Hi there. Sometimes when I search for something on google and click on a link, I am sent to some other random website. I have also recently had to use a system restore because eventually some random program was blocking me from accessing the internet. I hope you can help me. I have run the 8 steps already. A note--before I found your website I had already run MALWAREBYTES and removed some items, but my problem still persists.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6160
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
3/25/2011 9:02:23 PM
mbam-log-2011-03-25 (21-02-23).txt
Scan type: Quick scan
Objects scanned: 163949
Time elapsed: 1 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
----------------------------------------------------------------------------------------------------------------------------------------------------------------
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-25 22:09:14
Windows 6.1.7600
Running: i2x1qb3t.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4B 0x11 0xE7 0x6A ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x15 0xCA 0xE1 0xA1 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x69 0x5C 0x6C 0x6D ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4B 0x11 0xE7 0x6A ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x15 0xCA 0xE1 0xA1 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x69 0x5C 0x6C 0x6D ...
---- EOF - GMER 1.0.15 ----
------------------------------------------------------------------------------------------------------------------------------------------------------
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by Mitch at 22:14:12.71 on Fri 03/25/2011
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_16
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.6134.4508 [GMT -5:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Kodak\KODAK Share Button App\Listener.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\Rosewill\Common\RegistryWriter.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Rosewill\Common\RaUI.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Everything\Everything.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Users\Mitch\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uURLSearchHooks: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
mURLSearchHooks: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~3\Office12\GR469A~1.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
TB: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
TB: @C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\Mitch\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
mRun: [Ad-Watch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Everything] "C:\Program Files (x86)\Everything\Everything.exe" -startup
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ROSEWI~1.LNK - C:\Program Files (x86)\Rosewill\Common\RaUI.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files (x86)\AIM\aim.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~3\Office12\GRA32A~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~3\Office12\GR469A~1.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
TB-X64: {ECDEE021-0D17-467F-A1FF-C7A115230949} - No File
mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
mRun-x64: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Mitch\AppData\Roaming\Mozilla\Firefox\Profiles\8nvd561z.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\Users\Mitch\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\Mitch\AppData\Roaming\Move Networks\plugins\npqmp071705000014.dll
FF - plugin: C:\Users\Mitch\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Mitch\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: XULRunner: {01168458-244C-4947-9D23-EA763DD803F9} - C:\Users\Mitch\AppData\Local\{01168458-244C-4947-9D23-EA763DD803F9}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Forecastbar Enhanced: {3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8} - %profile%\extensions\{3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: YouTube mp3: info@youtube-mp3.org - %profile%\extensions\info@youtube-mp3.org
FF - Ext: Move Media Player: moveplayer@movenetworks.com - C:\Users\Mitch\AppData\Roaming\Move Networks
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2011-3-24 69376]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-1-4 203776]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-1-1 135336]
R2 AntiVirService;Avira AntiVir Guard;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-1-1 269480]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2011-1-1 83120]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-3-16 1405384]
R2 RalinkRegistryWriter;Ralink Registry Writer;C:\Program Files (x86)\Rosewill\Common\RegistryWriter.exe [2010-5-13 185632]
R2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-5-28 275968]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2011-1-4 8283136]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2011-1-4 294400]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2010-11-17 115216]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;C:\Windows\System32\drivers\rt2870.sys [2010-5-13 946688]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-6-10 187392]
S3 cpuz132;cpuz132;C:\Windows\System32\drivers\cpuz132_x64.sys [2009-6-1 19432]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-20 128928]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-3-24 17152]
S3 OV550I;Film and Photo Scanner;C:\Windows\System32\drivers\OVTX16.sys [2010-6-4 139520]
.
=============== Created Last 30 ================
.
2011-03-25 00:27:57 69376 ----a-w- C:\Windows\System32\drivers\Lbd.sys
2011-03-24 22:29:14 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-24 22:29:10 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-03-24 22:12:05 -------- d-----w- C:\Windows\pss
2011-03-22 22:04:03 -------- d-----w- C:\Users\Mitch\AppData\Local\NeoSmart_Technologies
2011-03-22 22:03:03 -------- d-----w- C:\Program Files (x86)\NeoSmart Technologies
2011-03-21 01:31:05 -------- d-----w- C:\Users\Mitch\AppData\Local\Sunbelt Software
2011-03-21 01:30:00 -------- dc----w- C:\PROGRA~3\{870E601A-FE70-4098-94B2-6E9963FCAA51}
2011-03-19 06:01:43 -------- d-----w- C:\Users\Mitch\AppData\Roaming\Malwarebytes
2011-03-19 06:01:40 -------- d-----w- C:\PROGRA~3\Malwarebytes
2011-03-19 06:01:37 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-03-18 00:15:07 -------- d-----w- C:\Users\Mitch\AppData\Local\{01168458-244C-4947-9D23-EA763DD803F9}
2011-03-16 08:26:32 0 ----a-w- C:\Users\Mitch\AppData\Local\Stutiveba.bin
.
==================== Find3M ====================
.
2011-03-25 00:27:16 49752 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys
2011-03-09 00:24:02 107832 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-03-03 00:33:11 107832 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-02-11 06:19:42 270904 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-01-05 03:37:14 8283136 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-01-05 03:22:46 22100480 ----a-w- C:\Windows\System32\atio6axx.dll
2011-01-05 03:03:34 17043968 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-01-05 03:02:40 143360 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-01-05 03:02:28 596480 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-01-05 03:01:12 708608 ----a-w- C:\Windows\System32\aticfx64.dll
2011-01-05 02:58:42 462848 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2011-01-05 02:58:22 480256 ----a-w- C:\Windows\System32\atieclxx.exe
2011-01-05 02:57:44 203776 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-01-05 02:56:30 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2011-01-05 02:56:10 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2011-01-05 02:56:02 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-01-05 02:55:50 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-01-05 02:55:46 16384 ----a-w- C:\Windows\System32\atimuixx.dll
2011-01-05 02:55:40 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-01-05 02:55:34 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-01-05 02:52:20 4101632 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-01-05 02:43:20 4844544 ----a-w- C:\Windows\System32\atidxx64.dll
2011-01-05 02:33:30 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2011-01-05 02:33:28 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-01-05 02:33:20 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-01-05 02:33:20 4162048 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-01-05 02:33:16 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2011-01-05 02:33:08 6815232 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-01-05 02:32:56 1208320 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-01-05 02:32:22 3218944 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-01-05 02:31:52 5441024 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-01-05 02:28:08 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-01-05 02:27:06 5305856 ----a-w- C:\Windows\System32\atiumd64.dll
2011-01-05 02:25:04 3461120 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-01-05 02:20:20 353792 ----a-w- C:\Windows\System32\atiadlxx.dll
2011-01-05 02:20:10 249856 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-01-05 02:19:58 14848 ----a-w- C:\Windows\System32\atig6pxx.dll
2011-01-05 02:19:54 12800 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2011-01-05 02:19:54 12800 ----a-w- C:\Windows\System32\atiglpxx.dll
2011-01-05 02:19:52 32256 ----a-w- C:\Windows\System32\atig6txx.dll
2011-01-05 02:19:44 27648 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2011-01-05 02:19:38 294400 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2011-01-05 02:18:52 39936 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-01-05 02:18:46 30720 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2011-01-05 02:18:34 38400 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-01-05 02:18:26 28672 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2011-01-05 02:17:20 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-01-05 02:11:10 53760 ----a-w- C:\Windows\System32\atimpc64.dll
2011-01-05 02:11:10 53760 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-01-05 02:11:00 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-01-05 02:11:00 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2010-12-29 05:48:13 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
.
============= FINISH: 22:14:27.91 ===============
--------------------------------------------------------------------------------------------------------------------------------------------------
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 2/26/2010 2:25:38 AM
System Uptime: 3/25/2011 7:45:01 PM (3 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P6T
Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz | LGA1366 | 2668/133mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 596 GiB total, 37.677 GiB free.
D: is FIXED (NTFS) - 466 GiB total, 242.19 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is FIXED (NTFS) - 0 GiB total, 0.06 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Hamachi Network Interface
Device ID: ROOT\NET\0000
Manufacturer: Applied Networking Inc.
Name: Hamachi Network Interface
PNP Device ID: ROOT\NET\0000
Service: hamachi
.
Class GUID:
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
.
==== System Restore Points ===================
.
RP89: 3/17/2011 8:43:03 PM - Scheduled Checkpoint
RP90: 3/18/2011 11:06:48 PM - Windows Update
RP91: 3/19/2011 12:27:18 AM - Restore Operation
RP92: 3/20/2011 9:58:22 PM - Ad-Aware Checkpoint
RP93: 3/21/2011 3:02:26 PM - Windows Backup
.
==== Installed Programs ======================
.
µTorrent
AC3Filter 1.63b
Acrobat.com
Ad-Aware
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Aliens vs. Predator
AOL Instant Messenger
Apple Software Update
ATI Catalyst Registration
Avira AntiVir Personal - Free Antivirus
Battlefield: Bad Company 2
Bing Bar
Bing Bar Platform
Bit Che
Call of Duty(R) - World at War(TM)
Call of Duty(R) 4 - Modern Warfare(TM)
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
ccc-core-static
CCC Help English
CDBurnerXP
Crysis WARHEAD(R)
DVD-lab PRO 1.00
DVD Flick 1.3.0.7
EA Download Manager
eMule
Everything 1.2.1.371
Fallout 3
FastStone Photo Resizer 2.8
Folding@home-x86
free-downloads.net Toolbar
Futuremark SystemInfo
GameSpy Arcade
GIMP 2.6.7
Google Chrome
Google Talk Plugin
Grand Theft Auto IV
GRID
GRID Demo
Hamachi 1.0.1.1
HP Deskjet 1050 J410 series Help
HP Photo Creations
HP Update
HydraVision
Java(TM) 6 Update 16
KODAK Share Button App
Left 4 Dead
Left 4 Dead 2
Malwarebytes' Anti-Malware
Microsoft Default Manager
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft WSE 3.0 Runtime
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mirror's Edge
MKVtoolnix 2.9.7
Move Media Player
Mozilla Firefox (3.6.15)
MSXML4 Parser
NBA 2K10
NVIDIA PhysX v8.10.17
OpenAL
Osmos
Pcsx2 0.9.6
PunkBuster Services
Pure
Pure DEMO
Qtracker
Quake Live Mozilla Plugin
QuickTime
Rise of Nations
Rockstar Games Social Club
Rosewill Wireless Network 11N USB adapter RNX-EasyN1
Seismovision 3 (remove only)
Serious Sam HD: The First Encounter
Serious Sam HD: The Second Encounter
Sony CD Architect 5.2
Sony Sound Forge 7.0
StarCraft II
Steam
Streamripper (Remove only)
STREET FIGHTER IV
STREET FIGHTER IV BENCHMARK
Team Fortress 2
The Lord of the Rings FREE Trial
The Sims™ 3
TMPGEnc 3.0 XPress
TMPGEnc 4.0 XPress
Torchlight
Trine Demo
Viewpoint Media Player
Visual Studio 2008 x64 Redistributables
VLC media player 0.9.9
Winamp (remove only)
Yahoo! Messenger
zbattle.net 1.09 SR-1 beta
.
==== Event Viewer Messages From Past Week ========
.
3/25/2011 7:40:08 PM, Error: Service Control Manager [7031] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
3/24/2011 7:27:57 PM, Error: Service Control Manager [7000] - The Lbd service failed to start due to the following error: The system cannot find the file specified.
3/24/2011 5:45:21 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:21 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
3/24/2011 5:45:21 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
3/24/2011 5:45:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
3/24/2011 5:45:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
3/24/2011 5:45:19 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
3/24/2011 5:45:12 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
3/24/2011 5:45:08 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avipbb CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:06:47 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
3/24/2011 5:04:28 PM, Error: Service Control Manager [7023] - The Windows Update service terminated with the following error: %%-2147467243
3/24/2011 5:04:25 PM, Error: Service Control Manager [7038] - The wscsvc service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
3/24/2011 5:04:25 PM, Error: Service Control Manager [7000] - The Security Center service failed to start due to the following error: The service did not start due to a logon failure.
3/23/2011 7:28:10 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR2.
3/23/2011 10:23:45 PM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: 490@01010004
3/20/2011 8:30:42 PM, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
3/19/2011 12:24:29 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR3.
.
==== End Of File ===========================
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6160
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
3/25/2011 9:02:23 PM
mbam-log-2011-03-25 (21-02-23).txt
Scan type: Quick scan
Objects scanned: 163949
Time elapsed: 1 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
----------------------------------------------------------------------------------------------------------------------------------------------------------------
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-25 22:09:14
Windows 6.1.7600
Running: i2x1qb3t.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4B 0x11 0xE7 0x6A ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x15 0xCA 0xE1 0xA1 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x69 0x5C 0x6C 0x6D ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4B 0x11 0xE7 0x6A ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x15 0xCA 0xE1 0xA1 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x69 0x5C 0x6C 0x6D ...
---- EOF - GMER 1.0.15 ----
------------------------------------------------------------------------------------------------------------------------------------------------------
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by Mitch at 22:14:12.71 on Fri 03/25/2011
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_16
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.6134.4508 [GMT -5:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Kodak\KODAK Share Button App\Listener.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\Rosewill\Common\RegistryWriter.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Rosewill\Common\RaUI.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Everything\Everything.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Users\Mitch\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uURLSearchHooks: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
mURLSearchHooks: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~3\Office12\GR469A~1.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
TB: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
TB: @C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\Mitch\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
mRun: [Ad-Watch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Everything] "C:\Program Files (x86)\Everything\Everything.exe" -startup
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ROSEWI~1.LNK - C:\Program Files (x86)\Rosewill\Common\RaUI.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files (x86)\AIM\aim.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~3\Office12\GRA32A~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~3\Office12\GR469A~1.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
TB-X64: {ECDEE021-0D17-467F-A1FF-C7A115230949} - No File
mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
mRun-x64: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Mitch\AppData\Roaming\Mozilla\Firefox\Profiles\8nvd561z.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\Users\Mitch\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\Mitch\AppData\Roaming\Move Networks\plugins\npqmp071705000014.dll
FF - plugin: C:\Users\Mitch\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Mitch\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: XULRunner: {01168458-244C-4947-9D23-EA763DD803F9} - C:\Users\Mitch\AppData\Local\{01168458-244C-4947-9D23-EA763DD803F9}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Forecastbar Enhanced: {3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8} - %profile%\extensions\{3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: YouTube mp3: info@youtube-mp3.org - %profile%\extensions\info@youtube-mp3.org
FF - Ext: Move Media Player: moveplayer@movenetworks.com - C:\Users\Mitch\AppData\Roaming\Move Networks
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2011-3-24 69376]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-1-4 203776]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-1-1 135336]
R2 AntiVirService;Avira AntiVir Guard;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-1-1 269480]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2011-1-1 83120]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-3-16 1405384]
R2 RalinkRegistryWriter;Ralink Registry Writer;C:\Program Files (x86)\Rosewill\Common\RegistryWriter.exe [2010-5-13 185632]
R2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-5-28 275968]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2011-1-4 8283136]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2011-1-4 294400]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2010-11-17 115216]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;C:\Windows\System32\drivers\rt2870.sys [2010-5-13 946688]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-6-10 187392]
S3 cpuz132;cpuz132;C:\Windows\System32\drivers\cpuz132_x64.sys [2009-6-1 19432]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-20 128928]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-3-24 17152]
S3 OV550I;Film and Photo Scanner;C:\Windows\System32\drivers\OVTX16.sys [2010-6-4 139520]
.
=============== Created Last 30 ================
.
2011-03-25 00:27:57 69376 ----a-w- C:\Windows\System32\drivers\Lbd.sys
2011-03-24 22:29:14 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-24 22:29:10 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-03-24 22:12:05 -------- d-----w- C:\Windows\pss
2011-03-22 22:04:03 -------- d-----w- C:\Users\Mitch\AppData\Local\NeoSmart_Technologies
2011-03-22 22:03:03 -------- d-----w- C:\Program Files (x86)\NeoSmart Technologies
2011-03-21 01:31:05 -------- d-----w- C:\Users\Mitch\AppData\Local\Sunbelt Software
2011-03-21 01:30:00 -------- dc----w- C:\PROGRA~3\{870E601A-FE70-4098-94B2-6E9963FCAA51}
2011-03-19 06:01:43 -------- d-----w- C:\Users\Mitch\AppData\Roaming\Malwarebytes
2011-03-19 06:01:40 -------- d-----w- C:\PROGRA~3\Malwarebytes
2011-03-19 06:01:37 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-03-18 00:15:07 -------- d-----w- C:\Users\Mitch\AppData\Local\{01168458-244C-4947-9D23-EA763DD803F9}
2011-03-16 08:26:32 0 ----a-w- C:\Users\Mitch\AppData\Local\Stutiveba.bin
.
==================== Find3M ====================
.
2011-03-25 00:27:16 49752 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys
2011-03-09 00:24:02 107832 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-03-03 00:33:11 107832 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-02-11 06:19:42 270904 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-01-05 03:37:14 8283136 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-01-05 03:22:46 22100480 ----a-w- C:\Windows\System32\atio6axx.dll
2011-01-05 03:03:34 17043968 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-01-05 03:02:40 143360 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-01-05 03:02:28 596480 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-01-05 03:01:12 708608 ----a-w- C:\Windows\System32\aticfx64.dll
2011-01-05 02:58:42 462848 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2011-01-05 02:58:22 480256 ----a-w- C:\Windows\System32\atieclxx.exe
2011-01-05 02:57:44 203776 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-01-05 02:56:30 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2011-01-05 02:56:10 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2011-01-05 02:56:02 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-01-05 02:55:50 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-01-05 02:55:46 16384 ----a-w- C:\Windows\System32\atimuixx.dll
2011-01-05 02:55:40 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-01-05 02:55:34 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-01-05 02:52:20 4101632 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-01-05 02:43:20 4844544 ----a-w- C:\Windows\System32\atidxx64.dll
2011-01-05 02:33:30 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2011-01-05 02:33:28 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-01-05 02:33:20 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-01-05 02:33:20 4162048 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-01-05 02:33:16 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2011-01-05 02:33:08 6815232 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-01-05 02:32:56 1208320 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-01-05 02:32:22 3218944 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-01-05 02:31:52 5441024 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-01-05 02:28:08 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-01-05 02:27:06 5305856 ----a-w- C:\Windows\System32\atiumd64.dll
2011-01-05 02:25:04 3461120 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-01-05 02:20:20 353792 ----a-w- C:\Windows\System32\atiadlxx.dll
2011-01-05 02:20:10 249856 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-01-05 02:19:58 14848 ----a-w- C:\Windows\System32\atig6pxx.dll
2011-01-05 02:19:54 12800 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2011-01-05 02:19:54 12800 ----a-w- C:\Windows\System32\atiglpxx.dll
2011-01-05 02:19:52 32256 ----a-w- C:\Windows\System32\atig6txx.dll
2011-01-05 02:19:44 27648 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2011-01-05 02:19:38 294400 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2011-01-05 02:18:52 39936 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-01-05 02:18:46 30720 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2011-01-05 02:18:34 38400 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-01-05 02:18:26 28672 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2011-01-05 02:17:20 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-01-05 02:11:10 53760 ----a-w- C:\Windows\System32\atimpc64.dll
2011-01-05 02:11:10 53760 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-01-05 02:11:00 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-01-05 02:11:00 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2010-12-29 05:48:13 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
.
============= FINISH: 22:14:27.91 ===============
--------------------------------------------------------------------------------------------------------------------------------------------------
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 2/26/2010 2:25:38 AM
System Uptime: 3/25/2011 7:45:01 PM (3 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P6T
Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz | LGA1366 | 2668/133mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 596 GiB total, 37.677 GiB free.
D: is FIXED (NTFS) - 466 GiB total, 242.19 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is FIXED (NTFS) - 0 GiB total, 0.06 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Hamachi Network Interface
Device ID: ROOT\NET\0000
Manufacturer: Applied Networking Inc.
Name: Hamachi Network Interface
PNP Device ID: ROOT\NET\0000
Service: hamachi
.
Class GUID:
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
.
==== System Restore Points ===================
.
RP89: 3/17/2011 8:43:03 PM - Scheduled Checkpoint
RP90: 3/18/2011 11:06:48 PM - Windows Update
RP91: 3/19/2011 12:27:18 AM - Restore Operation
RP92: 3/20/2011 9:58:22 PM - Ad-Aware Checkpoint
RP93: 3/21/2011 3:02:26 PM - Windows Backup
.
==== Installed Programs ======================
.
µTorrent
AC3Filter 1.63b
Acrobat.com
Ad-Aware
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Aliens vs. Predator
AOL Instant Messenger
Apple Software Update
ATI Catalyst Registration
Avira AntiVir Personal - Free Antivirus
Battlefield: Bad Company 2
Bing Bar
Bing Bar Platform
Bit Che
Call of Duty(R) - World at War(TM)
Call of Duty(R) 4 - Modern Warfare(TM)
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
ccc-core-static
CCC Help English
CDBurnerXP
Crysis WARHEAD(R)
DVD-lab PRO 1.00
DVD Flick 1.3.0.7
EA Download Manager
eMule
Everything 1.2.1.371
Fallout 3
FastStone Photo Resizer 2.8
Folding@home-x86
free-downloads.net Toolbar
Futuremark SystemInfo
GameSpy Arcade
GIMP 2.6.7
Google Chrome
Google Talk Plugin
Grand Theft Auto IV
GRID
GRID Demo
Hamachi 1.0.1.1
HP Deskjet 1050 J410 series Help
HP Photo Creations
HP Update
HydraVision
Java(TM) 6 Update 16
KODAK Share Button App
Left 4 Dead
Left 4 Dead 2
Malwarebytes' Anti-Malware
Microsoft Default Manager
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft WSE 3.0 Runtime
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mirror's Edge
MKVtoolnix 2.9.7
Move Media Player
Mozilla Firefox (3.6.15)
MSXML4 Parser
NBA 2K10
NVIDIA PhysX v8.10.17
OpenAL
Osmos
Pcsx2 0.9.6
PunkBuster Services
Pure
Pure DEMO
Qtracker
Quake Live Mozilla Plugin
QuickTime
Rise of Nations
Rockstar Games Social Club
Rosewill Wireless Network 11N USB adapter RNX-EasyN1
Seismovision 3 (remove only)
Serious Sam HD: The First Encounter
Serious Sam HD: The Second Encounter
Sony CD Architect 5.2
Sony Sound Forge 7.0
StarCraft II
Steam
Streamripper (Remove only)
STREET FIGHTER IV
STREET FIGHTER IV BENCHMARK
Team Fortress 2
The Lord of the Rings FREE Trial
The Sims™ 3
TMPGEnc 3.0 XPress
TMPGEnc 4.0 XPress
Torchlight
Trine Demo
Viewpoint Media Player
Visual Studio 2008 x64 Redistributables
VLC media player 0.9.9
Winamp (remove only)
Yahoo! Messenger
zbattle.net 1.09 SR-1 beta
.
==== Event Viewer Messages From Past Week ========
.
3/25/2011 7:40:08 PM, Error: Service Control Manager [7031] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
3/24/2011 7:27:57 PM, Error: Service Control Manager [7000] - The Lbd service failed to start due to the following error: The system cannot find the file specified.
3/24/2011 5:45:21 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:21 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
3/24/2011 5:45:21 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
3/24/2011 5:45:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
3/24/2011 5:45:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
3/24/2011 5:45:19 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
3/24/2011 5:45:12 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
3/24/2011 5:45:08 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avipbb CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:45:08 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
3/24/2011 5:06:47 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
3/24/2011 5:04:28 PM, Error: Service Control Manager [7023] - The Windows Update service terminated with the following error: %%-2147467243
3/24/2011 5:04:25 PM, Error: Service Control Manager [7038] - The wscsvc service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
3/24/2011 5:04:25 PM, Error: Service Control Manager [7000] - The Security Center service failed to start due to the following error: The service did not start due to a logon failure.
3/23/2011 7:28:10 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR2.
3/23/2011 10:23:45 PM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: 490@01010004
3/20/2011 8:30:42 PM, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
3/19/2011 12:24:29 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR3.
.
==== End Of File ===========================