbehci.sys
2011/01/21 21:14:00.0886 usbhub (cc6b28e4ce39951357963119ce47b143) C:\Windows\system32\DRIVERS\usbhub.sys
2011/01/21 21:14:00.0936 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\Windows\system32\DRIVERS\usbohci.sys
2011/01/21 21:14:00.0974 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
2011/01/21 21:14:01.0008 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/01/21 21:14:01.0070 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/01/21 21:14:01.0141 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2011/01/21 21:14:01.0193 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/01/21 21:14:01.0215 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/01/21 21:14:01.0255 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/01/21 21:14:01.0287 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/01/21 21:14:01.0333 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/01/21 21:14:01.0366 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/01/21 21:14:01.0400 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys
2011/01/21 21:14:01.0435 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys
2011/01/21 21:14:01.0492 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/01/21 21:14:01.0563 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/01/21 21:14:01.0613 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/01/21 21:14:01.0630 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/01/21 21:14:01.0692 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/01/21 21:14:01.0756 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/01/21 21:14:01.0880 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
2011/01/21 21:14:01.0989 WpdUsb (0cec23084b51b8288099eb710224e955) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/01/21 21:14:02.0036 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/01/21 21:14:02.0097 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/01/21 21:14:02.0159 \HardDisk1 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/01/21 21:14:02.0254 ================================================================================
2011/01/21 21:14:02.0254 Scan finished
2011/01/21 21:14:02.0254 ================================================================================
2011/01/21 21:14:02.0269 Detected object count: 1
2011/01/21 21:14:10.0613 \HardDisk1 - will be cured after reboot
2011/01/21 21:14:10.0682 Rootkit.Win32.TDSS.tdl4(\HardDisk1) - User select action: Cure
2011/01/21 21:14:22.0262 Deinitialize success
 
Second Scan:
2011/01/21 21:18:56.0165 TDSS rootkit removing tool 2.4.14.0 Jan 18 2011 09:33:51
2011/01/21 21:18:56.0165 ================================================================================
2011/01/21 21:18:56.0165 SystemInfo:
2011/01/21 21:18:56.0165
2011/01/21 21:18:56.0165 OS Version: 6.0.6001 ServicePack: 1.0
2011/01/21 21:18:56.0165 Product type: Workstation
2011/01/21 21:18:56.0165 ComputerName: ALEX-PC
2011/01/21 21:18:56.0166 UserName: Alex
2011/01/21 21:18:56.0166 Windows directory: C:\Windows
2011/01/21 21:18:56.0166 System windows directory: C:\Windows
2011/01/21 21:18:56.0166 Processor architecture: Intel x86
2011/01/21 21:18:56.0166 Number of processors: 2
2011/01/21 21:18:56.0166 Page size: 0x1000
2011/01/21 21:18:56.0166 Boot type: Normal boot
2011/01/21 21:18:56.0166 ================================================================================
2011/01/21 21:18:56.0889 Initialize success
2011/01/21 21:18:59.0041 ================================================================================
2011/01/21 21:18:59.0041 Scan started
2011/01/21 21:18:59.0041 Mode: Manual;
2011/01/21 21:18:59.0041 ================================================================================
2011/01/21 21:19:04.0495 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
2011/01/21 21:19:05.0010 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/01/21 21:19:05.0546 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/01/21 21:19:05.0972 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/01/21 21:19:06.0282 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/01/21 21:19:06.0867 AFD (763e172a55177e478cb419f88fd0ba03) C:\Windows\system32\drivers\afd.sys
2011/01/21 21:19:07.0302 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/01/21 21:19:07.0685 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/01/21 21:19:08.0094 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/01/21 21:19:08.0551 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/01/21 21:19:08.0902 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/01/21 21:19:09.0262 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/01/21 21:19:09.0704 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2011/01/21 21:19:10.0316 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/01/21 21:19:10.0769 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/01/21 21:19:11.0205 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/01/21 21:19:11.0574 atapi (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys
2011/01/21 21:19:12.0099 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\Windows\System32\Drivers\avgldx86.sys
2011/01/21 21:19:12.0483 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\Windows\System32\Drivers\avgmfx86.sys
2011/01/21 21:19:12.0866 AvgTdiX (22e3b793c3e61720f03d3a22351af410) C:\Windows\System32\Drivers\avgtdix.sys
2011/01/21 21:19:13.0224 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/01/21 21:19:13.0654 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/01/21 21:19:14.0044 BLKWGDv8 (e4074a8efc2693d5541633529ef6beeb) C:\Windows\system32\DRIVERS\BLKWGDv8.sys
2011/01/21 21:19:14.0520 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2011/01/21 21:19:14.0896 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/01/21 21:19:15.0246 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/01/21 21:19:15.0586 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/01/21 21:19:16.0032 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/01/21 21:19:16.0459 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/01/21 21:19:16.0770 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/01/21 21:19:17.0173 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/01/21 21:19:17.0657 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/01/21 21:19:18.0014 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys
2011/01/21 21:19:18.0440 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/01/21 21:19:18.0731 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys
2011/01/21 21:19:19.0094 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/01/21 21:19:19.0471 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
2011/01/21 21:19:19.0759 cpuz134 (75fa19142531cbf490770c2988a7db64) C:\Windows\system32\drivers\cpuz134_x32.sys
2011/01/21 21:19:19.0970 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/01/21 21:19:20.0250 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/01/21 21:19:20.0628 CSC (9a5434125c3dfe42393de4bbb791bd19) C:\Windows\system32\drivers\csc.sys
2011/01/21 21:19:21.0052 DfsC (9e635ae5e8ad93e2b5989e2e23679f97) C:\Windows\system32\Drivers\dfsc.sys
2011/01/21 21:19:21.0539 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys
2011/01/21 21:19:21.0885 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/01/21 21:19:22.0220 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys
2011/01/21 21:19:22.0737 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/01/21 21:19:23.0048 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys
2011/01/21 21:19:23.0428 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/01/21 21:19:23.0747 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/01/21 21:19:24.0084 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys
2011/01/21 21:19:24.0485 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys
2011/01/21 21:19:24.0715 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/01/21 21:19:24.0971 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/01/21 21:19:25.0189 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/01/21 21:19:25.0577 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/01/21 21:19:25.0856 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys
2011/01/21 21:19:26.0117 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/01/21 21:19:26.0548 fvevol (1400c747e2b73966b100fdce5426b7b2) C:\Windows\system32\DRIVERS\fvevol.sys
2011/01/21 21:19:26.0905 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/01/21 21:19:27.0460 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/01/21 21:19:27.0712 giveio (77ebf3e9386daa51551af429052d88d0) C:\Windows\system32\giveio.sys
2011/01/21 21:19:28.0215 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
2011/01/21 21:19:28.0795 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/01/21 21:19:29.0110 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/01/21 21:19:29.0507 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/01/21 21:19:29.0853 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/01/21 21:19:30.0198 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys
2011/01/21 21:19:30.0519 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/01/21 21:19:30.0964 HTTP (33b02459e86d0a2b86a6b9fe19139390) C:\Windows\system32\drivers\HTTP.sys
2011/01/21 21:19:31.0416 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/01/21 21:19:31.0788 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/01/21 21:19:31.0997 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/01/21 21:19:32.0135 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/01/21 21:19:32.0585 IntcAzAudAddService (4de88b49c891f45cd9ea6d83a341d3e3) C:\Windows\system32\drivers\RTKVHDA.sys
2011/01/21 21:19:32.0930 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/01/21 21:19:33.0157 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/01/21 21:19:33.0372 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/01/21 21:19:33.0887 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/01/21 21:19:34.0023 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/01/21 21:19:34.0311 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/01/21 21:19:34.0530 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/01/21 21:19:34.0666 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/01/21 21:19:34.0782 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/01/21 21:19:35.0029 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/01/21 21:19:35.0213 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/01/21 21:19:35.0439 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/01/21 21:19:35.0903 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys
2011/01/21 21:19:36.0158 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys
2011/01/21 21:19:36.0510 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/01/21 21:19:36.0968 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/01/21 21:19:37.0420 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/01/21 21:19:37.0720 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/01/21 21:19:38.0034 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/01/21 21:19:38.0681 LVcKap (8113133ec42dd6c566908008ce913edd) C:\Windows\system32\DRIVERS\LVcKap.sys
2011/01/21 21:19:39.0883 LVMVDrv (0dd5b8af4917a2821047450195c511b3) C:\Windows\system32\DRIVERS\LVMVDrv.sys
2011/01/21 21:19:40.0737 LVPr2Mon (406b1d186f75b4b4832d6237859e1b00) C:\Windows\system32\DRIVERS\LVPr2Mon.sys
2011/01/21 21:19:40.0941 LVUSBSta (be5e104be263921d6842c555db6a5c23) C:\Windows\system32\drivers\LVUSBSta.sys
2011/01/21 21:19:41.0127 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/01/21 21:19:41.0606 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/01/21 21:19:41.0986 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/01/21 21:19:42.0229 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/01/21 21:19:42.0442 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/01/21 21:19:42.0574 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/01/21 21:19:42.0764 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/01/21 21:19:42.0984 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/01/21 21:19:43.0307 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/01/21 21:19:43.0662 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/01/21 21:19:43.0817 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys
2011/01/21 21:19:44.0060 mrxsmb (c4ad205530888404e2b5fc8d9319b119) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/01/21 21:19:44.0373 mrxsmb10 (0a986b34f1678a2697574d7b1664e2dd) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/01/21 21:19:44.0527 mrxsmb20 (3268b8c3fa92bfc086355c39b45e9cc9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/01/21 21:19:44.0870 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/01/21 21:19:45.0119 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/01/21 21:19:45.0549 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/01/21 21:19:45.0920 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/01/21 21:19:46.0192 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/01/21 21:19:46.0513 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/01/21 21:19:46.0894 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/01/21 21:19:47.0267 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys
2011/01/21 21:19:47.0599 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/01/21 21:19:47.0969 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/01/21 21:19:48.0445 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys
2011/01/21 21:19:48.0836 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys
2011/01/21 21:19:49.0357 NDIS (9bdc71790fa08f0a0b5f10462b1bd0b1) C:\Windows\system32\drivers\ndis.sys
2011/01/21 21:19:49.0875 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/01/21 21:19:50.0220 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/01/21 21:19:50.0651 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/01/21 21:19:50.0982 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/01/21 21:19:51.0364 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/01/21 21:19:51.0507 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys
2011/01/21 21:19:51.0717 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/01/21 21:19:51.0906 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys
2011/01/21 21:19:52.0137 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/01/21 21:19:52.0552 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys
2011/01/21 21:19:52.0861 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/01/21 21:19:53.0265 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/01/21 21:19:53.0740 NVENETFD (d958a2b5f6ad5c3b8ccdc4d7da62466c) C:\Windows\system32\DRIVERS\nvmfdx32.sys
2011/01/21 21:19:54.0867 nvlddmkm (e572ebf0a86a76e7cfcaab00648f0f83) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/01/21 21:19:56.0576 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/01/21 21:19:56.0662 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/01/21 21:19:56.0818 nvstor32 (8ee374b6fb3cb2bb8d70395218b464a5) C:\Windows\system32\DRIVERS\nvstor32.sys
2011/01/21 21:19:57.0004 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/01/21 21:19:57.0607 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
2011/01/21 21:19:57.0852 Parport (8a79fdf04a73428597e2caf9d0d67850) C:\Windows\system32\DRIVERS\parport.sys
2011/01/21 21:19:58.0151 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys
2011/01/21 21:19:58.0581 Parvdm (6c580025c81caf3ae9e3617c22cad00e) C:\Windows\system32\DRIVERS\parvdm.sys
2011/01/21 21:19:58.0945 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys
2011/01/21 21:19:59.0252 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/01/21 21:19:59.0613 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/01/21 21:19:59.0804 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys
2011/01/21 21:20:00.0167 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/01/21 21:20:00.0644 PID_PEPI (0da6c5e0c8da6cebe52daacfe7ae9de6) C:\Windows\system32\DRIVERS\LV302V32.SYS
2011/01/21 21:20:00.0977 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/01/21 21:20:01.0198 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/01/21 21:20:01.0493 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys
2011/01/21 21:20:01.0810 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/01/21 21:20:02.0119 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/01/21 21:20:02.0280 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/01/21 21:20:02.0479 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/01/21 21:20:02.0752 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/01/21 21:20:02.0897 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/01/21 21:20:03.0131 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys
2011/01/21 21:20:03.0491 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys
2011/01/21 21:20:03.0830 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/01/21 21:20:04.0022 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\DRIVERS\rdpdr.sys
2011/01/21 21:20:04.0222 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/01/21 21:20:04.0466 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys
2011/01/21 21:20:04.0867 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/01/21 21:20:05.0016 SASDIFSV (5bf35c4ea3f00fa8d3f1e5bf03d24584) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/01/21 21:20:05.0096 SASENUM (a22f08c98ac2f44587bf3a1fb52bf8cd) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
2011/01/21 21:20:05.0164 SASKUTIL (c7d81c10d3befeee41f3408714637438) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
2011/01/21 21:20:05.0369 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/01/21 21:20:05.0513 SCDEmu (612a3d69e603dbbe5c3c1079186a0393) C:\Windows\system32\drivers\SCDEmu.sys
2011/01/21 21:20:05.0606 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/01/21 21:20:05.0795 Serenum (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys
2011/01/21 21:20:05.0901 Serial (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys
2011/01/21 21:20:06.0017 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/01/21 21:20:06.0160 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/01/21 21:20:06.0324 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/01/21 21:20:06.0396 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/01/21 21:20:06.0516 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/01/21 21:20:06.0737 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/01/21 21:20:06.0851 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/01/21 21:20:07.0082 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/01/21 21:20:07.0454 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys
2011/01/21 21:20:07.0602 speedfan (5d6401db90ec81b71f8e2c5c8f0fef23) C:\Windows\system32\speedfan.sys
2011/01/21 21:20:07.0722 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/01/21 21:20:07.0941 sptd (7f1b7c4d446cd3f926af45b8c48bd593) C:\Windows\system32\Drivers\sptd.sys
2011/01/21 21:20:08.0225 srv (73dddbeec61e78568082916a27aadaee) C:\Windows\system32\DRIVERS\srv.sys
2011/01/21 21:20:08.0524 srv2 (4ceeb95e0b79e48b81f2da0a6c24c64b) C:\Windows\system32\DRIVERS\srv2.sys
2011/01/21 21:20:08.0583 srvnet (f63a0a58aafe34d7a1a0a74abccdd9c0) C:\Windows\system32\DRIVERS\srvnet.sys
2011/01/21 21:20:08.0842 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/01/21 21:20:08.0960 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/01/21 21:20:09.0155 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/01/21 21:20:09.0397 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/01/21 21:20:09.0639 Tcpip (8a7ad2a214233f684242f289ed83ebc3) C:\Windows\system32\drivers\tcpip.sys
2011/01/21 21:20:09.0786 Tcpip6 (8a7ad2a214233f684242f289ed83ebc3) C:\Windows\system32\DRIVERS\tcpip.sys
2011/01/21 21:20:09.0853 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys
2011/01/21 21:20:09.0962 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/01/21 21:20:10.0056 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/01/21 21:20:10.0121 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys
2011/01/21 21:20:10.0237 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys
2011/01/21 21:20:10.0498 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/01/21 21:20:10.0719 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/01/21 21:20:10.0843 tunnel (119b8184e106baedc83fce5ddf3950da) C:\Windows\system32\DRIVERS\tunnel.sys
2011/01/21 21:20:10.0994 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/01/21 21:20:11.0078 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys
2011/01/21 21:20:11.0225 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/01/21 21:20:11.0322 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/01/21 21:20:11.0499 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/01/21 21:20:11.0654 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/01/21 21:20:11.0767 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/01/21 21:20:11.0999 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\Windows\system32\Drivers\usbaapl.sys
2011/01/21 21:20:12.0212 usbaudio (292a25bb75a568ae2c67169ba2c6365a) C:\Windows\system32\drivers\usbaudio.sys
2011/01/21 21:20:12.0464 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/01/21 21:20:12.0657 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/01/21 21:20:12.0895 usbehci (cebe90821810e76320155beba722fcf9) C:\Windows\system32\DRIVERS\usbehci.sys
2011/01/21 21:20:13.0060 usbhub (cc6b28e4ce39951357963119ce47b143) C:\Windows\system32\DRIVERS\usbhub.sys
2011/01/21 21:20:13.0233 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\Windows\system32\DRIVERS\usbohci.sys
2011/01/21 21:20:13.0423 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
2011/01/21 21:20:13.0632 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/01/21 21:20:13.0852 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/01/21 21:20:14.0044 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2011/01/21 21:20:14.0267 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/01/21 21:20:14.0551 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/01/21 21:20:14.0729 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/01/21 21:20:14.0811 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/01/21 21:20:15.0007 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/01/21 21:20:15.0174 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/01/21 21:20:16.0542 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys
2011/01/21 21:20:16.0760 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys
2011/01/21 21:20:16.0858 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/01/21 21:20:16.0955 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/01/21 21:20:17.0072 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/01/21 21:20:17.0163 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/01/21 21:20:17.0251 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/01/21 21:20:17.0482 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/01/21 21:20:17.0840 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
2011/01/21 21:20:18.0073 WpdUsb (0cec23084b51b8288099eb710224e955) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/01/21 21:20:18.0262 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/01/21 21:20:18.0531 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/01/21 21:20:18.0714 \HardDisk1 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/01/21 21:20:18.0827 ================================================================================
2011/01/21 21:20:18.0827 Scan finished
2011/01/21 21:20:18.0827 ================================================================================
2011/01/21 21:20:18.0846 Detected object count: 1
2011/01/21 21:20:25.0145 \HardDisk1 - will be cured after reboot
2011/01/21 21:20:25.0146 Rootkit.Win32.TDSS.tdl4(\HardDisk1) - User select action: Cure
2011/01/21 21:20:26.0553 Deinitialize success
 
does that mean I need to disable automatic Windows Updates for now? Do I need to go a step further still and cease use of my computer until we have it cleaned? Should it be disconnected from the network when not in use?
Yes to the 1st question. No to the others.

Download MBRCheck to your desktop

Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
It will show a black screen with some data on it.
Enter N to exit.
A report called MBRcheckxxxx.txt will be on your desktop
Open this report and post its content in your next reply.

======================================================================

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  4. Double click on combofix.exe & follow the prompts.
  5. When finished, it will produce a report for you.
  6. Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
Use AppRemover to uninstall it: https://www.techspot.com/downloads/5514-appremover.html
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try one of the following:

1. Run Combofix from Safe Mode.

2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.

Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

Rkill.com
Rkill.scr
Rkill.exe

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

If normal mode still doesn't work, run BOTH tools from safe mode.

In case #2, please post BOTH logs, rKill and Combofix.

DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
 
How long should AppRemover take to kill AVG? I tried to run it before bed the last few nights, but it only ever got to about 10% through the removal. Today I left the machine all day - 12 hours - and it only reached 60%. Tomorrow when I go to work and am not using the machine I will try to let it run for 24 hours if it needs to but geez, that seems like a long time to remove one program. I just wondered if something else was amiss here.
 
I had a couple problems with these.

1. MBRCheck froze up the whole system when I tried to use it. If left for a few hours, when I came back the machine had bluescreened. Logs were still created, so I will post what I had.
2. ComboFix - I ran AVG remover successfully and disabled AdWatch live before starting ComboFix. Nonetheless, it said these two were still running, so I clicked OK, believing that the program would quit and I could verify that these were uninstalled. But instead of closing, a second dialog box appeared that again said both services were running, and that I was therefore running ComboFix "at my own risk". If there had been a cancel button on that dialog I would have stopped the process and asked before running it, but I never got the chance to change my mind. Hopefully that didn't hose the scan. Logs are below.

EDIT: Google redirection appears to have stopped. However, I'm still concerned by the bluescreening that happens when I run MBRCheck. I don't know the exact error reported by the bluescreen since my only indication when I return is the dialog that says "Windows recovered from a serious error."

MBRCheck:
MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Ultimate Edition
Windows Information: Service Pack 1 (build 6001), 32-bit
Base Board Manufacturer: ECS-USA
BIOS Manufacturer: Phoenix Technologies, LTD
System Manufacturer: ECS-USA
System Product Name: GeForce6100PM-M2
Logical Drives Mask: 0x0000015c

Kernel Drivers (total 153):
0x82019000 \SystemRoot\system32\ntkrnlpa.exe
0x823D2000 \SystemRoot\system32\hal.dll
0x80606000 \SystemRoot\system32\kdcom.dll
0x8060E000 \SystemRoot\system32\PSHED.dll
0x8061F000 \SystemRoot\system32\BOOTVID.dll
0x80627000 \SystemRoot\system32\CLFS.SYS
0x80668000 \SystemRoot\system32\CI.dll
0x80748000 \SystemRoot\system32\drivers\Wdf01000.sys
0x807C4000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8260F000 \SystemRoot\system32\drivers\acpi.sys
0x82655000 \SystemRoot\system32\drivers\WMILIB.SYS
0x8265E000 \SystemRoot\system32\drivers\msisadrv.sys
0x82666000 \SystemRoot\system32\drivers\pci.sys
0x8268D000 \SystemRoot\System32\drivers\partmgr.sys
0x8269C000 \SystemRoot\system32\drivers\volmgr.sys
0x826AB000 \SystemRoot\System32\drivers\volmgrx.sys
0x826F5000 \SystemRoot\system32\drivers\pciide.sys
0x826FC000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8270A000 \SystemRoot\System32\drivers\mountmgr.sys
0x8271A000 \SystemRoot\system32\drivers\atapi.sys
0x82722000 \SystemRoot\system32\drivers\ataport.SYS
0x82740000 \SystemRoot\system32\drivers\nvstor.sys
0x8274D000 \SystemRoot\system32\drivers\storport.sys
0x8278E000 \SystemRoot\system32\DRIVERS\nvstor32.sys
0x827B3000 \SystemRoot\system32\drivers\fltmgr.sys
0x827E5000 \SystemRoot\system32\drivers\fileinfo.sys
0x82600000 \SystemRoot\system32\DRIVERS\Lbd.sys
0x83002000 \SystemRoot\System32\Drivers\ksecdd.sys
0x83073000 \SystemRoot\system32\drivers\ndis.sys
0x8317E000 \SystemRoot\system32\drivers\msrpc.sys
0x831A9000 \SystemRoot\system32\drivers\NETIO.SYS
0x83205000 \SystemRoot\System32\drivers\tcpip.sys
0x832EE000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8820B000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8831A000 \SystemRoot\system32\drivers\volsnap.sys
0x88353000 \SystemRoot\System32\Drivers\spldr.sys
0x8835B000 \SystemRoot\system32\speedfan.sys
0x8835D000 \SystemRoot\System32\Drivers\mup.sys
0x8836C000 \SystemRoot\system32\giveio.sys
0x8836D000 \SystemRoot\System32\drivers\ecache.sys
0x88394000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x883B8000 \SystemRoot\system32\drivers\disk.sys
0x883C9000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x883EA000 \SystemRoot\system32\drivers\crcdisk.sys
0x8333F000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8334A000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x83353000 \SystemRoot\system32\DRIVERS\amdk8.sys
0x83363000 \SystemRoot\system32\DRIVERS\fdc.sys
0x8336E000 \SystemRoot\system32\DRIVERS\serial.sys
0x83388000 \SystemRoot\system32\DRIVERS\serenum.sys
0x83392000 \SystemRoot\system32\DRIVERS\parport.sys
0x833AA000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x833B4000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x831E3000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x807D1000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x807E3000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x833F2000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8C002000 \SystemRoot\system32\DRIVERS\nvmfdx32.sys
0x8C20A000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8CB28000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x8CB2A000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8CBC9000 \SystemRoot\System32\drivers\watchdog.sys
0x8C102000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8CBD6000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8CBE1000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8C130000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8C13B000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8C15E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8C16D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8C181000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8C196000 \SystemRoot\System32\Drivers\pcouffin.sys
0x8CE05000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0x8CE8E000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8CE9E000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8CEA9000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8CEB4000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8CEB6000 \SystemRoot\system32\DRIVERS\ks.sys
0x8CEE0000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8CEEA000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8CEF7000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8CF2B000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8D000000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8CF47000 \SystemRoot\system32\drivers\portcls.sys
0x8CF74000 \SystemRoot\system32\drivers\drmk.sys
0x8CF99000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8D1F8000 \SystemRoot\System32\Drivers\Null.SYS
0x8CFA2000 \SystemRoot\System32\Drivers\Beep.SYS
0x8CFC5000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8CFCC000 \SystemRoot\System32\drivers\vga.sys
0x8CFD8000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8CF3C000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8CFA9000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8CFB1000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8C1A2000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8CFBC000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8C1B0000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8C1C6000 \SystemRoot\system32\DRIVERS\smb.sys
0x8D208000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8D23A000 \SystemRoot\system32\drivers\afd.sys
0x8D282000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8D298000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8D2A6000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8D2B9000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0x8D2C1000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
0x8D2E6000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0x8D2EC000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8D328000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8D332000 \SystemRoot\system32\drivers\csc.sys
0x8D38C000 \SystemRoot\System32\Drivers\dfsc.sys
0x8D3A3000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x8D3B5000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8D3B7000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8D3CE000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8D3D7000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8D3E7000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8D3F0000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8C1DA000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8C200000 \SystemRoot\System32\Drivers\dump_diskdump.sys
0x83309000 \SystemRoot\System32\Drivers\dump_nvstor32.sys
0x8C1E7000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x95820000 \SystemRoot\System32\win32k.sys
0x883F3000 \SystemRoot\System32\drivers\Dxapi.sys
0x8332E000 \SystemRoot\system32\DRIVERS\monitor.sys
0x95A40000 \SystemRoot\System32\TSDDD.dll
0x95A60000 \SystemRoot\System32\ATMFD.DLL
0x95AB0000 \SystemRoot\System32\cdd.dll
0x9A001000 \SystemRoot\system32\drivers\luafv.sys
0x9A01C000 \SystemRoot\system32\drivers\spsys.sys
0x9A0CB000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9A0DB000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9A105000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9A10F000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9A122000 \SystemRoot\system32\drivers\HTTP.sys
0x9A18F000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9A1AC000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9A1C5000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9A1DA000 \SystemRoot\system32\drivers\mrxdav.sys
0x9E004000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9E023000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9E05C000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9E074000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9E09B000 \SystemRoot\System32\DRIVERS\srv.sys
0x9E0E7000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x9E0EE000 \??\C:\Windows\system32\drivers\cpuz134_x32.sys
0x9E0F2000 \SystemRoot\system32\drivers\peauth.sys
0x9E1D0000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9E1DA000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9E1E6000 \SystemRoot\system32\DRIVERS\LVPr2Mon.sys
0x9E1EB000 \SystemRoot\system32\drivers\tdtcp.sys
0x831F2000 \SystemRoot\System32\DRIVERS\tssecsrv.sys
0xA1E0E000 \SystemRoot\System32\Drivers\RDPWD.SYS
0xA1E41000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x76F70000 \Windows\System32\ntdll.dll

Processes (total 63):
0 System Idle Process
4 System
460 C:\Windows\System32\smss.exe
536 csrss.exe
588 C:\Windows\System32\wininit.exe
600 csrss.exe
632 C:\Windows\System32\services.exe
644 C:\Windows\System32\lsass.exe
652 C:\Windows\System32\lsm.exe
788 C:\Windows\System32\svchost.exe
856 C:\Windows\System32\nvvsvc.exe
864 C:\Windows\System32\winlogon.exe
904 C:\Windows\System32\svchost.exe
960 C:\Windows\System32\svchost.exe
992 C:\Windows\System32\svchost.exe
1020 C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
1048 C:\Windows\System32\svchost.exe
1108 C:\Windows\System32\audiodg.exe
1176 C:\Windows\System32\svchost.exe
1196 C:\Windows\System32\SLsvc.exe
1308 C:\Windows\System32\svchost.exe
1384 C:\Windows\System32\nvvsvc.exe
1480 C:\Windows\System32\svchost.exe
1680 C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
1796 C:\Windows\System32\spoolsv.exe
1820 C:\Windows\System32\svchost.exe
1984 C:\Windows\System32\taskeng.exe
196 C:\Windows\System32\taskeng.exe
284 C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
288 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
888 C:\Program Files\Bonjour\mDNSResponder.exe
1700 C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
2164 C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
2268 C:\Windows\System32\PnkBstrA.exe
2284 C:\Windows\System32\svchost.exe
2324 C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
2356 C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
2396 C:\Windows\System32\svchost.exe
2468 C:\Program Files\TightVNC\tvnserver.exe
2488 C:\Windows\System32\svchost.exe
2508 C:\Windows\System32\SearchIndexer.exe
2604 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
2892 C:\Windows\System32\dwm.exe
2984 unsecapp.exe
3012 C:\Windows\explorer.exe
3140 WmiPrvSE.exe
3412 C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
3488 C:\Windows\RtHDVCpl.exe
3560 C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
3680 C:\Program Files\TightVNC\tvnserver.exe
3760 C:\Program Files\Windows Media Player\wmpnscfg.exe
3792 C:\Windows\ehome\ehtray.exe
3896 C:\Program Files\Windows Media Player\wmpnetwk.exe
4008 C:\Program Files\Windows Sidebar\sidebar.exe
4044 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
4064 C:\Program Files\AirVideoServer\AirVideoServer.exe
1364 C:\Program Files\WordWeb\wweb32.exe
308 C:\Windows\ehome\ehmsas.exe
2616 C:\Program Files\Windows Sidebar\sidebar.exe
3100 WmiPrvSE.exe
4184 C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
2024 C:\Windows\System32\wuauclt.exe
6024 C:\Users\Alex\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)
\\.\E: --> \\.\PhysicalDrive1 at offset 0x00000000`00100000 (NTFS)
\\.\G: --> \\.\PhysicalDrive2 at offset 0x00000000`00007e00 (NTFS)
\\.\I: --> \\.\PhysicalDrive3 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive0 Model Number: WDC WD1600JB-00GVC0, Rev: 08.0
PhysicalDrive1 Model Number: HitachiHDP725050GLA, Rev: GM4O
PhysicalDrive2 Model Number: SeagateFreeAgentDesktop, Rev: 100D
PhysicalDrive3 Model Number: SeagateDesktop, Rev: 0130

Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0

ComboFix:
ComboFix 11-01-24.01 - Alex 01/24/2011 20:33:33.3.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.2046.998 [GMT -7:00]
Running from: c:\users\Alex\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {DAAC1C79-1A96-9DFE-FC4C-6940214C33E6}
SP: AVG Anti-Virus Free *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Alex\AppData\Roaming\0AA35AA340E408D76C950D7A0C838F79
c:\users\Alex\AppData\Roaming\0AA35AA340E408D76C950D7A0C838F79\enemies-names.txt
c:\users\Alex\AppData\Roaming\0AA35AA340E408D76C950D7A0C838F79\local.ini
c:\windows\ST6UNST.000
c:\windows\system32\twunk_32.exe

.
((((((((((((((((((((((((( Files Created from 2010-12-25 to 2011-01-25 )))))))))))))))))))))))))))))))
.

2011-01-25 03:41 . 2011-01-25 03:42 -------- d-----w- c:\users\Alex\AppData\Local\temp
2011-01-25 03:41 . 2011-01-25 03:41 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-01-25 03:41 . 2011-01-25 03:41 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp
2011-01-25 03:41 . 2011-01-25 03:41 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-19 04:55 . 2011-01-19 04:55 98304 --sha-r- c:\windows\system32\FXSCOVERS.dll
2011-01-19 04:35 . 2011-01-19 04:35 -------- d-----w- c:\program files\Aimersoft
2011-01-19 04:06 . 2011-01-19 04:06 -------- d-----w- c:\program files\Easy Video Splitter
2011-01-18 03:33 . 2011-01-18 03:34 -------- d-----w- c:\program files\SpaceBattle ScreenSaver
2011-01-12 04:15 . 2011-01-12 04:15 -------- d-----w- C:\wav2voc
2011-01-09 08:09 . 2011-01-15 16:14 -------- d-----w- C:\bmpdf
2011-01-08 21:53 . 2011-01-08 22:27 -------- d-----w- c:\windows\system32\Adobe
2011-01-08 18:14 . 2011-01-15 20:34 -------- d-----w- C:\WDFUSE
2010-12-29 05:37 . 2006-11-29 20:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 01:09 . 2009-12-21 08:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 01:08 . 2009-12-21 08:03 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-10 08:16 . 2010-12-10 08:16 749832 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-11-18 04:56 . 2009-11-23 18:18 234536 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-11-18 04:36 . 2009-08-17 20:25 138520 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-11-18 04:36 . 2010-07-10 03:36 234536 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-11-05 02:50 . 2010-07-27 03:44 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-10-29 05:35 . 2009-08-17 20:25 139152 ----a-w- c:\users\Alex\AppData\Roaming\PnkBstrK.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfir.dll" [2009-11-10 2331672]

[HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]
2009-11-10 01:38 2331672 ----a-w- c:\program files\XfireXO\tbXfir.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfir.dll" [2009-11-10 2331672]

[HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}"= "c:\program files\XfireXO\tbXfir.dll" [2009-11-10 2331672]

[HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 01:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 01:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 01:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 01:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 01:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 01:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 01:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 01:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 01:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-11-21 4608]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-16 39408]
"AirVideoServer"="c:\program files\AirVideoServer\AirVideoServer.exe" [2010-09-13 4917384]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-02-26 4939776]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-05-31 323976]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2010-06-24 126976]
"tvncontrol"="c:\program files\TightVNC\tvnserver.exe" [2010-07-08 815704]

c:\users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
WordWeb.lnk - c:\program files\WordWeb\wweb32.exe [2009-9-28 42168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 21:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-10-15 03:38 623992 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2009-08-28 04:59 2356088 ----a-w- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0EYTHM]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
2010-06-24 02:07 126976 ----a-w- c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-29 03:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2007-10-25 23:33 563984 ----a-w- c:\program files\Common Files\logishrd\LComMgr\Communications_Helper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2007-10-25 23:37 2178832 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 07:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 23:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-12-29 02:22 1242448 ----a-w- e:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-12-27 04:41 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-08-16 22:05 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-07-12 16:32 74752 ----a-w- e:\program files\Winamp\winampa.exe

R2 gupdate1ca1ebe79c66296;Google Update Service (gupdate1ca1ebe79c66296);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-16 133104]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-01-20 1402272]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R3 BLKWGDv8;Belkin Wireless G Desktop Card Service v8;c:\windows\system32\DRIVERS\BLKWGDv8.sys [2006-11-18 312832]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-12-16 7408]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-11-21 716272]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-07-12 64288]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-12-16 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-12-16 74480]
S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-07-14 239648]
S2 tvnserver;TightVNC Server;c:\program files\TightVNC\tvnserver.exe [2010-07-08 815704]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
2008-04-11 23:23 38400 ----a-w- c:\windows\System32\SoundSchemes.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
2008-08-28 16:50 30720 ----a-w- c:\windows\System32\soundschemes2.exe
.
Contents of the 'Scheduled Tasks' folder

2011-01-25 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-16 22:10]

2011-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-16 22:11]

2011-01-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-16 22:11]

2011-01-25 c:\windows\Tasks\User_Feed_Synchronization-{D0500D9A-B244-4FCF-A56A-701030FBCBD2}.job
- c:\windows\system32\msfeedssync.exe [2009-12-10 04:59]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Add to Evernote - e:\program files\Evernote\Evernote3\enbar.dll/2000
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
TCP: {45B82F13-8CAA-44B2-A0BF-232ABD77AF8C} = 68.87.85.102,68.87.69.150
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
FF - ProfilePath - c:\users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\14mmi5nt.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - e:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Multi Links: multilinks@plugin - %profile%\extensions\multilinks@plugin
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - %profile%\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
MSConfigStartUp-EA Core - e:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
AddRemove-Convert Doc_is1 - c:\program files\Softinterface



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-24 20:41
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
AirVideoServer = c:\program files\AirVideoServer\AirVideoServer.exe?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6001 Disk: WDC_WD16 rev.08.0 -> Harddisk0\DR0 -> \Device\00000061

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
sectors 312581806 (+255): user != kernel

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-770543726-423754612-1244475062-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c7,a3,f1,f4,b3,01,05,66,12,ab,2f,ab,6a,9a,23,46,b9,dc,d0,a0,48,46,ef,
af,b3,79,34,37,ec,dd,fa,df,a2,46,06,5b,2e,df,22,6b,31,eb,24,d2,c1,ed,66,c1,\
"??"=hex:dd,99,0c,75,e0,d9,b3,83,e9,61,6d,9e,fe,35,fe,09

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-01-24 20:46:10
ComboFix-quarantined-files.txt 2011-01-25 03:46
ComboFix2.txt 2010-01-01 00:39
ComboFix3.txt 2009-12-27 20:51

Pre-Run: 33,190,977,536 bytes free
Post-Run: 33,179,619,328 bytes free

- - End Of File - - 285FAFF20CDADA7D378C33BEB95F53C6

Rkill:
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 01/25/2011 at 19:39:06.
Operating System: Windows Vista (TM) Ultimate


Processes terminated by Rkill or while it was running:

C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


Rkill completed on 01/25/2011 at 19:39:53.
 
You did fine, however MBRCheck log is incomplete.
It may be due to a fact, that your MBR is possibly infected.

Let's double check....

Download Bootkit Remover to your Desktop.

  • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
  • After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator).
  • It will show a Black screen with some data on it.
  • Right click on the screen and click Select All.
  • Press CTRL+C
  • Open a Notepad and press CTRL+V
  • Post the output back here.
 
OK, that seems to have completed OK. I did get an error in a dialog box:

"ATA_PASS_THROUGH_DIRECT is not supported by your disk controller. SCSI_PASS_THROUGH_DIRECT will be use for disk I/O"

Once I clicked OK, however, the scan completed without an issue. Here is the output:

Bootkit Remover
(c) 2009 eSage Lab
www.esagelab.com

Program version: 1.2.0.0
OS Version: Microsoft Windows Vista Ultimate Edition Service Pack 1 (build 6001)
, 32-bit

System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`00100000
ATA_Read(): DeviceIoControl() ERROR 1
Boot sector MD5 is: 0ec6b2481fc707d1e901dc2a875f2826

Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


Done;
Press any key to quit...
 
MBR looks fine.

If you're planning on reinstalling AVG, you have to uninstall Lavasoft Ad-Watch Live! Anti-Virus.
You can't be running two AV programs.

Combofix log looks good too.

How is redirection?

Download OTL to your Desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Scan All Users checkbox.
  • Under the Custom Scan box paste this in:


netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\0*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\system32\drivers\*.rmv
dir /b "%systemroot%\system32\*.exe" | find /i " " /c
dir /b "%systemroot%\*.exe" | find /i " " /c
%PROGRAMFILES%\Microsoft\*.*
%systemroot%\System32\Wbem\proquota.exe
%PROGRAMFILES%\Mozilla Firefox\*.dat
%USERPROFILE%\Cookies\*.txt /x
%SystemRoot%\system32\fonts\*.*
%systemroot%\system32\winlog\*.*
%systemroot%\system32\Language\*.*
%systemroot%\system32\Settings\*.*
%systemroot%\system32\*.quo
%SYSTEMROOT%\AppPatch\*.exe
%SYSTEMROOT%\inf\*.exe
%SYSTEMROOT%\Installer\*.exe
%systemroot%\system32\config\*.bak2
%systemroot%\system32\Computers\*.*
%SystemRoot%\system32\Sound\*.*
%SystemRoot%\system32\SpecialImg\*.*
%SystemRoot%\system32\code\*.*
%SystemRoot%\system32\draft\*.*
%SystemRoot%\system32\MSSSys\*.*
%ProgramFiles%\Javascript\*.*
%systemroot%\pchealth\helpctr\System\*.exe /s
%systemroot%\Web\*.exe
%systemroot%\system32\msn\*.*
%systemroot%\system32\*.tro
%AppData%\Microsoft\Installer\msupdates\*.*
%ProgramFiles%\Messenger\*.*
%systemroot%\system32\systhem32\*.*
%systemroot%\system\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
/md5stop


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
 
The redirection appears to have stopped. Here are my OTL and Extras files. Once we have everything cleaned, I want to talk to you about an ideal antivirus/anti-malware solution. I've tried a lot of the "big name" antivirus solutions - Norton, McAfee, AVG - but none of them have ever stopped anything like this latest adventure. They seem to pick up only the most basic viruses... anything with any stopping power gets right through, usually without even triggering the antivirus. I've heard really good things about Nod32 from Leo Laporte's TWiT podcast... does anyone have any experience (good or bad) with that product?

As to installing more than one AV, I know it's not recommended, but I haven't found anything as good as AdAware for getting rid of spyware, adware, and malware, an area that a lot of antivirus programs don't touch. However, I wouldn't trust AdAware as a complete security solution either. Is there a way to run AdAware only when I need, disabling its active scanning component to avoid the conflict? Thanks for any advice you can give me... your help has already been invaluable! :)

Logs in the next two posts...
 
Extras:
OTL Extras logfile created on: 1/27/2011 7:43:46 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Alex\Desktop
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 60.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 32.23 Gb Free Space | 21.62% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 291.38 Gb Free Space | 62.56% Space Free | Partition Type: NTFS
Drive G: | 465.76 Gb Total Space | 274.98 Gb Free Space | 59.04% Space Free | Partition Type: NTFS
Drive I: | 1863.01 Gb Total Space | 920.53 Gb Free Space | 49.41% Space Free | Partition Type: NTFS

Computer Name: ALEX-PC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "E:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "E:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "E:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "E:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "E:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0986E5C0-A30D-46A4-9677-D50709A29B3B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0E0A7B19-30FA-495B-AD64-A3EED3CC57B4}" = lport=139 | protocol=6 | dir=in | app=system |
"{1BD225BE-A2D0-49F1-BBBA-0874AD31C2C6}" = lport=10243 | protocol=6 | dir=in | app=system |
"{1E35400F-AF1A-4406-8E98-6AD394058DEF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{1FA97061-8905-4446-B997-837289C8A8B5}" = lport=50901 | protocol=6 | dir=in | name=adobe version cue cs3 server |
"{2E15A108-F834-4AA2-9E8A-B75134778304}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs3 server |
"{40D593B8-54F8-412F-8612-D4EAA12A655C}" = rport=138 | protocol=17 | dir=out | app=system |
"{470B9C28-45E7-46DA-832F-AD3BABCD328B}" = lport=138 | protocol=17 | dir=in | app=system |
"{48F2186E-9C31-475E-92E4-BF7D529746A0}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{4E28D1D6-F86D-41B4-80F9-867B72861396}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4F7FB5D3-9B69-4E80-990D-A3CBFB454F45}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{551F3B8B-D485-49C7-BD90-E47EEDF96E5B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{59066E38-AA3D-4C49-91A1-983ECB6EEC86}" = lport=1900 | protocol=17 | dir=in | name=udp 1900 |
"{5EC066DA-B75D-48B2-A52C-F6328E81A1C9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6205E06C-A326-4E14-AAE1-17C107C3F30B}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{64918511-BF4F-439B-89A9-858C72CD40D6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{65D271B1-DCD2-47F6-8AA5-2F42E0775935}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{66E6C4B6-287B-4008-A9A5-0722248524A5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6A61C780-98C4-4EB3-871D-3A9D4B3DFA8E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{7193B6F3-0620-4193-B65B-044626A2DF96}" = lport=445 | protocol=6 | dir=in | app=system |
"{771BDF34-DFC6-41FA-94EA-6325BBB9B8BE}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{7795918B-0A8A-4501-BF12-6EA2BF7A17EA}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7D9055BC-3C18-4A7B-A19C-C5788FAC528A}" = lport=2869 | protocol=6 | dir=in | name=tcp 2869 |
"{85475178-EF16-45FB-B932-A3EE6961C61A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8FDA3744-6B78-47A0-9BE0-5D1734903BD1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A1CAE8B1-F32E-4D95-A7A7-071F91584201}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A98B3603-C06F-43D8-8CF7-51350A5F1AAE}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{B45F69D6-22C8-4129-B62A-4055A207FADC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B7A9972E-844B-4627-89EA-695FF64513E2}" = lport=50900 | protocol=6 | dir=in | name=adobe version cue cs3 server |
"{BD1A99AF-9B97-40F5-8367-B11F61BB767F}" = rport=445 | protocol=6 | dir=out | app=system |
"{CDD14980-9C8F-48A8-A0E2-A1BA12DC6217}" = rport=139 | protocol=6 | dir=out | app=system |
"{D206AE6E-6C5A-4502-BA54-7D23409F3F2C}" = lport=3389 | protocol=6 | dir=in | app=system |
"{DC761D9E-673A-4AEA-A3DD-F0E5DA8C30FD}" = rport=137 | protocol=17 | dir=out | app=system |
"{DD6E2206-1FB1-4127-A05D-FBF69044B75D}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs3 server |
"{E5379864-4801-4146-ADA4-0B43D96CC918}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0008B3C1-3E23-48DB-AA73-11F3AF512B2E}" = protocol=17 | dir=in | app=e:\program files\lucasarts\star wars empire at war\gamedata\sweaw.exe |
"{001BB5FE-74D4-4EDD-91D8-F2D0EE1066D7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{01185C1E-717E-4DD8-99D4-2CAFCC6514A4}" = protocol=6 | dir=in | app=e:\program files\lucasarts\star wars battlefront\gamedata\battlefront.exe |
"{01C957A5-5B9E-4414-BBE7-73B9375FDBAF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{03686E01-D5BC-405B-9707-605852DC5AF1}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{042FC1D4-7127-4424-B07B-9059B84B28AB}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{04D01A71-23D1-4975-9E2C-24249448D34A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{087139D5-758C-40AB-A017-3D4ADBCD12EE}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{08D1F244-76B2-4204-88B4-C8F326AC6BBC}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{08EF1D52-7899-42E3-8E22-7554982C339A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{0C54B0DC-E236-45B8-BCC2-D3BA4AAFE5A0}" = protocol=17 | dir=in | app=e:\program files\id software\enemy territory - quake wars\etqw.exe |
"{0D172052-E902-4448-B7CE-E47F1E6A9E81}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{0F3EEB86-EFDA-49E2-8FA5-FCECAB6D2199}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\psychonauts\psycholauncher.exe |
"{170384AC-6298-4002-9413-4B1A45618243}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{19DCF694-0754-4AB1-9A82-8AAADBA3D4F6}" = protocol=6 | dir=in | app=e:\program files\lucasarts\star wars republic commando\gamedata\system\swrepubliccommando.exe |
"{1E0F4C94-41D3-43A6-977A-A9F8B1EB04C8}" = protocol=17 | dir=in | app=e:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{1EA06F37-3441-472E-8F81-F749189F9CBE}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\poker night at the inventory\celebritypoker.exe |
"{1F5C3BA0-ACC2-46B1-BD29-583B5836C7BA}" = protocol=17 | dir=in | app=e:\program files\lucasarts\star wars battlefront\gamedata\battlefront.exe |
"{216F8D68-700C-4A7E-87DF-0581BB134784}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{252F3B47-E8CE-4B33-9330-3007FE7EA072}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{261A50C1-1163-463D-93AB-0D653A0466F5}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{2F0FD184-7DCE-486A-836C-D2D21CC2C202}" = protocol=17 | dir=in | app=c:\program files\airvideoserver\airvideoserver.exe |
"{30C795DC-C964-4E00-8C1F-A4D81F0466A3}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{35EB123B-3076-45D6-B5B2-51756247DD01}" = protocol=6 | dir=in | app=e:\program files\ea games\battlefield 2\bf2.exe |
"{3697F300-564C-474F-91DF-2AFD1BD50AC4}" = protocol=6 | dir=in | app=e:\program files\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe |
"{3A496361-AAE4-4753-9437-484D3C9073C5}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{3C629CC8-12D8-4FBF-8085-0D438E464824}" = protocol=6 | dir=in | app=e:\program files\2k games\bioshock 2\mp\builds\binaries\bioshock2.exe |
"{401926B5-64EF-4B44-B836-9264D77F881B}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{422CE033-7530-4B22-B825-74999F57416C}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{472340B7-3DAC-4569-B151-73CB47AFDBA9}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs3\server\bin\versioncuecs3.exe |
"{4772205E-0A82-4B5F-B352-14346AA0B3AD}" = protocol=6 | dir=in | app=e:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{477753A3-FAA6-4D83-BC7B-A26D7B8C5410}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{47B1CA49-F6D9-40E5-9CFF-4F53081F7563}" = protocol=17 | dir=in | app=e:\program files\id software\enemy territory - quake wars\etqwded.exe |
"{49488513-4F49-440A-AB60-3DE19A03C908}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{501F1E06-4EC0-4656-B0D8-5B9394F8E1AA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{50DD9DBF-7871-4AF8-8B07-490FA405323B}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{57408EF1-29C6-43BB-943B-F989BBA324EA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5A929762-E2AB-4BC9-99B4-A8BA91665ABA}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\alexg2490\garrysmod\hl2.exe |
"{5C7DD78C-693D-40FF-B39B-203561A3A547}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{5D921CCE-E455-4525-994B-9A2836339F72}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\alexg2490\garrysmod\hl2.exe |
"{6ABDE204-5AA8-413C-9F31-4E7CDBA1A4B9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{73A7D338-E8EA-4159-9A02-900E5805A43F}" = protocol=6 | dir=out | app=c:\program files\airvideoserver\airvideoserver.exe |
"{7403E879-9EAD-4A70-BC26-2C224894A764}" = protocol=17 | dir=in | app=e:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{79828BF7-0E01-4CE3-A10D-CA5F679960A7}" = dir=in | app=c:\program files\avg\avg9\avgnsx.exe |
"{7D63FA37-29A8-428D-AFD4-02D2C85311D0}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{7E923C7E-CAF1-4F3E-8378-9B20A9DA1DF6}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8025A057-0348-4CF7-8AB6-235327206EA8}" = protocol=6 | dir=in | app=c:\program files\tightvnc\tvnserver.exe |
"{84FE9BCF-FC81-4351-8C0A-37FB85CDF2EA}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{851E5C33-1175-4737-B736-75BDB6ED4E3F}" = protocol=6 | dir=in | app=c:\program files\airvideoserver\airvideoserver.exe |
"{86C7CF7B-1593-4138-B7FD-4B6F9747F5C5}" = protocol=17 | dir=in | app=e:\program files\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe |
"{870AC926-46FA-4455-BA54-892E0F15F17D}" = protocol=17 | dir=in | app=e:\program files\lucasarts\star wars republic commando\gamedata\system\swrepubliccommando.exe |
"{87BA5E7B-E362-4295-BE82-3EC6D2A541AC}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{89BB3BC0-EAD5-4F46-96D9-8E898DE1FD48}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8AA74538-E04F-48EB-881C-1C3984B68573}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9248107E-C936-4699-8F9C-AF49237B1FBB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{94801A57-DEE3-416A-9BA1-183451908A02}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs3\server\bin\versioncuecs3.exe |
"{9829DAA4-60DC-4D32-B857-F8710D45CFAF}" = protocol=17 | dir=in | app=c:\program files\tightvnc\vncviewer.exe |
"{99BDF910-E26B-4215-99E4-19476FCA5199}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A4B3C692-44A3-48E1-9B70-5A4BCE15A51E}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{ADC0725F-528B-49F7-94BA-B3B376EC4CA4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AFB81F65-21AB-402D-A9E9-AFC4CE954161}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B1D2E713-CD4D-46B0-B58F-080FA90F4B8D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{B312BF45-46BE-40CC-8E6A-7AAB0CE65493}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\alexg2490\half-life\hl.exe |
"{B33DF0B8-CF79-41C2-9B4C-D88927321ADE}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{B36BC063-806D-4741-9E8E-FBE0CB850069}" = protocol=6 | dir=in | app=e:\program files\id software\enemy territory - quake wars\etqwded.exe |
"{B8614CD3-36C7-45A3-902C-2BB4A08C6DEC}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{BC588D3D-19A1-45D8-93DD-62877988803A}" = protocol=6 | dir=in | app=e:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{C02DB95B-2E22-45F2-80F7-B7CA9B2A6B3F}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{C64CABC9-135D-4999-975A-680FAA8E8B06}" = protocol=17 | dir=in | app=e:\program files\2k games\bioshock 2\sp\builds\binaries\bioshock2.exe |
"{C9C7BF72-D097-4EF1-9E3A-53C285C01FC4}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CA42114C-8A30-4701-9CC5-A387283EB331}" = protocol=6 | dir=in | app=e:\program files\lucasarts\star wars empire at war\gamedata\sweaw.exe |
"{CAA99263-D51F-4594-8F2E-6E4F03FE18A4}" = protocol=6 | dir=in | app=e:\program files\id software\enemy territory - quake wars\etqw.exe |
"{CAF1164C-A84D-48C3-9F30-E7FAF60650EB}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\alexg2490\half-life\hl.exe |
"{CD70206E-A8B4-4368-A448-8F8E0FF2DDE4}" = protocol=6 | dir=out | app=c:\program files\airvideoserver\airvideoserver.exe |
"{D222F10D-6062-4921-A915-95915B7364E8}" = protocol=6 | dir=out | app=system |
"{D389098E-0D83-47E2-ADE7-883304B65872}" = protocol=6 | dir=in | app=c:\program files\airvideoserver\airvideoserver.exe |
"{D51C2CC9-75EF-4A3D-9833-D05B6C00543C}" = protocol=17 | dir=in | app=e:\program files\lucasarts\star wars empire at war forces of corruption\swfoc.exe |
"{D616467E-9947-4A3B-8CAA-C7EA08CF7434}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{D6A127CA-BD69-4F3F-9E2A-842394D936CB}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{D88BC05E-B084-4066-8920-6F992B29FD97}" = protocol=6 | dir=in | app=e:\program files\lucasarts\star wars empire at war forces of corruption\swfoc.exe |
"{D8AE77DD-70A4-47CF-BDE2-D565E93C1AE0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DA3A86AA-5C25-420B-A99D-DDA1BD00A70A}" = dir=in | app=c:\program files\avg\avg9\avgupd.exe |
"{DF15C66F-1FD8-4F91-832D-062846A07933}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{E415C4DE-5D2B-404A-A39F-777D83BBB03A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\psychonauts\psycholauncher.exe |
"{E90A8B8E-24A9-46B9-8EBF-138A764C82B5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E91142C6-5E34-4819-B30E-8383AE034C48}" = protocol=6 | dir=in | app=e:\program files\2k games\bioshock 2\sp\builds\binaries\bioshock2.exe |
"{EE50441F-4854-4C1F-AE09-ED583018353A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\poker night at the inventory\celebritypoker.exe |
"{EF9CB30D-FE72-44FE-AA1F-58000A49C357}" = protocol=6 | dir=in | app=c:\program files\tightvnc\vncviewer.exe |
"{F1523249-AC56-4C3A-AEA8-B6D3F8A0E687}" = protocol=17 | dir=in | app=e:\program files\2k games\bioshock 2\mp\builds\binaries\bioshock2.exe |
"{F2232718-42CD-4F9A-9D41-1561D97B9428}" = protocol=17 | dir=in | app=c:\program files\tightvnc\tvnserver.exe |
"{F55707EF-5ABD-43FA-9CA5-1149CB7A859B}" = protocol=17 | dir=in | app=e:\program files\ea games\battlefield 2\bf2.exe |
"{FB745020-E98F-47A7-8C75-575750FC233D}" = protocol=6 | dir=in | app=c:\program files\airvideoserver\airvideoserver.exe |
"{FCFEF71A-C963-4C46-91B8-5AB9EF7CF379}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{FEC4538C-BD17-4787-913C-9D81B17FDD05}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{01F1FB80-6B4C-40C9-BEC3-6476278AE49E}C:\program files\lionhead studios ltd\black & white\runblack.exe" = protocol=6 | dir=in | app=c:\program files\lionhead studios ltd\black & white\runblack.exe |
"TCP Query User{06370C90-1CFA-49CA-AD2F-912CBF586A9A}C:\games\btrl\demo\fs2_open_3_6_9.exe" = protocol=6 | dir=in | app=c:\games\btrl\demo\fs2_open_3_6_9.exe |
"TCP Query User{09ED9C80-2EFE-426E-A892-42095941712E}C:\warpath 21st century\warpath21stcentury.exe" = protocol=6 | dir=in | app=c:\warpath 21st century\warpath21stcentury.exe |
"TCP Query User{09EE8907-FD5E-4364-ACA0-D79114E74B9D}E:\program files\raven\star trek voyager elite force\stvoyhm.exe" = protocol=6 | dir=in | app=e:\program files\raven\star trek voyager elite force\stvoyhm.exe |
"TCP Query User{2DB75105-A39C-4FA1-BA74-EBDC6FD2C985}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe |
"TCP Query User{2E22689C-666E-47C7-9A34-9B12726304BF}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{37728FB9-2DD3-4BE1-A81D-F41E8EC3D912}C:\program files\hamachi\hamachi.exe" = protocol=6 | dir=in | app=c:\program files\hamachi\hamachi.exe |
"TCP Query User{4CC4F338-AE8E-4BB1-9952-B654D2524CEC}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"TCP Query User{4E1BDE19-1940-4D1F-94E0-F07BCAC83E22}C:\program files\adobe\adobe contribute cs3\contribute.exe" = protocol=6 | dir=in | app=c:\program files\adobe\adobe contribute cs3\contribute.exe |
"TCP Query User{590B4CDE-8391-4558-861D-0B946376FAA5}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{6342A4FA-0575-4B8D-9CE0-421A8F37468A}E:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=e:\program files\electronic arts\eadm\core.exe |
"TCP Query User{63E119A5-9F9C-4BCA-98F5-F3A05BB4370F}E:\games\freespace2\fs2_open_3_6_10.exe" = protocol=6 | dir=in | app=e:\games\freespace2\fs2_open_3_6_10.exe |
"TCP Query User{8582388F-6383-4FB6-AAF0-9055DBAD590D}E:\program files\secondlife\slvoice.exe" = protocol=6 | dir=in | app=e:\program files\secondlife\slvoice.exe |
"TCP Query User{8703C1E7-19FE-4348-B4AF-1140D7A38F68}E:\program files\secondlife\slvoice.exe" = protocol=6 | dir=in | app=e:\program files\secondlife\slvoice.exe |
"TCP Query User{8F40EDDF-9CC5-4476-9288-992D94C375DE}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"TCP Query User{90C4C82F-7C26-4E6B-9CE3-4F59BBAAF51B}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{97DDAEBA-5341-421A-9707-6F2B2C46BD48}E:\program files\secondlife\secondlife.exe" = protocol=6 | dir=in | app=e:\program files\secondlife\secondlife.exe |
"TCP Query User{A0F7475B-F217-45E9-AD12-4A942F3ACD8D}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{B2DDD234-87A8-4A1B-800E-14F62C3E0614}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe |
"TCP Query User{B858DB10-6059-459C-80D4-39B1A5C2F606}E:\program files\ioquake3\ioquake3.x86.exe" = protocol=6 | dir=in | app=e:\program files\ioquake3\ioquake3.x86.exe |
"TCP Query User{BAFDCFFD-1E76-4792-AA9D-DCCAC1D18437}E:\program files\steam\steamapps\alexg2490\garrysmod\hl2.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\alexg2490\garrysmod\hl2.exe |
"TCP Query User{CDF110DB-D42B-469E-901A-CA438C3B7A4D}C:\warpath 21st century\mix\mix.exe" = protocol=6 | dir=in | app=c:\warpath 21st century\mix\mix.exe |
"TCP Query User{CF481168-7AE7-4ACF-AA78-4A527DDC9E9C}E:\program files\starcraft\starcraft.exe" = protocol=6 | dir=in | app=e:\program files\starcraft\starcraft.exe |
"TCP Query User{E92D7B2B-AB67-4DAE-8255-767161109D2F}E:\program files\electronic arts\battlefield 2142\bf2142pace.exe" = protocol=6 | dir=in | app=e:\program files\electronic arts\battlefield 2142\bf2142pace.exe |
"TCP Query User{F8822BB9-D2CF-4720-B1AE-04A94A28FA0B}C:\program files\talkshoe\pjsua_win.exe" = protocol=6 | dir=in | app=c:\program files\talkshoe\pjsua_win.exe |
"TCP Query User{FB4F60C0-DA0A-4C44-88EF-543B0F1FF958}E:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=e:\program files\electronic arts\eadm\core.exe |
"UDP Query User{3D8238A1-3374-4688-99F3-7CFA89CADFAA}E:\games\freespace2\fs2_open_3_6_10.exe" = protocol=17 | dir=in | app=e:\games\freespace2\fs2_open_3_6_10.exe |
"UDP Query User{451DBD19-2BF1-443B-93B7-0F81C266AE05}E:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=e:\program files\electronic arts\eadm\core.exe |
"UDP Query User{4724A973-50B4-48CB-8B9A-BD2809C42357}E:\program files\secondlife\slvoice.exe" = protocol=17 | dir=in | app=e:\program files\secondlife\slvoice.exe |
"UDP Query User{498600A8-FEE3-4BFE-9EFE-AF046F4E661D}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{564C729C-E7DD-49B3-851D-D258ED3B22B6}C:\warpath 21st century\warpath21stcentury.exe" = protocol=17 | dir=in | app=c:\warpath 21st century\warpath21stcentury.exe |
"UDP Query User{5F8A9C2C-BFF5-44B3-9130-F35D17614B6B}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"UDP Query User{64073F06-8B94-4FC7-8323-CB2B9200EE5B}E:\program files\electronic arts\battlefield 2142\bf2142pace.exe" = protocol=17 | dir=in | app=e:\program files\electronic arts\battlefield 2142\bf2142pace.exe |
"UDP Query User{68A78BCD-3044-4F11-934D-3E2F6EAEA1BE}C:\program files\talkshoe\pjsua_win.exe" = protocol=17 | dir=in | app=c:\program files\talkshoe\pjsua_win.exe |
"UDP Query User{71DD6D83-30BD-4F89-B46B-CD03AD4D08CB}E:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=e:\program files\electronic arts\eadm\core.exe |
"UDP Query User{7737D17B-8DF9-4333-A0AB-8722147C9A49}E:\program files\secondlife\secondlife.exe" = protocol=17 | dir=in | app=e:\program files\secondlife\secondlife.exe |
"UDP Query User{8297DE40-A741-4834-B8A2-3991845AA95E}E:\program files\secondlife\slvoice.exe" = protocol=17 | dir=in | app=e:\program files\secondlife\slvoice.exe |
"UDP Query User{84515103-33C0-4562-9EDE-17ED4AEED24C}C:\program files\adobe\adobe contribute cs3\contribute.exe" = protocol=17 | dir=in | app=c:\program files\adobe\adobe contribute cs3\contribute.exe |
"UDP Query User{92BCB4F1-E4C4-4B75-BF5F-0FB939FDD1CA}C:\program files\hamachi\hamachi.exe" = protocol=17 | dir=in | app=c:\program files\hamachi\hamachi.exe |
"UDP Query User{9E9BCD27-0AAA-4964-9232-42D00F57A858}E:\program files\raven\star trek voyager elite force\stvoyhm.exe" = protocol=17 | dir=in | app=e:\program files\raven\star trek voyager elite force\stvoyhm.exe |
"UDP Query User{A58DD528-3E77-482C-B68D-EEE7E7174F32}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"UDP Query User{A60DE08E-E49E-4BC3-A198-74C5023401A5}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe |
"UDP Query User{B3544FAB-F73C-48D7-8C40-7F73E00A5888}C:\games\btrl\demo\fs2_open_3_6_9.exe" = protocol=17 | dir=in | app=c:\games\btrl\demo\fs2_open_3_6_9.exe |
"UDP Query User{CB31A1DA-6851-488A-9E2C-BA4BC05D34DC}E:\program files\ioquake3\ioquake3.x86.exe" = protocol=17 | dir=in | app=e:\program files\ioquake3\ioquake3.x86.exe |
"UDP Query User{CD323C67-BAAD-4EEF-8FE0-1CE2326E2E1F}E:\program files\steam\steamapps\alexg2490\garrysmod\hl2.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\alexg2490\garrysmod\hl2.exe |
"UDP Query User{CF834112-656B-411B-B613-6EC6B19DFC01}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{D5133E4E-5B2D-4449-BDBA-4DAA7C0A67AC}C:\program files\lionhead studios ltd\black & white\runblack.exe" = protocol=17 | dir=in | app=c:\program files\lionhead studios ltd\black & white\runblack.exe |
"UDP Query User{D5D6D3DA-C47E-43BF-A9F5-25A3EEA3C6D6}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe |
"UDP Query User{DD147613-004F-4160-9A84-D0AA368C826B}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{DD8584FE-C8B4-403D-8B06-CBFE566400EC}C:\warpath 21st century\mix\mix.exe" = protocol=17 | dir=in | app=c:\warpath 21st century\mix\mix.exe |
"UDP Query User{EAB29115-6D33-48AE-AC8A-7232A8C746C8}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{FD9E9B09-B75D-4C8A-82A4-7D7AEB4605AA}E:\program files\starcraft\starcraft.exe" = protocol=17 | dir=in | app=e:\program files\starcraft\starcraft.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
""Christmas" template for ConvertXToDVD 3_is1" = "Christmas" template for ConvertXToDVD 3
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis(R)
"{004685F7-9FB6-4789-812F-59ABB34A55AF}" = Adobe Setup
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{012048E1-BFFF-682E-8FA2-8325B2B16784}" = TweetDeck
"{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
"{0327FA9D-975C-448C-A086-577D57BB25B8}" = Adobe Soundbooth CS3 Codecs
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0C321D1F-2262-42C2-94C5-5E5765507C72}" = Star Wars Starfighter
"{0D005F09-A5F4-473B-A901-5735C6AF5628}" = Silent Hunter Wolves of the Pacific
"{0D025345-1033-4F35-A5CE-68CDCDE6CC03}" = Evernote
"{1446A30C-6DAF-461E-96B1-31C554870082}_is1" = Tag - IGF Professional 2008
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}" = Adobe After Effects CS3 Presets
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1D58229F-C505-45CA-8223-F35F3A34B963}" = Adobe Version Cue CS3 Server
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{287A4E96-AC57-4A19-9B51-C5EED2EAB382}" = Star Trek Legacy
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2A9A40C7-6670-4D5F-8F41-D12E2E08B48B}" = Star Wars Knights of the Old Republic
"{2AAD0AD0-99DB-4C13-9796-D4205949B447}" = Scrabble 2
"{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}" = Microsoft Games for Windows - LIVE
"{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
"{3C6B103A-1CDD-B3F2-5E8C-A2E5AAA6B555}" = GOG.com Downloader
"{3F99D180-34C3-4151-8C6C-86FC5D7BDFBD}" = Hoyle Casino
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{4458C442-7376-4CF9-AF58-E8CEA6722363}" = Adobe Setup
"{485ACF57-F364-440A-8496-E1E81C8FA1AA}" = Adobe Premiere Pro CS3 Third Party Content
"{491CE650-2867-4AF3-8B66-E2A8847AA4EB}" = Pradis 6: Understanding the Bible Library 6.0
"{49DB3527-121C-4E11-83FA-1016BECFA2DA}_is1" = "Film" template for ConvertXToDVD 3
"{4A8B461A-9336-4CF9-98F4-14DD38E673F0}" = BioShock 2
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows
"{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}" = Adobe Premiere Pro CS3 Functional Content
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}" = Adobe Encore CS3
"{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}" = Adobe Premiere Pro CS3
"{5DC6B387-DCD5-4B66-B866-434020FF2ECC}" = TortoiseSVN 1.6.7.18415 (32 bit)
"{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}" = GameSpy Comrade
"{6592FDEC-2C1A-413A-9985-25FEC2F0848D}" = Star Wars Empire at War Forces of Corruption
"{66333C41-085E-4DA1-8273-E2BCA382D766}" = NET Installation Assistance for VB6 App (Runtime Only)
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7546C4F7-5E12-4E46-BF59-323924C2456B}_is1" = "Champetre" template for ConvertXToDVD 3
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.8.0.193f
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7ACFB90E-8FD0-4397-AD3A-5195412623A3}" = Adobe Help Viewer CS3
"{7C0759C8-4C6C-4AD7-89B8-0842C4C44F23}" = Jeopardy! 2003
"{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}" = Adobe Dreamweaver CS3
"{7DFC1012-D346-46CE-B03E-FF79125AE029}" = Adobe Fireworks CS3
"{7ECEF10B-F1C2-4FD5-861F-A3FCB4653304}" = Adobe After Effects CS3 Third Party Content
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
"{8681B1E6-CD96-46EF-9065-CE0D1085ED99}" = Star Wars JK II Jedi Outcast
"{8718DC03-D066-4957-94E5-50C3C5042E8E}" = Adobe Creative Suite 3 Master Collection
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}" = Logitech QuickCam
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9720C029-0C2C-4D1E-9DE0-E89971C4C8C7}" = Silent Hunter III
"{99AE7207-8612-4DBA-A8F8-BAE5C633390D}" = Star Wars Empire at War
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A589DA26-51BD-475D-8C32-E19E34145842}" = Camtasia Studio 6
"{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}" = Adobe Soundbooth CS3
"{A785BBA7-3FB9-4D81-BC35-4A2028915ACB}" = Prey
"{A8DBF55D-73C0-4E37-A10E-365BFBB14119}" = Battlefield 2 Complete Collection
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
"{B7A585C8-CE4E-4150-84C6-A13C3CB1379F}" = Enemy Territory - Quake Wars(TM)
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}" = Adobe Encore CS3 Codecs
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{C79CB9C7-10A4-4814-8402-F574672C2192}" = Star Wars Battlefront
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB3F8375-B600-4B9F-83C9-238ED1E583FD}" = Adobe InDesign CS3
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1A74FBB-CA8D-4CCA-9B89-BAAA436DB178}" = iTunes
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
"{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}" = Far Cry
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{D9354DD0-C69A-469A-8A48-B9AA15A74174}" = Space Quest Collection(TM)
"{D98C9637-93DA-44DB-B73A-B11A1192AB26}" = GameShadow
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DFAE9340-E8BB-4433-9A08-C8334DAFE1B9}" = Star Wars Republic Commando
"{E51B4CD9-A0A6-4324-B26A-31B3F2DE26CE}" = Black and White
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{EB0202F7-016A-410C-ADE4-40F848CCC661}" = Adobe After Effects CS3
"{ED50ECE9-EC54-4C05-B5ED-EE4741A9F2EC}" = Battlefield 2142
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1D9C08A-10B4-29A5-3EF4-C54F14BD4282}" = TWiT Live Desktop
"{F2527115-B8BF-4FDB-B5DA-5AADFB7C13E1}" = The Sims Complete Collection
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}" = Adobe Contribute CS3
"ABC Amber LIT Converter" = ABC Amber LIT Converter
"Activision_StarTrekArmadaUninstallKey" = Star Trek: Armada
"Ad-Aware" = Ad-Aware
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8.1.3 Professional
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_3675c95c239b992d5d0ee8fce969b9e" = Adobe After Effects CS3 Third Party Content
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_4dcfd9b7e901b57f81f667144603236" = Add or Remove Adobe Creative Suite 3 Master Collection
"AIM_7" = AIM 7
"Aimersoft Video Studio Express_is1" = Aimersoft Video Studio Express(Build 1.2.0.25)
"Air Video Server" = Air Video Server 2.4.1
"AJCompressCopy" = AJScreensaver
"Audacity_is1" = Audacity 1.2.6
"AudibleManager" = AudibleManager
"AudioShell_is1" = AudioShell 1.3.5
"AutoGK" = Auto Gordian Knot 2.55
"AviSynth" = AviSynth 2.5
"Beyond the Red Line 1.0" = Beyond the Red Line
"BIMPLite" = BIMP Lite 1.62
"BitTorrent" = BitTorrent
"BlockCAD3.19_is1" = BlockCAD 3.19
"BN_DesktopReader" = Barnes & Noble Desktop Reader
"CamStudio" = CamStudio
"Celestia_is1" = Celestia 1.6.0
"com.gog.downloader.87F90EC6C28C7E479115BE2E026DB87A08BC420D.1" = GOG.com Downloader
 
Extras Continued from above
"com.peterelst.twitlivedesktop.9D94051F60D28C644C841A09CCF1BAF0E2819EED.1" = TWiT Live Desktop
"Comparator" = Comparator
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.55
"dBpowerAMP Music Converter" = dBpowerAMP Music Converter
"Descent and Descent 2_is1" = Descent and Descent 2
"Descent Manager Tools" = Descent Manager Tools
"Doctor Who - The Adventure Games" = Doctor Who - The Adventure Games 3.0
"Download Manager" = Download Manager 2.3.9
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"EADM" = EA Download Manager
"Easy Video Splitter_is1" = Easy Video Splitter 1.28
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"FeedForAll v2.0" = FeedForAll v2.0
"FileZilla Client" = FileZilla Client 3.3.4.1
"Flash Slideshow Maker Pro" = Flash Slideshow Maker Pro 5.00
"Fraps" = Fraps (remove only)
"Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 6.1
"FreeSpace2" = FreeSpace 2
"GameSpy Arcade" = GameSpy Arcade
"GoldWave v5.22" = GoldWave v5.22
"GoldWave v5.52" = GoldWave v5.52
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"Graphing Calculator 3D_is1" = Graphing Calculator 3D 3.1
"HandBrake" = HandBrake 0.9.3
"ImgBurn" = ImgBurn
"InstallShield_{491CE650-2867-4AF3-8B66-E2A8847AA4EB}" = Pradis 6: Understanding the Bible Library 6.0
"InstallShield_{9720C029-0C2C-4D1E-9DE0-E89971C4C8C7}" = Silent Hunter III
"InstallShield_{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}" = Far Cry
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LucasArts' Jedi Knight" = LucasArts' Jedi Knight
"LucasArts' X-Wing Alliance" = LucasArts' X-Wing Alliance
"lvdrivers_11.50" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MechWarrior 3" = MechWarrior 3
"MechWarrior 3 Pirate's Moon" = MechWarrior 3 Pirate's Moon
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"Notepad++" = Notepad++
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"PageNest_is1" = PageNest
"Pamela" = Pamela Pro 4.6
"Peggle Deluxe 1.0" = Peggle Deluxe 1.0
"PowerISO" = PowerISO
"PunkBusterSvc" = PunkBuster Services
"Scrivener for Windows Beta 1" = Scrivener for Windows Beta
"SecondLife" = SecondLife (remove only)
"SecondLifeViewer2" = SecondLifeViewer2 (remove only)
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SpaceBattle ScreenSaver" = SpaceBattle ScreenSaver 3.1
"SpeedFan" = SpeedFan (remove only)
"Star Trek Elite Force II" = Star Trek Elite Force II
"Starcraft" = Starcraft
"Steam App 12900" = Audiosurf
"Steam App 130" = Half-Life: Blue Shift
"Steam App 31280" = Poker Night at the Inventory
"Steam App 32390" = Star Wars Jedi Knight: Mysteries of the Sith
"Steam App 3830" = Psychonauts
"Steam App 400" = Portal
"Steam App 4000" = Garry's Mod
"Steam App 50" = Opposing Force
"Steam App 500" = Left 4 Dead
"Steam App 550" = Left 4 Dead 2
"Steam App 70" = Half-Life
"Steam App 7940" = Call of Duty 4: Modern Warfare
"SubtitleWorkshop" = Subtitle Workshop 2.51
"SystemRequirementsLab" = System Requirements Lab
"TalkShoe Live! 2.0" = TalkShoe Live! 2.0
"Tardis Screensaver- Widescreen" = Tardis Screensaver- Widescreen
"TightVNC" = TightVNC 2.0.2
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"TWiT TV" = TWiT TV
"Uber Jedi Suite" = Über Jedi Mod Manager
"UltraLott Powerball and Mega Millions_is1" = UltraLott Powerball and Mega Millions 1.2.6
"UltSounds" = Windows Sound Schemes
"UltSounds2" = Ultimate Extras sounds from Microsoft® Tinker™
"VISPRO" = Microsoft Office Visio Professional 2007
"VLC media player" = VLC media player 1.0.1
"VobSub" = VobSub v2.23 (Remove Only)
"WAV to MP3 Encoder" = WAV to MP3 Encoder
"Winamp" = Winamp
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.43-9C
"WinPatrol" = WinPatrol
"WinRAR archiver" = WinRAR archiver
"WordWeb" = WordWeb
"Xfire" = Xfire (remove only)
"XfireXO Toolbar" = XfireXO Toolbar
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-770543726-423754612-1244475062-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Knight" = Knight
"Winamp Detect" = Winamp Detector Plug-in
"WinDirStat" = WinDirStat 1.1.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/24/2011 1:07:16 AM | Computer Name = Alex-PC | Source = WinMgmt | ID = 10
Description =

Error - 1/24/2011 1:08:59 AM | Computer Name = Alex-PC | Source = Perflib | ID = 1008
Description =

Error - 1/25/2011 12:22:15 AM | Computer Name = Alex-PC | Source = WinMgmt | ID = 10
Description =

Error - 1/25/2011 12:23:19 AM | Computer Name = Alex-PC | Source = Perflib | ID = 1010
Description =

Error - 1/25/2011 12:25:32 AM | Computer Name = Alex-PC | Source = WinMgmt | ID = 10
Description =

Error - 1/25/2011 12:27:34 AM | Computer Name = Alex-PC | Source = Perflib | ID = 1010
Description =

Error - 1/25/2011 11:05:07 AM | Computer Name = Alex-PC | Source = WinMgmt | ID = 10
Description =

Error - 1/25/2011 11:06:40 AM | Computer Name = Alex-PC | Source = Perflib | ID = 1008
Description =

Error - 1/26/2011 12:28:51 AM | Computer Name = Alex-PC | Source = Perflib | ID = 1010
Description =

Error - 1/27/2011 12:28:51 AM | Computer Name = Alex-PC | Source = Perflib | ID = 1010
Description =

[ Media Center Events ]
Error - 10/15/2009 2:27:09 AM | Computer Name = Alex-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.SqmFlushSession failed; Win32 GetLastError
returned 0D Process: DefaultDomain Object Name: Media Center Guide

[ System Events ]
Error - 1/24/2011 11:41:57 PM | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7030
Description =

Error - 1/25/2011 12:21:56 AM | Computer Name = Alex-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:41:59 PM on 1/24/2011 was unexpected.

Error - 1/25/2011 12:22:00 AM | Computer Name = Alex-PC | Source = HTTP | ID = 15016
Description =

Error - 1/25/2011 12:22:15 AM | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 1/25/2011 12:25:18 AM | Computer Name = Alex-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:22:42 PM on 1/24/2011 was unexpected.

Error - 1/25/2011 12:25:20 AM | Computer Name = Alex-PC | Source = HTTP | ID = 15016
Description =

Error - 1/25/2011 12:25:33 AM | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 1/25/2011 11:04:50 AM | Computer Name = Alex-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:57:57 AM on 1/25/2011 was unexpected.

Error - 1/25/2011 11:04:55 AM | Computer Name = Alex-PC | Source = HTTP | ID = 15016
Description =

Error - 1/25/2011 11:05:11 AM | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
 
OTL:
OTL logfile created on: 1/27/2011 7:43:46 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Alex\Desktop
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 60.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 32.23 Gb Free Space | 21.62% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 291.38 Gb Free Space | 62.56% Space Free | Partition Type: NTFS
Drive G: | 465.76 Gb Total Space | 274.98 Gb Free Space | 59.04% Space Free | Partition Type: NTFS
Drive I: | 1863.01 Gb Total Space | 920.53 Gb Free Space | 49.41% Space Free | Partition Type: NTFS

Computer Name: ALEX-PC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/27 07:42:34 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
PRC - [2011/01/19 21:46:40 | 000,936,712 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/01/19 21:46:39 | 001,402,272 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010/10/18 23:14:18 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
PRC - [2010/09/13 16:29:40 | 004,917,384 | ---- | M] () -- C:\Program Files\AirVideoServer\AirVideoServer.exe
PRC - [2010/07/08 06:28:56 | 000,815,704 | ---- | M] (GlavSoft LLC.) -- C:\Program Files\TightVNC\tvnserver.exe
PRC - [2010/05/31 04:18:16 | 000,323,976 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2010/02/07 12:00:56 | 007,661,587 | ---- | M] () -- C:\Program Files\AirVideoServer\ffmpeg.exe
PRC - [2010/01/22 19:36:00 | 000,621,320 | ---- | M] (http://tortoisesvn.net) -- C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
PRC - [2009/08/16 15:05:12 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/07/14 11:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/10/28 23:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/06/12 21:17:01 | 000,042,168 | ---- | M] (Antony Lewis) -- C:\Program Files\WordWeb\wweb32.exe
PRC - [2008/02/26 15:24:06 | 004,939,776 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007/10/19 13:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
PRC - [2007/05/28 09:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe


========== Modules (SafeList) ==========

MOD - [2011/01/27 07:42:34 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
MOD - [2008/01/20 19:21:54 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
MOD - [2007/10/19 13:19:10 | 000,109,080 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcInj.dll
MOD - [2007/03/26 11:03:20 | 000,057,344 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/01/19 21:46:39 | 001,402,272 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011/01/11 07:40:40 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/07/08 06:28:56 | 000,815,704 | ---- | M] (GlavSoft LLC.) [Auto | Running] -- C:\Program Files\TightVNC\tvnserver.exe -- (tvnserver)
SRV - [2009/08/25 11:00:37 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/07/14 11:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/01/20 19:21:41 | 000,272,952 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/10/19 13:21:16 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2007/10/19 13:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2007/05/28 09:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2007/03/20 15:41:24 | 000,153,792 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe -- (Adobe Version Cue CS3)


========== Driver Services (SafeList) ==========

DRV - [2010/07/12 01:55:39 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010/07/09 12:18:54 | 000,020,328 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\cpuz134_x32.sys -- (cpuz134)
DRV - [2009/12/16 16:27:00 | 000,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2009/12/16 16:26:58 | 000,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/12/16 16:26:56 | 000,074,480 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2009/11/20 23:19:33 | 000,716,272 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2009/09/23 09:41:58 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2009/07/14 11:54:00 | 009,557,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/08/18 17:58:00 | 000,145,952 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2008/08/01 18:51:14 | 001,052,704 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2008/02/26 15:10:22 | 002,070,304 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/01/20 19:21:35 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008/01/20 19:21:35 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008/01/20 19:21:35 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008/01/20 19:21:34 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008/01/20 19:21:34 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008/01/20 19:21:34 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008/01/20 19:21:33 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008/01/20 19:21:33 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008/01/20 19:21:33 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2008/01/20 19:21:33 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008/01/20 19:21:32 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008/01/20 19:21:32 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008/01/20 19:21:32 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2008/01/20 19:21:31 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008/01/20 19:21:31 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008/01/20 19:21:31 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008/01/20 19:21:31 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008/01/20 19:21:30 | 000,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008/01/20 19:21:29 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008/01/20 19:21:29 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008/01/20 19:21:29 | 000,073,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/01/20 19:21:29 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008/01/20 19:21:28 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008/01/20 19:21:09 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008/01/20 19:21:09 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008/01/20 19:21:09 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/10/19 13:16:30 | 002,109,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/10/11 19:00:42 | 000,041,752 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/10/11 18:59:24 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007/10/11 18:59:02 | 002,142,488 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/08/06 17:15:07 | 000,033,052 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007/05/09 21:47:00 | 001,276,832 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2006/11/18 12:29:48 | 000,312,832 | ---- | M] (Belkin) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BLKWGDv8.sys -- (BLKWGDv8)
DRV - [2006/11/02 02:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 02:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 02:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 02:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 02:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 02:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 02:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 02:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 02:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 02:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 02:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 01:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 01:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 01:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 01:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 01:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 01:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 00:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/09/24 06:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\Windows\system32\speedfan.sys -- (speedfan)
DRV - [1996/04/03 12:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-770543726-423754612-1244475062-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-770543726-423754612-1244475062-1000\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-770543726-423754612-1244475062-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-770543726-423754612-1244475062-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "XfireXO Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource=3&q={searchTerms}"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: multilinks@plugin:2.0.0.17
FF - prefs.js..extensions.enabledItems: {5e5ab302-7f65-44cd-8211-c1d4caaccea3}:2.5.6.0
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&q="


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2010/12/12 21:13:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2010/12/12 21:13:06 | 000,000,000 | ---D | M]

[2009/08/22 08:26:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions
[2011/01/04 21:02:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\14mmi5nt.default\extensions
[2010/05/30 13:53:58 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\14mmi5nt.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/30 13:53:58 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\14mmi5nt.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2010/10/27 07:08:46 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\14mmi5nt.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/05/31 08:10:39 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\14mmi5nt.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/05/31 08:41:32 | 000,000,000 | ---D | M] (Multi Links) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\14mmi5nt.default\extensions\multilinks@plugin
[2009/11/13 02:25:04 | 000,000,917 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\14mmi5nt.default\searchplugins\conduit.xml
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG9\FIREFOX
[2009/09/27 18:17:36 | 000,000,000 | ---D | M] (Java Console) -- E:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009/12/26 21:42:54 | 000,000,000 | ---D | M] (Java Console) -- E:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

O1 HOSTS File: ([2011/01/24 20:41:55 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-770543726-423754612-1244475062-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-770543726-423754612-1244475062-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-770543726-423754612-1244475062-1000\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [tvncontrol] C:\Program Files\TightVNC\tvnserver.exe (GlavSoft LLC.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKU\S-1-5-21-770543726-423754612-1244475062-1000..\Run: [AirVideoServer] C:\Program Files\AirVideoServer\AirVideoServer.exe ()
O4 - HKU\S-1-5-21-770543726-423754612-1244475062-1000..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe ()
O4 - HKU\S-1-5-21-770543726-423754612-1244475062-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe (Antony Lewis)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-770543726-423754612-1244475062-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-770543726-423754612-1244475062-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Evernote - E:\Program Files\Evernote\Evernote3\enbar.dll (Evernote Corporation)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - E:\Program Files\Evernote\Evernote3\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - E:\Program Files\Evernote\Evernote3\enbar.dll (Evernote Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab (Device Detection)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/downl...-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab (CDownloadCtrl Object)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Dont Panic.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Dont Panic.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codec - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.dvsd - C:\Windows\System32\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.I420 - C:\Windows\System32\LVCodec2.dll (Logitech Inc.)
Drivers32: vidc.tscc - C:\Windows\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/01/27 07:42:33 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
[2011/01/25 21:42:04 | 000,000,000 | ---D | C] -- C:\Users\Alex\Desktop\bootkit_remover
[2011/01/24 20:46:16 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/01/24 20:46:12 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/01/24 20:46:12 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Local\temp
[2011/01/24 20:29:03 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/01/18 21:36:16 | 000,000,000 | ---D | C] -- C:\Users\Alex\Documents\Aimersoft Video Studio Express
[2011/01/18 21:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aimersoft
[2011/01/18 21:35:59 | 000,000,000 | ---D | C] -- C:\Program Files\Aimersoft
[2011/01/18 21:06:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy Video Splitter
[2011/01/18 21:06:28 | 000,000,000 | ---D | C] -- C:\Program Files\Easy Video Splitter
[2011/01/17 20:33:58 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpaceBattle ScreenSaver
[2011/01/17 20:33:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpaceBattle ScreenSaver
[2011/01/17 20:33:43 | 000,000,000 | ---D | C] -- C:\Program Files\SpaceBattle ScreenSaver
[2011/01/11 21:15:40 | 000,000,000 | ---D | C] -- C:\wav2voc
[2011/01/09 01:09:21 | 000,000,000 | ---D | C] -- C:\bmpdf
[2011/01/08 14:53:13 | 000,000,000 | ---D | C] -- C:\Windows\System32\Adobe
[2011/01/08 11:14:34 | 000,000,000 | ---D | C] -- C:\WDFUSE
[2010/12/28 22:39:00 | 000,000,000 | ---D | C] -- C:\Users\Alex\Documents\Telltale Games
[2009/09/06 08:35:27 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Alex\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011/01/27 07:42:34 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
[2011/01/27 07:19:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/27 06:04:54 | 000,005,008 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/27 06:04:54 | 000,005,008 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/27 04:28:28 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{D0500D9A-B244-4FCF-A56A-701030FBCBD2}.job
[2011/01/27 02:23:20 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011/01/27 00:19:00 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/25 21:41:53 | 000,039,605 | ---- | M] () -- C:\Users\Alex\Desktop\bootkit_remover.rar
[2011/01/25 20:05:13 | 000,095,232 | ---- | M] () -- C:\Users\Alex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/25 08:05:10 | 000,271,006 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011/01/25 08:05:08 | 000,271,006 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011/01/25 08:04:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/01/25 08:04:40 | 2145,873,920 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/25 08:04:26 | 208,641,798 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/01/24 20:41:55 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/01/22 16:37:21 | 000,607,118 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/01/22 16:37:21 | 000,106,014 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/01/18 21:55:54 | 000,098,304 | RHS- | M] () -- C:\Windows\System32\FXSCOVERS.dll
[2011/01/17 20:33:59 | 000,000,964 | ---- | M] () -- C:\Users\Alex\Desktop\SBSS Configuration Editor.lnk
[2011/01/17 20:33:59 | 000,000,555 | ---- | M] () -- C:\Users\Alex\Desktop\SpaceBattleSS.lnk
[2011/01/16 20:43:11 | 011,129,926 | ---- | M] () -- C:\Users\Alex\Desktop\mischief still managed.mp3
[2011/01/16 20:18:35 | 000,419,840 | ---- | M] () -- C:\Users\Alex\Desktop\silentfear.MSWMM
[2011/01/16 00:06:22 | 044,316,724 | ---- | M] () -- C:\Users\Alex\Desktop\mypart2.mp3
[2011/01/04 21:24:45 | 000,035,904 | ---- | M] () -- C:\Users\Alex\Desktop\strictdroid.png
[2011/01/01 21:32:02 | 000,001,178 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\vso_ts_preview.xml
[2011/01/01 14:11:03 | 000,048,487 | ---- | M] () -- C:\Users\Alex\Desktop\ProMDBilling2.png
[2011/01/01 12:34:02 | 000,005,651 | ---- | M] () -- C:\Users\Alex\Desktop\ProMDBilling.png
[2010/12/29 22:07:47 | 000,049,010 | ---- | M] () -- C:\Users\Alex\Desktop\Star Trek Books DJ.xlsx
 
OTL Continued from above:
========== Files Created - No Company Name ==========

[2011/01/25 21:41:53 | 000,039,605 | ---- | C] () -- C:\Users\Alex\Desktop\bootkit_remover.rar
[2011/01/20 19:35:39 | 2145,873,920 | -HS- | C] () -- C:\hiberfil.sys
[2011/01/18 21:55:54 | 000,098,304 | RHS- | C] () -- C:\Windows\System32\FXSCOVERS.dll
[2011/01/17 20:33:59 | 000,000,964 | ---- | C] () -- C:\Users\Alex\Desktop\SBSS Configuration Editor.lnk
[2011/01/17 20:33:59 | 000,000,555 | ---- | C] () -- C:\Users\Alex\Desktop\SpaceBattleSS.lnk
[2011/01/16 20:42:55 | 011,129,926 | ---- | C] () -- C:\Users\Alex\Desktop\mischief still managed.mp3
[2011/01/16 00:49:44 | 000,419,840 | ---- | C] () -- C:\Users\Alex\Desktop\silentfear.MSWMM
[2011/01/16 00:04:35 | 044,316,724 | ---- | C] () -- C:\Users\Alex\Desktop\mypart2.mp3
[2011/01/04 21:24:44 | 000,035,904 | ---- | C] () -- C:\Users\Alex\Desktop\strictdroid.png
[2011/01/01 14:10:57 | 000,048,487 | ---- | C] () -- C:\Users\Alex\Desktop\ProMDBilling2.png
[2011/01/01 12:34:01 | 000,005,651 | ---- | C] () -- C:\Users\Alex\Desktop\ProMDBilling.png
[2010/12/29 22:07:33 | 000,049,010 | ---- | C] () -- C:\Users\Alex\Desktop\Star Trek Books DJ.xlsx
[2010/05/27 17:09:00 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2010/04/21 19:34:55 | 000,000,024 | ---- | C] () -- C:\Windows\SW_Win3112X32.DLL
[2010/04/21 19:34:48 | 001,720,320 | ---- | C] () -- C:\Windows\System32\beconvlib.dll
[2010/04/21 19:34:48 | 000,282,624 | ---- | C] () -- C:\Windows\System32\bprgcomm.dll
[2010/04/21 19:34:48 | 000,131,072 | ---- | C] () -- C:\Windows\System32\CSVSpecialProcessing.dll
[2010/04/21 19:34:48 | 000,000,530 | ---- | C] () -- C:\Windows\System32\tx151ic.ini
[2010/04/21 19:34:47 | 000,221,184 | ---- | C] () -- C:\Windows\System32\SII_PDF.dll
[2010/04/21 19:34:47 | 000,102,400 | ---- | C] () -- C:\Windows\System32\SARzilla.dll
[2010/04/21 19:34:47 | 000,098,304 | ---- | C] () -- C:\Windows\System32\DVM.dll
[2010/04/06 20:53:05 | 000,000,165 | ---- | C] () -- C:\Users\Alex\AppData\Local\RAExpertHistory.xml
[2010/02/18 07:21:01 | 000,000,564 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\AutoGK.ini
[2010/02/13 12:25:56 | 000,000,760 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\setup_ldm.iss
[2010/01/28 20:19:33 | 000,000,162 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/11/06 09:58:04 | 000,178,975 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2009/09/15 20:43:44 | 000,004,252 | ---- | C] () -- C:\Windows\warp1px.drv
[2009/09/14 09:41:18 | 000,034,308 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2009/09/09 19:15:59 | 000,000,725 | ---- | C] () -- C:\Windows\EF2.INI
[2009/09/06 08:36:19 | 000,001,178 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\vso_ts_preview.xml
[2009/09/06 08:35:48 | 000,000,034 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\pcouffin.log
[2009/09/06 08:35:28 | 000,007,887 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\pcouffin.cat
[2009/09/06 08:35:27 | 000,001,144 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\pcouffin.inf
[2009/08/25 11:05:52 | 002,463,976 | ---- | C] () -- C:\Windows\System32\NPSWF32.dll
[2009/08/17 13:25:45 | 000,139,152 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\PnkBstrK.sys
[2009/08/17 13:25:45 | 000,138,520 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009/08/17 13:19:49 | 000,000,316 | ---- | C] () -- C:\Windows\game.ini
[2009/08/16 17:07:39 | 000,095,232 | ---- | C] () -- C:\Users\Alex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/16 14:54:08 | 000,271,006 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/08/16 14:54:07 | 000,271,006 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/08/15 21:54:18 | 000,000,680 | ---- | C] () -- C:\Users\Alex\AppData\Local\d3d9caps.dat
[2009/01/25 14:10:48 | 000,179,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/01/08 16:01:22 | 000,629,760 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2008/10/07 08:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008/01/20 19:23:41 | 000,081,158 | ---- | C] () -- C:\Windows\System32\manage-bde.ini.en
[2007/10/11 18:59:24 | 000,025,624 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2007/05/09 20:35:54 | 000,057,126 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2006/11/02 05:34:20 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2002/10/15 15:54:04 | 000,153,088 | ---- | C] () -- C:\Windows\System32\unrar.dll
[1996/04/03 12:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2010/07/05 09:33:54 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\acccore
[2010/04/10 10:36:28 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Barnes & Noble
[2011/01/20 18:28:37 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\BC3FC61EBD2390BE003660698B68EBA6
[2010/08/14 11:18:08 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Bioshock
[2010/09/19 13:15:04 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Bioshock2
[2010/12/28 19:52:10 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\BitTorrent
[2009/08/26 09:10:52 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\com.gog.downloader.87F90EC6C28C7E479115BE2E026DB87A08BC420D.1
[2010/06/12 07:17:13 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\com.peterelst.twitlivedesktop.9D94051F60D28C644C841A09CCF1BAF0E2819EED.1
[2010/12/19 22:30:52 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Doctor Who
[2011/01/17 20:41:49 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\FileZilla
[2009/09/03 22:18:44 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Hoyle Casino
[2009/09/03 21:38:58 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Hoyle FaceCreator
[2009/09/06 09:49:39 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\ImgBurn
[2010/08/25 19:13:03 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Notepad++
[2010/10/28 21:55:02 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\PACE Anti-Piracy
[2010/01/28 19:35:02 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Pamela
[2009/09/03 10:30:54 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Petroglyph
[2009/11/13 22:24:29 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Quake3
[2009/09/28 06:56:31 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Runiter
[2010/08/14 22:27:57 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\SecondLife
[2010/03/21 20:11:53 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Subversion
[2010/09/03 19:43:09 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\TightVNC
[2010/09/04 10:13:35 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2011/01/01 21:32:03 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Vso
[2010/05/31 08:32:34 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\WebStripper
[2010/06/13 07:03:05 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\WinPatrol
[2009/09/28 06:54:15 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\WordWeb
[2011/01/21 21:20:33 | 000,032,520 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/01/27 04:28:28 | 000,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{D0500D9A-B244-4FCF-A56A-701030FBCBD2}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/08/18 17:20:29 | 000,001,024 | ---- | M] () -- C:\.rnd
[2006/09/18 14:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2010/01/28 20:48:40 | 000,001,180 | ---- | M] () -- C:\bar.emf
[2008/01/20 19:22:49 | 000,333,203 | RHS- | M] () -- C:\bootmgr
[2009/08/15 22:13:21 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006/09/18 14:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010/02/28 16:03:39 | 000,000,762 | ---- | M] () -- C:\DXL_Log.rtf
[2008/04/14 18:51:45 | 000,171,136 | RHS- | M] () -- C:\grldr
[2011/01/25 08:04:40 | 2145,873,920 | -HS- | M] () -- C:\hiberfil.sys
[2009/08/16 19:58:32 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/07/05 09:33:04 | 000,000,361 | -H-- | M] () -- C:\IPH.PH
[2009/12/26 21:43:23 | 000,013,926 | ---- | M] () -- C:\JavaRa.log
[2009/08/16 19:58:32 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/11/17 21:05:58 | 000,025,600 | ---- | M] () -- C:\myNumbers.dat
[2011/01/25 08:04:37 | 2459,709,440 | -HS- | M] () -- C:\pagefile.sys
[2009/12/20 00:52:25 | 000,002,348 | ---- | M] () -- C:\rollback.ini
[2010/04/18 07:10:01 | 000,000,063 | ---- | M] () -- C:\stif.cfg
[2010/11/17 21:06:33 | 000,001,388 | ---- | M] () -- C:\synReal.ini
[2010/04/18 20:04:17 | 000,002,330 | ---- | M] () -- C:\vpview21.log

< %systemroot%\Fonts\*.com >
[2006/11/02 05:35:26 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:35:26 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:35:26 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 05:35:26 | 000,030,808 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 05:34:09 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 18:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/09/12 18:34:19 | 000,561,152 | ---- | M] (Anne Jan Beeks) -- C:\Windows\AJScreensaver.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 19:41:56 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 20:16:46 | 017,956,864 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 20:16:31 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 20:16:46 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/09/06 01:18:17 | 000,000,286 | -HS- | M] () -- C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/01/27 07:42:34 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2006/11/02 05:33:56 | 000,000,802 | ---- | M] () -- C:\Windows\addins\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/08/15 21:54:32 | 000,000,402 | -HS- | M] () -- C:\Users\Alex\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2011/01/25 08:05:08 | 000,271,006 | ---- | M] () -- C:\ProgramData\nvModes.001

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
uninstall Tardis_S.exe

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >

< %SYSTEMROOT%\Installer\*.exe >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< %systemroot%\pchealth\helpctr\System\*.exe /s >

< %systemroot%\Web\*.exe >

< %systemroot%\system32\msn\*.* >

< %systemroot%\system32\*.tro >

< %AppData%\Microsoft\Installer\msupdates\*.* >

< %ProgramFiles%\Messenger\*.* >

< %systemroot%\system32\systhem32\*.* >

< %systemroot%\system\*.exe >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\Alex\Desktop\mypart2.mp3:TOC.WMV
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:05EE1EEF
@Alternate Data Stream - 1287 bytes -> C:\ProgramData\Microsoft:RwdTX1KUFp8aKUKOQThggRpKf
@Alternate Data Stream - 1241 bytes -> C:\ProgramData\Microsoft:FepSSYbZS47pD8gU2Vu8Q4tvDno
@Alternate Data Stream - 1181 bytes -> C:\ProgramData\Microsoft:CGIW1c8jY6NsClmT81j23Lm
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:0A8E2C33

< End of report >
 
Good news :)

I want to talk to you about an ideal antivirus/anti-malware solution.
A very simple answer. It doesn't exist :)
A human at the keyboard creates the biggest danger to the computer.
If the computer's operator habits are bad, nothing will protect you.
At the end of this topic I'll present you with some security hints.

Regarding Ad-aware...forget it. It's a tool of the past.
Today's best antispyware tools are Malwarebytes, which you already know and Superantispyware: http://www.superantispyware.com/download.html

Now, I'll review your logs.
 
You're free to reinstall your AVG now.

Update your Java version here: http://www.java.com/en/download/installed.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

Now, we need to remove old Java version and its remnants...

Download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.

====================================================================

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
    @Alternate Data Stream - 64 bytes -> C:\Users\Alex\Desktop\mypart2.mp3:TOC.WMV
    @Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:05EE1EEF
    @Alternate Data Stream - 1287 bytes -> C:\ProgramData\Microsoft:RwdTX1KUFp8aKUKOQThggRpKf
    @Alternate Data Stream - 1241 bytes -> C:\ProgramData\Microsoft:FepSSYbZS47pD8gU2Vu8Q4tvDno
    @Alternate Data Stream - 1181 bytes -> C:\ProgramData\Microsoft:CGIW1c8jY6NsClmT81j23Lm
    @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:0A8E2C33
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

=======================================================================

Last scans....

1. Download Security Check from HERE, and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


2. Download Temp File Cleaner (TFC)
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


3. Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • IMPORTANT! UN-check Remove found threats
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
I need a couple more days to get these scans and updates done. I've been working double shifts running tax forms for shareholders. Yaaaay tax season!
 
OK, it's evening, not afternoon, but at least it's still today... for a whole 38 minutes more!

Checkup.txt:
Results of screen317's Security Check version 0.99.7
Windows Vista Service Pack 2 (UAC is disabled!)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
ESET Online Scanner v3
Adobe After Effects CS3 Presets
[size=1]WMI entry may not exist for antivirus; attempting automatic update.[/size]
```````````````````````````````
Anti-malware/Other Utilities Check:

Ad-Aware
Malwarebytes' Anti-Malware
Java(TM) 6 Update 23
Out of date Java installed!
Adobe Flash Player 10.0.45.2
Mozilla Firefox (3.5.11) Firefox Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Ad-Aware AAWService.exe
Ad-Aware AAWTray.exe
WinPatrol winpatrol.exe
Spybot Teatimer.exe is disabled!
BillP Studios WinPatrol WinPatrol.exe
``````````End of Log````````````

OTL Log:
All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
ADS C:\Users\Alex\Desktop\mypart2.mp3:TOC.WMV deleted successfully.
ADS C:\ProgramData\TEMP:05EE1EEF deleted successfully.
ADS C:\ProgramData\Microsoft:RwdTX1KUFp8aKUKOQThggRpKf deleted successfully.
ADS C:\ProgramData\Microsoft:FepSSYbZS47pD8gU2Vu8Q4tvDno deleted successfully.
ADS C:\ProgramData\Microsoft:CGIW1c8jY6NsClmT81j23Lm deleted successfully.
ADS C:\ProgramData\TEMP:0A8E2C33 deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Alex
->Temp folder emptied: 136281 bytes
->Temporary Internet Files folder emptied: 45080805 bytes
->Java cache emptied: 2027 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 7062 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1199419 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 44.00 mb


[EMPTYFLASH]

User: Alex
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: LogMeInRemoteUser

User: Public

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.20.6 log created on 02052011_145424

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

And ESET is running as I speak.
 
Status
Not open for further replies.
Back