TechSpot

Rootkit?

By Housez71
Aug 9, 2012
  1. Background: I had a virus install under the guise of a Java Update. It disabled firewall and had my google searches redirect to a payperclick advertising site. I installed avast and it updated. It kept alerting me of the virus and blocking it's activity, however I ran a boot time scan which takes around 90 minutes and it detected and removed the virus (Moved to Chest), supposedly. Everything works fine now except, I cannot use windows firewall, defender, etc. Avast and MBAM both show the computer as clean with a full scan but I knew something was wrong.

    I performed the 5 steps that were asked and the logs are attached. GMER did NOT produce any logs.

    After reading a thread , I ran the "boot cleaner" scan (but took no action, log attached). Please have a look at the log and advise on a course of action.

    Malware Bytes Log:

    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.08.09.11

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Reggin :: REGGIN-PC [administrator]

    8/9/2012 5:36:35 PM
    mbam-log-2012-08-09 (17-36-35).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 191057
    Time elapsed: 43 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)

    DDS LOGS:

    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
    Run by Reggin at 17:44:13 on 2012-08-09
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16382.14007 [GMT -5:00]
    .
    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\Steam\Steam.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\SysWOW64\PnkBstrA.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    D:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
    C:\Program Files (x86)\Windows Media Player\wmplayer.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    C:\Windows\system32\wuauclt.exe
    D:\Program Files (x86)\Mozilla Firefox\firefox.exe
    D:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Settings,ProxyOverride = *.local
    mWinlogon: Userinit=userinit.exe,
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
    mRun: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    mRun: [ASUS Sync Loader] "C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe" -startup
    mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    LSP: mswsock.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    TCP: DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{BA9BFBC8-4B24-41AC-8E49-FD11A10D1D95} : DhcpNameServer = 192.168.1.254
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
    BHO-X64: URLRedirectionBHO - No File
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    mRun-x64: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    mRun-x64: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    mRun-x64: [ASUS Sync Loader] "C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe" -startup
    mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun-x64: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe"
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Reggin\AppData\Roaming\Mozilla\Firefox\Profiles\n9jdz56u.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll
    FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
    FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll
    FF - plugin: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 amd_sata;amd_sata;C:\Windows\system32\DRIVERS\amd_sata.sys --> C:\Windows\system32\DRIVERS\amd_sata.sys [?]
    R0 amd_xata;amd_xata;C:\Windows\system32\DRIVERS\amd_xata.sys --> C:\Windows\system32\DRIVERS\amd_xata.sys [?]
    R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys --> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
    R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
    R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928]
    R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
    R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
    R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-7-27 44808]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\system32\drivers\LGBusEnum.sys --> C:\Windows\system32\drivers\LGBusEnum.sys [?]
    R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\system32\drivers\LGVirHid.sys --> C:\Windows\system32\drivers\LGVirHid.sys [?]
    R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
    R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-27 250056]
    S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
    S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-12-28 51727736]
    S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-27 113120]
    S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
    S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
    S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
    S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
    S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    .
    =============== Created Last 30 ================
    .
    2012-08-09 17:34:09 -------- d-----w- C:\Program Files\Microsoft Synchronization Services
    2012-08-09 17:33:57 -------- d-----w- C:\Program Files\Microsoft SQL Server Compact Edition
    2012-08-09 17:33:22 -------- d-----w- C:\Program Files\Microsoft Analysis Services
    2012-08-09 17:24:41 -------- d-----w- C:\Users\Reggin\AppData\Local\ElevatedDiagnostics
    2012-08-09 17:24:36 -------- d-----w- C:\MATS
    2012-08-05 17:40:18 955888 ----a-w- C:\Windows\System32\npDeployJava1.dll
    2012-07-29 17:50:50 -------- d-----w- C:\Program Files (x86)\Rosetta Stone
    2012-07-29 17:38:23 -------- d-----w- C:\Program Files (x86)\Common Files\Macrovision Shared
    2012-07-29 17:38:22 -------- d-----w- C:\ProgramData\Rosetta Stone
    2012-07-28 18:36:09 -------- d-----w- C:\Program Files\iTunes
    2012-07-28 18:36:09 -------- d-----w- C:\Program Files\iPod
    2012-07-28 18:26:20 889664 ----a-w- C:\Windows\System32\nvvsvc.exe
    2012-07-28 18:26:20 63296 ----a-w- C:\Windows\System32\nvshext.dll
    2012-07-28 18:26:20 6151488 ----a-w- C:\Windows\System32\nvcpl.dll
    2012-07-28 18:26:20 3149632 ----a-w- C:\Windows\System32\nvsvc64.dll
    2012-07-28 18:26:20 2621723 ----a-w- C:\Windows\System32\nvcoproc.bin
    2012-07-28 18:26:19 118080 ----a-w- C:\Windows\System32\nvmctray.dll
    2012-07-28 18:26:08 -------- d-----w- C:\ProgramData\NVIDIA Corporation
    2012-07-27 22:14:25 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
    2012-07-27 22:01:24 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-07-27 22:01:24 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2012-07-27 21:46:29 -------- d-sh--w- C:\Windows\Installer
    2012-07-27 18:38:32 -------- d-----w- C:\Windows\System32\appmgmt
    2012-07-27 18:07:41 958400 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
    2012-07-27 18:07:41 71064 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
    2012-07-27 18:07:41 54072 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
    2012-07-27 18:07:28 41224 ----a-w- C:\Windows\avastSS.scr
    2012-07-27 18:00:40 -------- d-----w- C:\Users\Reggin\AppData\Roaming\Malwarebytes
    2012-07-27 18:00:29 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2012-07-27 18:00:29 -------- d-----w- C:\ProgramData\Malwarebytes
    2012-07-27 18:00:29 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-07-27 17:29:22 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
    2012-07-27 17:24:09 -------- d-----w- C:\Users\Reggin\AppData\Local\{DB217A9F-D80F-11E1-8270-B8AC6F996F26}
    2012-07-19 23:29:18 -------- d-----w- C:\Users\Reggin\AppData\Local\SIX_Projects
    2012-07-19 22:56:54 -------- d-----w- C:\Users\Reggin\AppData\Roaming\gslist
    2012-07-19 22:56:54 -------- d-----w- C:\Users\Reggin\AppData\Local\DayZCommander
    2012-07-19 22:37:08 -------- d-----w- C:\Users\Reggin\AppData\Roaming\six-updater
    2012-07-19 22:37:07 -------- d-----w- C:\Users\Reggin\AppData\Roaming\six-zsync
    2012-07-19 22:36:33 -------- d-----w- C:\Users\Reggin\AppData\Local\ArmA 2
    2012-07-19 06:10:12 -------- d-----w- C:\Users\Reggin\AppData\Local\ArmA 2 OA
    2012-07-17 02:28:15 3148800 ----a-w- C:\Windows\System32\win32k.sys
    .
    ==================== Find3M ====================
    .
    2012-08-09 21:57:50 283304 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
    2012-08-09 21:57:50 283304 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
    2012-08-09 19:47:40 283304 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
    2012-08-05 17:40:12 839152 ----a-w- C:\Windows\System32\deployJava1.dll
    2012-06-25 21:04:24 1394248 ----a-w- C:\Windows\SysWow64\msxml4.dll
    2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
    2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
    2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
    2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
    2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
    2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
    2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
    2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
    2012-06-02 20:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
    2012-06-02 20:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
    2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
    2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
    2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
    2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
    2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
    2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
    2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
    2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
    2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
    2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
    2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
    2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
    2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
    2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
    .
    ============= FINISH: 17:44:24.59 ===============

    DDS ATTACH
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Ultimate
    Boot Device: \Device\HarddiskVolume1
    Install Date: 1/8/2012 12:22:50 PM
    System Uptime: 8/9/2012 1:43:27 PM (4 hours ago)
    .
    Motherboard: Gigabyte Technology Co., Ltd. | | GA-880GA-UD3H
    Processor: AMD Phenom(tm) II X6 1100T Processor | Socket M2 | 3300/200mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 112 GiB total, 25.897 GiB free.
    D: is FIXED (NTFS) - 466 GiB total, 395.271 GiB free.
    E: is FIXED (NTFS) - 466 GiB total, 252.847 GiB free.
    F: is CDROM ()
    G: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP88: 8/4/2012 2:55:18 PM - Installed Java(TM) 6 Update 33
    RP89: 8/4/2012 2:58:42 PM - Removed Java(TM) 6 Update 31 (64-bit)
    RP90: 8/5/2012 12:40:07 PM - Installed Java(TM) 7 Update 5 (64-bit)
    RP91: 8/9/2012 12:04:21 PM - Removed Microsoft Office Professional Plus 2010
    RP92: 8/9/2012 12:04:56 PM - Removed Microsoft Office Professional Plus 2010
    RP93: 8/9/2012 12:14:01 PM - Removed Microsoft Office Professional Plus 2010
    RP95: 8/9/2012 12:24:22 PM - Restore Point before Corrupt Patch Registry keys
    RP97: 8/9/2012 12:26:19 PM - Restore Point before Microsoft Office Professional Plus 2010 was removed using Program Install and Uninstall troubleshooter
    RP99: 8/9/2012 12:26:49 PM - Microsoft Office Professional Plus 2010
    RP101: 8/9/2012 12:28:40 PM - Restore Point before Microsoft Office Office 64-bit Components 2010 was removed using Program Install and Uninstall troubleshooter
    RP103: 8/9/2012 12:28:51 PM - Microsoft Office Office 64-bit Components 2010
    RP104: 8/9/2012 12:33:10 PM - Installed Microsoft Office Professional Plus 2010
    .
    ==== Installed Programs ======================
    .
    @Bios
    Adobe Flash Player 11 Plugin
    Adobe Reader X (10.1.3)
    AMD USB Filter Driver
    Apple Application Support
    Apple Software Update
    ARMA 2
    ARMA 2: Operation Arrowhead
    ASUS Sync
    avast! Free Antivirus
    Battlefield 3™
    Battlelog Web Plugins
    BattlEye for OA Uninstall
    BattlEye Uninstall
    DayZ Commander
    Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    DMIView B8.0717.01
    Dungeon Defenders
    ESN Sonar
    Half-Life
    Java Auto Updater
    Java(TM) 6 Update 31
    Malwarebytes Anti-Malware version 1.62.0.1300
    Microsoft Office 2010 Service Pack 1 (SP1)
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Groove MUI (English) 2010
    Microsoft Office InfoPath MUI (English) 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Professional Plus 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    Mozilla Firefox 14.0.1 (x86 en-US)
    Mozilla Maintenance Service
    MSXML 4.0 SP3 Parser
    MSXML 4.0 SP3 Parser (KB2721691)
    MSXML 4.0 SP3 Parser (KB973685)
    Natural Selection 3.2
    NEC Electronics USB 3.0 Host Controller Driver
    NVIDIA PhysX
    ON_OFF Charge B11.0110.1
    Origin
    PowerISO
    Realtek Ethernet Controller Driver
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553091)
    Security Update for Microsoft Office 2010 (KB2553096)
    Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition
    Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
    Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
    Security Update for Microsoft Visio Viewer 2010 (KB2597981) 32-Bit Edition
    Six Updater
    Steam
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft Office 2010 (KB2553065)
    Update for Microsoft Office 2010 (KB2553092)
    Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2566458)
    Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
    Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
    Vuze
    WinAce Archiver
    .
    ==== Event Viewer Messages From Past Week ========
    .
    8/9/2012 5:42:49 PM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891
    8/9/2012 5:42:49 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891
    8/9/2012 1:48:50 PM, Error: Service Control Manager [7024] - The Windows Firewall service terminated with service-specific error Access is denied..
    8/9/2012 1:43:43 PM, Error: Service Control Manager [7023] - The Windows Defender service terminated with the following error: The specified module could not be found.
    8/4/2012 12:03:22 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
    .
    ==== End Of File ===========================


    I did go ahead and scan with the Boot Cleaner and it gave this log (I took no action):

    "Bootkit Remover
    (c) 2009 Esage Lab
    www.esagelab.com

    Program version: 1.2.0.1
    OS Version: Microsoft Windows 7 Ultimate Edition Service Pack 1 (build 7601), 64
    -bit

    System volume is \\.\C:
    \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`06500000

    Size Device Name MBR Status
    --------------------------------------------
    111 GB \\.\PhysicalDrive0 Controlled by rootkit!

    Boot code on some of your physical disks is hidden by a rootkit.
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]



    Done;
    Press any key to quit..."

    Do you have any suggestions?
     
  2. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    =========================================

    Please download the below tool named Rkill (courtesy of BleepingComputer.com) to your desktop.

    There are 2 different versions. If one of them won't run then download and try to run the other one.

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    http://download.bleepingcomputer.com/grinler/beta/rkill.exe
    http://download.bleepingcomputer.com/grinler/beta/iExplore.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    If normal mode still doesn't work, run the tool from safe mode.

    When the scan is done Notepad will open with rKill log.
    Post it in your next reply.

    NOTE. rKill.txt log will also be present on your desktop.

    ===========================================

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
     
  3. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    Ok I ran RKill:

    Here is the Log

    RogueKiller V7.6.5 [08/03/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User: Reggin [Admin rights]
    Mode: Scan -- Date: 08/09/2012 13:58:57

    ¤¤¤ Bad processes: 0 ¤¤¤

    ¤¤¤ Registry Entries: 5 ¤¤¤
    [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
    [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
    [ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\Reggin\AppData\Local\{af70a4e2-dbb6-273b-1caf-d4176d30b398}\n.) -> FOUND
    [HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Particular Files / Folders: ¤¤¤
    [ZeroAccess][FILE] @ : c:\users\reggin\appdata\local\{af70a4e2-dbb6-273b-1caf-d4176d30b398}\@ --> FOUND
    [ZeroAccess][FOLDER] U : c:\users\reggin\appdata\local\{af70a4e2-dbb6-273b-1caf-d4176d30b398}\U --> FOUND
    [ZeroAccess][FOLDER] L : c:\users\reggin\appdata\local\{af70a4e2-dbb6-273b-1caf-d4176d30b398}\L --> FOUND

    ¤¤¤ Driver: [NOT LOADED] ¤¤¤

    ¤¤¤ Infection : ZeroAccess ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: OCZ-AGIL ITY3 SATA Disk Device +++++
    --- User ---
    [MBR] 9089f9f1d71bb7d2c099ee928d0a4548
    [BSP] 79a50891c64a12b5420c785ba8c5bf98 : Windows 7 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 114371 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive1: WDC WD50 00AAKX-001CA0 SATA Disk Device +++++
    --- User ---
    [MBR] cec8ceb24691eba40e498181254a23e2
    [BSP] eb157c6643b00bf98bc6a16014d8d8ee : TestDisk MBR Code
    Partition table:
    0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 476937 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive2: ST350063 0AS SATA Disk Device +++++
    --- User ---
    [MBR] d08d6d771578d9ccf658383903963ed0
    [BSP] 6ddb7a887a9cf2f65289e6fe25d9ade7 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[1].txt >>
    RKreport[1].txt
     
  4. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    There was no instruction for reboot on Rkill.
     
  5. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    aswMBR Log:

    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-08-09 14:17:48
    -----------------------------
    14:17:48.827 OS Version: Windows x64 6.1.7601 Service Pack 1
    14:17:48.827 Number of processors: 6 586 0xA00
    14:17:48.828 ComputerName: REGGIN-PC UserName: Reggin
    14:17:49.045 Initialize success
    14:17:49.087 AVAST engine defs: 12080900
    14:18:07.353 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005f
    14:18:07.355 Disk 0 Vendor: OCZ-AGIL 2.15 Size: 114473MB BusType: 11
    14:18:07.356 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000060
    14:18:07.357 Disk 1 Vendor: WDC_WD50 15.0 Size: 476940MB BusType: 11
    14:18:07.359 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000061
    14:18:07.360 Disk 2 Vendor: ST350063 3.AA Size: 476938MB BusType: 11
    14:18:07.363 Disk 0 MBR read successfully
    14:18:07.364 Disk 0 MBR scan
    14:18:07.366 Disk 0 Windows 7 default MBR code
    14:18:07.367 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
    14:18:07.369 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 114371 MB offset 206848
    14:18:07.372 Disk 0 scanning C:\Windows\system32\drivers
    14:18:08.238 Service scanning
    14:18:11.083 Modules scanning
    14:18:11.084 Disk 0 trace - called modules:
    14:18:11.086 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
    14:18:11.087 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800d282790]
    14:18:11.087 3 CLASSPNP.SYS[fffff8800165143f] -> nt!IofCallDriver -> [0xfffffa800d177ac0]
    14:18:11.087 5 amd_xata.sys[fffff8800112eb98] -> nt!IofCallDriver -> \Device\0000005f[0xfffffa800d1709c0]
    14:18:11.232 AVAST engine scan C:\Windows
    14:18:11.447 AVAST engine scan C:\Windows\system32
    14:18:33.729 AVAST engine scan C:\Windows\system32\drivers
    14:18:34.863 AVAST engine scan C:\Users\Reggin
    14:18:46.558 AVAST engine scan C:\ProgramData
    14:18:48.038 Scan finished successfully
    14:19:40.644 Disk 0 MBR has been saved successfully to "D:\Users\Reggin\Desktop\MBR.dat"
    14:19:40.647 The log file has been saved successfully to "D:\Users\Reggin\Desktop\aswMBR.txt"


    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-08-09 18:35:25
    -----------------------------
    18:35:25.710 OS Version: Windows x64 6.1.7601 Service Pack 1
    18:35:25.710 Number of processors: 6 586 0xA00
    18:35:25.710 ComputerName: REGGIN-PC UserName: Reggin
    18:35:26.022 Initialize success
    18:35:26.053 AVAST engine defs: 12080901
    18:35:29.563 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005f
    18:35:29.563 Disk 0 Vendor: OCZ-AGIL 2.15 Size: 114473MB BusType: 11
    18:35:29.563 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000060
    18:35:29.563 Disk 1 Vendor: WDC_WD50 15.0 Size: 476940MB BusType: 11
    18:35:29.563 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000061
    18:35:29.563 Disk 2 Vendor: ST350063 3.AA Size: 476938MB BusType: 11
    18:35:29.579 Disk 0 MBR read successfully
    18:35:29.579 Disk 0 MBR scan
    18:35:29.579 Disk 0 Windows 7 default MBR code
    18:35:29.579 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
    18:35:29.594 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 114371 MB offset 206848
    18:35:29.610 Disk 0 scanning C:\Windows\system32\drivers
    18:35:33.869 Service scanning
    18:35:36.708 Modules scanning
    18:35:36.708 Disk 0 trace - called modules:
    18:35:36.708 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
    18:35:36.708 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800d282790]
    18:35:36.708 3 CLASSPNP.SYS[fffff8800165143f] -> nt!IofCallDriver -> [0xfffffa800d177ac0]
    18:35:36.708 5 amd_xata.sys[fffff8800112eb98] -> nt!IofCallDriver -> \Device\0000005f[0xfffffa800d1709c0]
    18:35:37.036 AVAST engine scan C:\Windows
    18:35:38.892 AVAST engine scan C:\Windows\system32
    18:36:25.131 AVAST engine scan C:\Windows\system32\drivers
    18:36:26.254 AVAST engine scan C:\Users\Reggin
    18:36:34.101 AVAST engine scan C:\ProgramData
    18:36:35.302 Scan finished successfully
    18:36:42.727 Disk 0 MBR has been saved successfully to "D:\Users\Reggin\Desktop\MBR.dat"
    18:36:42.727 The log file has been saved successfully to "D:\Users\Reggin\Desktop\aswMBR.txt"
     
  6. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    You ran RogueKiller not rKill.

    [​IMG]
     
  7. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    It is not producing the log on my desktop says Rkill finished:It says it has produced the rkill.txt log file and it will be on my desktop but it is not.
     
  8. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:

      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

    Next...

    Re-run FRST again.
    Type the following in the edit box after "Search:".

    services.exe

    Click Search button and post the log (Search.txt) it makes in your reply.

    I'll expect two logs:
    - FRST.txt
    - Search.txt
     
  9. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    I am running "rkill.exe" which I downloaded from the first link in your instructions of your second post. The second link Error 404.
     
  10. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Please read my previous reply.
     
  11. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    FRST TXT

    Scan result of Farbar Recovery Scan Tool Version: 09-08-2012
    Ran by SYSTEM at 09-08-2012 19:59:21
    Running from I:\
    Microsoft Windows XP Service Pack 1 (X64) OS Language: English(US)
    The current controlset is ControlSet001

    ATTENTION!:=====> THE OPERATING SYSTEM IS A X86 SYSTEM BUT THE BOOT DISK THAT IS USED TO BOOT TO RECOVERY ENVIRONMENT IS A X64 SYSTEM DISK.
    ========================== Registry (Whitelisted) =============

    HKLM\...\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe [59392 2004-08-10] (Microsoft Corporation)
    HKLM\...\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe [98304 2005-11-27] (Intel Corporation)
    HKLM\...\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe [77824 2005-11-27] (Intel Corporation)
    HKLM\...\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe [118784 2005-11-27] (Intel Corporation)
    HKLM\...\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking10\Ereg.ini [x]
    HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [110696 2010-04-03] (NVIDIA Corporation)
    HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [13670504 2010-04-03] (NVIDIA Corporation)
    HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [x]
    HKLM\...\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui [x]
    HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [x]
    HKLM\...\Run: [Launch LgDeviceAgent] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe" [x]
    HKLM\...\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE [x]
    HKLM-x32\...\Winlogon: [Userinit] [x]
    HKLM-x32\...\Winlogon: [Shell] [x ] ()
    Winlogon\Notify\crypt32chain: crypt32.dll (Microsoft Corporation)
    Winlogon\Notify\cryptnet: cryptnet.dll (Microsoft Corporation)
    Winlogon\Notify\cscdll: cscdll.dll (Microsoft Corporation)
    Winlogon\Notify\dimsntfy: %SystemRoot%\System32\dimsntfy.dll (Microsoft Corporation)
    Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
    Winlogon\Notify\ScCertProp: wlnotify.dll (Microsoft Corporation)
    Winlogon\Notify\Schedule: wlnotify.dll (Microsoft Corporation)
    Winlogon\Notify\sclgntfy: sclgntfy.dll (Microsoft Corporation)
    Winlogon\Notify\SensLogn: WlNotify.dll (Microsoft Corporation)
    Winlogon\Notify\termsrv: wlnotify.dll (Microsoft Corporation)
    Winlogon\Notify\wlballoon: wlnotify.dll (Microsoft Corporation)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

    ==================== Services (Whitelisted) ======

    2 6to4; C:\Windows\System32\6to4svc.dll [100352 2008-04-14] (Microsoft Corporation)
    4 Alerter; C:\Windows\System32\alrsvc.dll [17408 2008-04-14] (Microsoft Corporation)
    3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [34312 2008-07-25] (Microsoft Corporation)
    4 ClipSrv; C:\Windows\System32\clipsrv.exe [33280 2008-04-14] (Microsoft Corporation)
    3 dmadmin; C:\Windows\System32\dmadmin.exe /com [224768 2008-04-14] (Microsoft Corp., Veritas Software)
    2 dmserver; C:\Windows\System32\dmserver.dll [23552 2008-04-14] (Microsoft Corp.)
    2 ERSvc; C:\Windows\System32\ersvc.dll [23040 2008-04-14] (Microsoft Corporation)
    2 Eventlog; C:\Windows\System32\services.exe [108544 2008-04-14] (Microsoft Corporation)
    3 FastUserSwitchingCompatibility; C:\Windows\System32\shsvcs.dll [135168 2008-04-14] (Microsoft Corporation)
    3 FontCache3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [46104 2008-07-29] (Microsoft Corporation)
    2 helpsvc; C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400 2008-04-14] (Microsoft Corporation)
    3 HTTPFilter; C:\Windows\System32\w3ssl.dll [15872 2008-04-14] (Microsoft Corporation)
    3 idsvc; "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" [881664 2008-07-29] (Microsoft Corporation)
    3 ImapiService; C:\WINDOWS\system32\imapi.exe [150528 2008-04-14] (Microsoft Corporation)
    2 lxcj_device; C:\WINDOWS\system32\lxcjcoms.exe -service [537520 2007-01-30] ( )
    4 Messenger; C:\Windows\System32\msgsvc.dll [33792 2008-04-14] (Microsoft Corporation)
    3 MHN; C:\Windows\System32\mhn.dll [85504 2004-08-10] (Microsoft Corporation)
    4 mnmsrvc; C:\WINDOWS\system32\mnmsrvc.exe [32768 2008-04-14] (Microsoft Corporation)
    4 NetDDE; C:\Windows\System32\netdde.exe [111104 2008-04-14] (Microsoft Corporation)
    4 NetDDEdsdm; C:\Windows\System32\netdde.exe [111104 2008-04-14] (Microsoft Corporation)
    3 Nla; C:\Windows\System32\mswsock.dll [245248 2008-04-14] (Microsoft Corporation)
    3 NtLmSsp; C:\Windows\System32\lsass.exe [13312 2008-04-14] (Microsoft Corporation)
    3 NtmsSvc; C:\Windows\System32\ntmssvc.dll [435200 2008-04-14] (Microsoft Corporation)
    2 NVSvc; C:\Windows\System32\nvsvc32.exe [154216 2010-04-03] (NVIDIA Corporation)
    2 PlugPlay; C:\Windows\System32\services.exe [108544 2008-04-14] (Microsoft Corporation)
    2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [66872 2010-04-09] ()
    2 PolicyAgent; C:\Windows\System32\lsass.exe [13312 2008-04-14] (Microsoft Corporation)
    3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [141312 2008-04-14] (Microsoft Corporation)
    3 RSVP; C:\Windows\System32\rsvp.exe [132608 2004-08-10] (Microsoft Corporation)
    3 SCardSvr; C:\Windows\System32\SCardSvr.exe [95744 2008-04-14] (Microsoft Corporation)
    2 spupdsvc; C:\WINDOWS\system32\spupdsvc.exe [26144 2008-11-07] (Microsoft Corporation)
    2 srservice; C:\WINDOWS\system32\srsvc.dll [171008 2008-04-14] (Microsoft Corporation)
    3 SwPrv; C:\WINDOWS\system32\dllhost.exe /Processid:{F274480A-2FB4-47AA-AE28-712AFE5B340B} [5120 2008-04-14] (Microsoft Corporation)
    3 SysmonLog; C:\Windows\System32\smlogsvc.exe [89600 2008-04-14] (Microsoft Corporation)
    4 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [73216 2008-04-14] (Microsoft Corporation)
    3 UPS; C:\Windows\System32\ups.exe [18432 2008-04-14] (Microsoft Corporation)
    3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [25088 2005-01-28] (Microsoft Corporation)
    3 Wmi; C:\Windows\System32\advapi32.dll [617472 2008-04-14] (Microsoft Corporation)
    2 wuauserv; C:\WINDOWS\system32\wuauserv.dll [25944 2007-06-26] (Microsoft Corporation)
    2 WZCSVC; C:\Windows\System32\wzcsvc.dll [483840 2008-04-14] (Microsoft Corporation)
    3 xmlprov; C:\Windows\System32\xmlprov.dll [129024 2008-04-14] (Microsoft Corporation)
    2 ANIWZCSdService; C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe [x]
    2 Apple Mobile Device; "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" [x]
    2 avast! Antivirus; "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe" [x]
    2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [x]
    3 FLEXnet Licensing Service; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [x]
    3 IDriverT; "C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe" [x]
    3 iPod Service; "C:\Program Files\iPod\bin\iPodService.exe" [x]
    2 JavaQuickStarterService; "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" [x]
    4 LightScribeService; "C:\Program Files\Common Files\LightScribe\LSSrvc.exe" [x]
    3 NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [x]
    3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [x]
    4 ose; "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" [x]
    4 RoxLiveShare9; "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]
    4 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP2\RpcAgentSrv.exe [x]
    2 Viewpoint Manager Service; "C:\Program Files\Viewpoint\Common\ViewpointService.exe" [x]

    ========================== Drivers (Whitelisted) =============

    3 A3AB; C:\Windows\System32\Drivers\A3AB.sys [547744 2007-05-24] (D-Link Corporation)
    1 Aavmker4; C:\Windows\System32\Drivers\Aavmker4.sys [29392 2011-01-13] (AVAST Software)
    4 ACPIEC; C:\Windows\System32\Drivers\ACPIEC.sys [11648 2004-08-10] (Microsoft Corporation)
    3 aec; C:\Windows\System32\Drivers\aec.sys [142592 2008-04-13] (Microsoft Corporation)
    1 ASPI32; C:\Windows\System32\Drivers\ASPI32.sys [25244 1999-09-10] (Adaptec)
    2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [17744 2011-01-13] (AVAST Software)
    2 aswMon2; C:\Windows\System32\Drivers\aswMon2.sys [100176 2011-01-13] (AVAST Software)
    1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [23632 2011-01-13] (AVAST Software)
    1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [294608 2011-01-13] (AVAST Software)
    1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [47440 2011-01-13] (AVAST Software)
    3 Atmarpc; C:\Windows\System32\Drivers\Atmarpc.sys [59904 2008-04-13] (Microsoft Corporation)
    3 audstub; C:\Windows\System32\Drivers\audstub.sys [3072 2001-08-17] (Microsoft Corporation)
    4 cbidf2k; C:\Windows\System32\Drivers\cbidf2k.sys [13952 2004-08-10] (Microsoft Corporation)
    1 Cdaudio; C:\Windows\System32\Drivers\Cdaudio.sys [18688 2007-06-26] (Microsoft Corporation)
    3 ctljystk; C:\Windows\System32\Drivers\ctljystk.sys [3712 2001-08-17] (Creative Technology Ltd.)
    4 dmboot; C:\Windows\System32\Drivers\dmboot.sys [799744 2008-04-13] (Microsoft Corp., Veritas Software)
    0 dmio; C:\Windows\System32\Drivers\dmio.sys [153344 2008-04-13] (Microsoft Corp., Veritas Software)
    0 dmload; C:\Windows\System32\Drivers\dmload.sys [5888 2004-08-10] (Microsoft Corp., Veritas Software.)
    3 DMusic; C:\Windows\System32\Drivers\DMusic.sys [52864 2008-04-13] (Microsoft Corporation)
    3 emu10k; C:\Windows\System32\drivers\emu10k1m.sys [283904 2001-08-17] (Creative Technology Ltd.)
    3 emu10k1; C:\Windows\System32\drivers\ctlfacem.sys [6912 2001-08-17] (Creative Technology Ltd.)
    3 ET5Drv; C:\Windows\System32\Drivers\ET5Drv.sys [40136 2006-11-24] (Microsoft Corporation)
    1 Fips; C:\Windows\System32\Drivers\Fips.sys [44544 2008-04-13] (Microsoft Corporation)
    0 Ftdisk; C:\Windows\System32\Drivers\Ftdisk.sys [125056 2004-08-10] (Microsoft Corporation)
    3 gameenum; C:\Windows\System32\Drivers\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
    3 gdrv; \??\C:\WINDOWS\gdrv.sys [14656 2009-04-25] (Windows (R) Codename Longhorn DDK provider)
    3 Gpc; C:\Windows\System32\DRIVERS\msgpc.sys [35072 2008-04-13] (Microsoft Corporation)
    3 hamachi; C:\Windows\System32\Drivers\hamachi.sys [17480 2009-04-07] (LogMeIn, Inc.)
    3 HDAudBus; C:\Windows\System32\Drivers\HDAudBus.sys [138752 2007-06-26] (Windows (R) Server 2003 DDK provider)
    3 ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [1353820 2005-11-27] (Intel Corporation)
    1 Imapi; C:\Windows\System32\Drivers\Imapi.sys [42112 2008-04-13] (Microsoft Corporation)
    3 Ip6Fw; C:\Windows\System32\Drivers\Ip6Fw.sys [36608 2008-04-13] (Microsoft Corporation)
    3 IpInIp; C:\Windows\System32\Drivers\IpInIp.sys [20864 2008-04-13] (Microsoft Corporation)
    1 IPSec; C:\Windows\System32\Drivers\IPSec.sys [75264 2008-04-13] (Microsoft Corporation)
    3 kmixer; C:\Windows\System32\Drivers\kmixer.sys [172416 2008-04-13] (Microsoft Corporation)
    2 LBeepKE; C:\Windows\System32\Drivers\LBeepKE.sys [10448 2010-03-18] (Logitech, Inc.)
    3 MHNDRV; C:\Windows\System32\Drivers\MHNDRV.sys [11008 2004-08-10] (Microsoft Corporation)
    1 mnmdd; C:\Windows\System32\Drivers\mnmdd.sys [4224 2004-08-10] (Microsoft Corporation)
    3 nv; C:\Windows\System32\DRIVERS\nv4_mini.sys [10232128 2010-04-03] (NVIDIA Corporation)
    3 NwlnkFlt; C:\Windows\System32\Drivers\NwlnkFlt.sys [12416 2004-08-10] (Microsoft Corporation)
    3 NwlnkFwd; C:\Windows\System32\Drivers\NwlnkFwd.sys [32512 2004-08-10] (Microsoft Corporation)
    3 PSched; C:\Windows\System32\Drivers\PSched.sys [69120 2008-04-13] (Microsoft Corporation)
    3 Ptilink; C:\Windows\System32\Drivers\Ptilink.sys [17792 2004-08-10] (Parallel Technologies, Inc.)
    0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [44944 2009-04-28] (Sonic Solutions)
    3 Raspti; C:\Windows\System32\Drivers\Raspti.sys [16512 2004-08-10] (Microsoft Corporation)
    1 redbook; C:\Windows\System32\Drivers\redbook.sys [57600 2008-04-13] (Microsoft Corporation)
    3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial.sys [27136 2009-01-09] (Research in Motion Ltd)
    3 RTLE8023xp; C:\Windows\System32\DRIVERS\Rtenicxp.sys [98944 2007-08-07] (Realtek Semiconductor Corporation )
    3 sfman; C:\Windows\System32\drivers\sfmanm.sys [36480 2001-08-17] (Creative Technology Ltd.)
    3 splitter; C:\Windows\System32\Drivers\splitter.sys [6272 2008-04-13] (Microsoft Corporation)
    0 sr; C:\Windows\System32\Drivers\sr.sys [73472 2008-04-13] (Microsoft Corporation)
    3 swmidi; C:\Windows\System32\Drivers\swmidi.sys [56576 2008-04-13] (Microsoft Corporation)
    3 sysaudio; C:\Windows\System32\Drivers\sysaudio.sys [60800 2008-04-13] (Microsoft Corporation)
    1 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [225664 2008-04-13] (Microsoft Corporation)
    3 Update; C:\Windows\System32\Drivers\Update.sys [384768 2008-04-13] (Microsoft Corporation)
    3 USBAAPL; C:\Windows\System32\Drivers\USBAAPL.sys [30464 2008-02-18] (Apple, Inc.)
    3 wdmaud; C:\Windows\System32\Drivers\wdmaud.sys [83072 2008-04-13] (Microsoft Corporation)
    4 Abiosdsk; [x]
    4 abp480n5; [x]
    4 adpu160m; [x]
    4 Aha154x; [x]
    4 aic78u2; [x]
    4 aic78xx; [x]
    4 AliIde; [x]
    4 amsint; [x]
    4 asc; [x]
    4 asc3350p; [x]
    4 asc3550; [x]
    4 Atdisk; [x]
    4 cd20xrnt; [x]
    1 Changer; [x]
    4 CmdIde; [x]
    4 Cpqarray; [x]
    4 dac2w2k; [x]
    4 dac960nt; [x]
    4 dpti2o; [x]
    3 FreshIO; \??\C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys [x]
    4 hpn; [x]
    1 i2omgmt; [x]
    4 i2omp; [x]
    4 ini910u; [x]
    3 IntcAzAudAddService; C:\Windows\System32\drivers\RtkHDAud.sys [x]
    4 IntelIde; [x]
    3 iscFlash; \??\C:\SwSetup\SP46501\iscflash.sys [x]
    1 lbrtfdc; [x]
    4 mraid35x; [x]
    1 PCIDump; [x]
    3 PDCOMP; [x]
    3 PDFRAME; [x]
    3 PDRELI; [x]
    3 PDRFRAME; [x]
    4 perc2; [x]
    4 perc2hib; [x]
    4 ql1080; [x]
    4 Ql10wnt; [x]
    4 ql12160; [x]
    4 ql1240; [x]
    4 ql1280; [x]
    3 RimUsb; C:\Windows\System32\Drivers\RimUsb.sys [x]
    3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP2\WNt500x86\Sandra.sys [x]
    4 Simbad; [x]
    4 Sparrow; [x]
    4 symc810; [x]
    4 symc8xx; [x]
    4 sym_hi; [x]
    4 sym_u3; [x]
    4 TosIde; [x]
    4 ultra; [x]
    4 ViaIde; [x]
    3 WDICA; [x]

    ========================== NetSvcs (Whitelisted) ===========


    ============ One Month Created Files and Folders ==============


    ============ 3 Months Modified Files ========================


    ========================= Known DLLs (Whitelisted) ============

    C:\Windows\SysWOW64\advapi32.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\comdlg32.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\gdi32.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\imagehlp.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\kernel32.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\lz32.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\ole32.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\oleaut32.dll IS MISSING <==== ATTENTION!
    [2007-06-26 03:56] - [2008-04-14 03:42] - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\olecli32.dll
    C:\Windows\SysWOW64\olecli32.dll IS MISSING <==== ATTENTION!
    [2007-06-26 03:56] - [2008-04-14 03:42] - 0037376 ____A (Microsoft Corporation) C:\Windows\System32\olecnv32.dll
    C:\Windows\SysWOW64\olecnv32.dll IS MISSING <==== ATTENTION!
    [2004-08-10 04:00] - [2004-08-10 04:00] - 0022016 ____A (Microsoft Corporation) C:\Windows\System32\olesvr32.dll
    C:\Windows\SysWOW64\olesvr32.dll IS MISSING <==== ATTENTION!
    [2004-08-10 04:00] - [2004-08-10 04:00] - 0069120 ____A (Microsoft Corporation) C:\Windows\System32\olethk32.dll
    C:\Windows\SysWOW64\olethk32.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\rpcrt4.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\shell32.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\url.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\urlmon.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\user32.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\version.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\wininet.dll IS MISSING <==== ATTENTION!
    C:\Windows\SysWOW64\wldap32.dll IS MISSING <==== ATTENTION!

    ========================= Bamital & volsnap Check ============

    C:\Windows\System32\winlogon.exe
    [2004-08-10 04:00] - [2008-04-14 03:42] - 0507904 ____A (Microsoft Corporation) ED0EF0A136DEC83DF69F04118870003E

    C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!.
    C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.
    C:\Windows\explorer.exe
    [2007-06-26 03:54] - [2008-04-14 03:42] - 1033728 ____A (Microsoft Corporation) 12896823FB95BFB3DC9B46BCAEDC9923

    C:\Windows\SysWOW64\explorer.exe IS MISSING <==== ATTENTION!.
    C:\Windows\System32\svchost.exe
    [2004-08-10 04:00] - [2008-04-14 03:42] - 0014336 ____A (Microsoft Corporation) 27C6D03BCDB8CFEB96B716F3D8BE3E18

    C:\Windows\SysWOW64\svchost.exe IS MISSING <==== ATTENTION!.
    C:\Windows\System32\services.exe
    [2004-08-10 04:00] - [2008-04-14 03:42] - 0108544 ____A (Microsoft Corporation) 0E776ED5F7CC9F94299E70461B7B8185

    C:\Windows\System32\User32.dll
    [2007-06-26 03:56] - [2008-04-14 03:42] - 0578560 ____A (Microsoft Corporation) B26B135FF1B9F60C9388B4A7D16F600B

    C:\Windows\SysWOW64\User32.dll IS MISSING <==== ATTENTION!.
    C:\Windows\System32\userinit.exe
    [2004-08-10 04:00] - [2008-04-14 03:42] - 0026112 ____A (Microsoft Corporation) A93AEE1928A9D7CE3E16D24EC7380F89

    C:\Windows\SysWOW64\userinit.exe IS MISSING <==== ATTENTION!.
    C:\Windows\System32\Drivers\volsnap.sys
    [2004-08-10 04:00] - [2008-04-13 22:11] - 0052352 ____A (Microsoft Corporation) 4C8FCB5CC53AAB716D810740FE59D025


    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ========================= Memory info ======================

    Percentage of memory in use: 6%
    Total physical RAM: 16381.53 MB
    Available physical RAM: 15268.53 MB
    Total Pagefile: 16379.73 MB
    Available Pagefile: 15283.43 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.9 MB

    ======================= Partitions =========================

    3 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
    4 Drive f: () (Fixed) (Total:111.69 GB) (Free:25.66 GB) NTFS
    7 Drive I: () (Removable) (Total:3.74 GB) (Free:2.5 GB) FAT32
    8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    9 Drive y: (Western Digital) (Fixed) (Total:465.76 GB) (Free:395.27 GB) NTFS

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 465 GB 1024 KB
    Disk 1 Online 111 GB 0 B
    Disk 2 Online 465 GB 0 B
    Disk 3 Online 3835 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 465 GB 1024 KB

    ==================================================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 Y Western Dig NTFS Partition 465 GB Healthy

    ==================================================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 100 MB 1024 KB
    Partition 2 Primary 111 GB 101 MB

    ==================================================================================

    Disk: 1
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 D System Rese NTFS Partition 100 MB Healthy

    ==================================================================================

    Disk: 1
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 F NTFS Partition 111 GB Healthy

    ==================================================================================

    Partitions of Disk 2:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 465 GB 31 KB

    ==================================================================================

    Disk: 2
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 5 C Partition 465 GB Healthy

    ==================================================================================

    Partitions of Disk 3:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 3827 MB 19 KB

    ==================================================================================

    Disk: 3
    Partition 1
    Type : 0B
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 6 I FAT32 Removable 3827 MB Healthy

    ==================================================================================
    ======================= End Of Log ==========================
     
  12. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    Search TXT

    Farbar Recovery Scan Tool Version: 09-08-2012
    Ran by SYSTEM at 2012-08-09 20:03:05
    Running from I:\

    ================== Search: "services.exe" ===================

    ====== End Of Search ======
     
  13. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Restart normally.

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.
    Vista and Win7 users need to right click Rkill and choose Run as Administrator
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.exe
    • Double-click on the Rkill icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  14. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    ComboFix 12-08-09.01 - Reggin 08/09/2012 20:24:33.1.6 - x64
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16382.14696 [GMT -5:00]
    Running from: d:\users\Reggin\Desktop\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-07-10 to 2012-08-10 )))))))))))))))))))))))))))))))
    .
    .
    2012-08-09 17:34 . 2012-08-09 17:34 -------- d-----w- c:\program files\Common Files\DESIGNER
    2012-08-09 17:34 . 2012-08-09 17:34 -------- d-----w- c:\program files\Microsoft Synchronization Services
    2012-08-09 17:33 . 2012-08-09 17:33 -------- d-----w- c:\program files\Microsoft Sync Framework
    2012-08-09 17:33 . 2012-08-09 17:33 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
    2012-08-09 17:33 . 2012-08-09 17:33 -------- d-----w- c:\program files\Microsoft Analysis Services
    2012-08-09 17:24 . 2012-08-09 17:24 -------- d-----w- c:\users\Reggin\AppData\Local\ElevatedDiagnostics
    2012-08-09 17:24 . 2012-08-09 17:28 -------- d-----w- C:\MATS
    2012-08-05 17:40 . 2012-08-05 17:40 955888 ----a-w- c:\windows\system32\npDeployJava1.dll
    2012-08-05 17:40 . 2012-08-05 17:40 268784 ----a-w- c:\windows\system32\javaws.exe
    2012-08-05 17:40 . 2012-08-05 17:40 189424 ----a-w- c:\windows\system32\javaw.exe
    2012-08-05 17:40 . 2012-08-05 17:40 188912 ----a-w- c:\windows\system32\java.exe
    2012-08-05 17:40 . 2012-08-05 17:40 -------- d-----w- c:\program files\Java
    2012-08-04 19:55 . 2012-08-04 19:55 -------- d-----w- c:\programdata\McAfee
    2012-07-29 17:50 . 2012-07-29 18:29 -------- d-----w- c:\program files (x86)\Rosetta Stone
    2012-07-29 17:38 . 2012-07-29 17:38 -------- d-----w- c:\program files (x86)\Common Files\Macrovision Shared
    2012-07-29 17:38 . 2012-07-29 17:49 -------- d-----w- c:\programdata\Rosetta Stone
    2012-07-28 18:36 . 2012-07-28 18:36 -------- d-----w- c:\program files\iTunes
    2012-07-28 18:36 . 2012-07-28 18:36 -------- d-----w- c:\program files\iPod
    2012-07-28 18:26 . 2012-05-15 09:29 889664 ----a-w- c:\windows\system32\nvvsvc.exe
    2012-07-28 18:26 . 2012-05-15 09:29 63296 ----a-w- c:\windows\system32\nvshext.dll
    2012-07-28 18:26 . 2012-05-15 09:29 2621723 ----a-w- c:\windows\system32\nvcoproc.bin
    2012-07-28 18:26 . 2012-05-15 09:29 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
    2012-07-28 18:26 . 2012-05-15 09:28 6151488 ----a-w- c:\windows\system32\nvcpl.dll
    2012-07-28 18:26 . 2012-05-15 09:29 118080 ----a-w- c:\windows\system32\nvmctray.dll
    2012-07-28 18:26 . 2012-07-28 18:26 -------- d-----w- c:\programdata\NVIDIA Corporation
    2012-07-28 17:57 . 2012-07-28 17:57 -------- d-----w- c:\program files (x86)\Common Files\Adobe
    2012-07-27 22:14 . 2012-07-27 22:14 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
    2012-07-27 22:01 . 2012-08-03 04:58 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-07-27 22:01 . 2012-08-03 04:58 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2012-07-27 21:46 . 2012-08-09 17:37 -------- d-sh--w- c:\windows\Installer
    2012-07-27 18:38 . 2012-07-27 18:38 -------- d-----w- c:\windows\system32\appmgmt
    2012-07-27 18:07 . 2012-07-03 16:21 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2012-07-27 18:07 . 2012-07-03 16:21 958400 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2012-07-27 18:07 . 2012-07-03 16:21 71064 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2012-07-27 18:07 . 2012-07-03 16:21 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2012-07-27 18:07 . 2012-07-03 16:21 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
    2012-07-27 18:07 . 2012-07-03 16:21 355856 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2012-07-27 18:07 . 2012-07-03 16:21 41224 ----a-w- c:\windows\avastSS.scr
    2012-07-27 18:07 . 2012-07-03 16:21 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
    2012-07-27 18:00 . 2012-07-27 18:00 -------- d-----w- c:\users\Reggin\AppData\Roaming\Malwarebytes
    2012-07-27 18:00 . 2012-07-27 18:00 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-07-27 18:00 . 2012-07-27 18:00 -------- d-----w- c:\programdata\Malwarebytes
    2012-07-27 18:00 . 2012-07-03 18:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-07-27 17:29 . 2012-07-27 17:29 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
    2012-07-27 17:24 . 2012-07-27 17:24 -------- d-----w- c:\users\Reggin\AppData\Local\{DB217A9F-D80F-11E1-8270-B8AC6F996F26}
    2012-07-19 23:29 . 2012-07-19 23:29 -------- d-----w- c:\users\Reggin\AppData\Local\SIX_Projects
    2012-07-19 22:56 . 2012-07-19 22:56 -------- d-----w- c:\users\Reggin\AppData\Roaming\gslist
    2012-07-19 22:56 . 2012-07-19 22:56 -------- d-----w- c:\users\Reggin\AppData\Local\DayZCommander
    2012-07-19 22:37 . 2012-07-19 23:32 -------- d-----w- c:\users\Reggin\AppData\Roaming\six-updater
    2012-07-19 22:37 . 2012-07-19 22:37 -------- d-----w- c:\users\Reggin\AppData\Roaming\six-zsync
    2012-07-19 22:36 . 2012-07-19 22:36 -------- d-----w- c:\users\Reggin\AppData\Local\ArmA 2
    2012-07-19 06:10 . 2012-08-03 20:23 -------- d-----w- c:\users\Reggin\AppData\Local\ArmA 2 OA
    2012-07-17 02:28 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
    2012-07-17 02:23 . 2012-06-09 05:43 14172672 ----a-w- c:\windows\system32\shell32.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-08-09 21:57 . 2012-06-22 05:28 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
    2012-08-09 21:57 . 2012-04-30 03:23 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
    2012-08-09 19:47 . 2012-04-30 03:23 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
    2012-08-05 17:40 . 2012-04-10 01:53 839152 ----a-w- c:\windows\system32\deployJava1.dll
    2012-07-03 16:21 . 2012-01-08 21:28 285328 ----a-w- c:\windows\system32\aswBoot.exe
    2012-07-03 08:19 . 2012-01-08 20:19 59701280 ----a-w- c:\windows\system32\MRT.exe
    2012-06-25 21:04 . 2012-06-25 21:04 1394248 ----a-w- c:\windows\SysWow64\msxml4.dll
    2012-06-02 22:19 . 2012-06-21 02:07 38424 ----a-w- c:\windows\system32\wups.dll
    2012-06-02 22:19 . 2012-06-21 02:07 2428952 ----a-w- c:\windows\system32\wuaueng.dll
    2012-06-02 22:19 . 2012-06-21 02:07 57880 ----a-w- c:\windows\system32\wuauclt.exe
    2012-06-02 22:19 . 2012-06-21 02:07 44056 ----a-w- c:\windows\system32\wups2.dll
    2012-06-02 22:19 . 2012-06-21 02:07 701976 ----a-w- c:\windows\system32\wuapi.dll
    2012-06-02 22:15 . 2012-06-21 02:07 2622464 ----a-w- c:\windows\system32\wucltux.dll
    2012-06-02 22:15 . 2012-06-21 02:07 99840 ----a-w- c:\windows\system32\wudriver.dll
    2012-06-02 20:19 . 2012-06-21 02:07 186752 ----a-w- c:\windows\system32\wuwebv.dll
    2012-06-02 20:15 . 2012-06-21 02:07 36864 ----a-w- c:\windows\system32\wuapp.exe
    2012-05-31 04:04 . 2012-06-22 03:47 9013136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{19B2C92D-36EA-4CA9-A3E7-8268BD5B346E}\mpengine.dll
    2012-05-15 10:48 . 2012-02-24 08:54 949056 ----a-w- c:\windows\system32\nvumdshimx.dll
    2012-05-15 10:48 . 2012-02-24 08:54 68928 ----a-w- c:\windows\system32\OpenCL.dll
    2012-05-15 10:48 . 2012-02-24 08:54 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
    2012-05-15 10:48 . 2012-02-24 08:54 2741568 ----a-w- c:\windows\system32\nvapi64.dll
    2012-05-15 10:48 . 2012-02-24 08:54 25743168 ----a-w- c:\windows\system32\nvoglv64.dll
    2012-05-15 10:48 . 2012-02-24 08:54 1738048 ----a-w- c:\windows\system32\nvdispco64.dll
    2012-05-15 10:48 . 2012-02-24 08:54 1468224 ----a-w- c:\windows\system32\nvgenco64.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files (x86)\Steam\steam.exe" [2012-08-04 1353080]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
    "ASUS Sync Loader"="c:\program files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe" [2012-06-15 638976]
    "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
    "iTunesHelper"="d:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-08 421776]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-03 250056]
    R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
    R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-12-28 51727736]
    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120]
    R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
    R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2011-10-04 80000]
    S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2011-10-04 40576]
    S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2011-01-11 21104]
    S1 aswSnx;aswSnx; [x]
    S1 aswSP;aswSP; [x]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
    S2 aswFsBlk;aswFsBlk; [x]
    S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-07-03 71064]
    S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2012-01-09 22408]
    S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2012-01-09 16008]
    S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-20 75776]
    S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-20 177152]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-11-09 187200]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-01-13 413800]
    S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2011-08-17 53376]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - WS2IFSL
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-08-09 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-27 04:58]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2012-07-03 16:21 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-09-29 110360]
    "Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
    TCP: DhcpNameServer = 192.168.1.254
    FF - ProfilePath - c:\users\Reggin\AppData\Roaming\Mozilla\Firefox\Profiles\n9jdz56u.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Wow6432Node-HKLM-Run-BCSSync - c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe
    AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
    AddRemove-BattlEye for A2 - c:\program files (x86)\steam\steamapps\common\arma 2BattlEye\UnInstallBE.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{01F2485C-FAEE-47E7-986E-B4F2FFC22D57} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{07CA44F3-F5B3-4D12-8C91-EDC5FE91D45C} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{10802A6D-EDBF-4383-BCBD-9D5B32F56D35} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{18B3CF2A-73F7-4716-B1AE-86D68726D408} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{28FAC187-7C0E-413A-B90A-76F19D0FBF30} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{337A3FB9-281D-4EC8-9CC1-7F6DDAC2359F} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{3613AECC-1454-4DDD-AC36-C42DC16D6DEE} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{38990592-F6A1-4A26-96C7-0600E36AE794} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{48E1B6C2-7299-4F3F-AA63-42F0ACE55AA4} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{4D98EEEA-A31B-42FA-991A-F989594F4DA5} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{61461470-8168-4F4B-97B7-617AF354F028} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7AC49FC8-F8D2-4DD8-9086-09E52385A21F} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{A8686D24-1E89-43A1-973E-05A258D2B3F8} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B75541D4-3970-4CC7-934B-D48F8C26DCA5} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B76D8C6D-1F13-42A7-9931-D7504CB89D6D} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BC6DFBFD-16DD-47E1-A7EF-2C062930FA4F} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{C8694FF0-8203-483B-A07A-2BC40433167D} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{CCC48FE2-175F-4CDE-82DF-F7BC4672C1A3} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{D0AC5F9F-1043-4569-ACE3-67EE990EB0E6} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DCE6D0BF-93E4-46C5-9A7C-F1EFF9707C02} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{ED31DE9A-3E13-4E2C-9106-E0D8AFFB9FA6} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFB525A0-E1C0-4E32-9968-FE401BC87363} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{1EEFF749-6F29-4F0B-AB08-4C6EA52AA110} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{5EBDE1DE-3B28-4134-AB00-85CFF2B4F94D} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{17E7B9AB-2DD2-457D-8D8E-CD14ACA973FE} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{15058154-469F-4794-ACD5-94F8420F9B80} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{995A7832-B512-46D5-87C9-2D71FB541435} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{337A3FB9-281D-4EC8-9CC1-7F6DDAC2359F} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{3613AECC-1454-4DDD-AC36-C42DC16D6DEE} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{4D98EEEA-A31B-42FA-991A-F989594F4DA5} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{967EF02C-5C7E-4718-8FCB-BDC050190CCF} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{73E67A3A-8D61-44EF-90C2-1697C3DBE668} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{9865DC3A-2898-48D9-B96A-46397571C934} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    AddRemove-{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
    "value"="?\01\01\09\01\02\04¯"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    @Denied: (A) (Everyone)
    "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    @Denied: (A) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    "Key"="ActionsPane3"
    "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\AVAST Software\Avast\AvastSvc.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\windows\SysWOW64\PnkBstrA.exe
    .
    **************************************************************************
    .
    Completion time: 2012-08-09 20:29:44 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-08-10 01:29
    .
    Pre-Run: 27,431,620,608 bytes free
    Post-Run: 27,286,052,864 bytes free
    .
    - - End Of File - - F410C995D81832A4F4F340576B49DCA0
     
  15. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    FRST log result is confusing.
    Do you have two Windows versions installed?
     
  16. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    No, However there is an old XP install on one of my HDD. The SSD has the Windows 7 64 bit OS install. Drive e: has an old XP install, well at least partially.
     
  17. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    That's probably why.

    Go back to running FRST.
    When it starts it gives you an option which Windows installation you want to repair.
    Make sure you select Windows 7.
    Post new log.
     
  18. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    Scan result of Farbar Recovery Scan Tool Version: 09-08-2012
    Ran by SYSTEM at 09-08-2012 20:58:36
    Running from I:\
    Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
    The current controlset is ControlSet001

    ========================== Registry (Whitelisted) =============

    HKLM\...\Run: [Launch LCore] "C:\Program Files\Logitech Gaming Software\LCore.exe" /minimized [110360 2011-09-29] (Logitech Inc.)
    HKLM\...\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui [190536 2010-06-14] (Logitech Inc.)
    HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
    HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [106496 2009-11-20] (NEC Electronics Corporation)
    HKLM-x32\...\Run: [ASUS Sync Loader] "C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe" -startup [638976 2012-06-15] (Futuredial Inc.)
    HKLM-x32\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4273976 2012-07-03] (AVAST Software)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-04-03] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe" [x]
    HKU\Reggin\...\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1353080 2012-08-04] (Valve Corporation)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

    ==================== Services (Whitelisted) ======

    3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
    2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [44808 2012-07-03] (AVAST Software)
    2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-04-29] ()

    ========================== Drivers (Whitelisted) =============

    1 AppleCharger; C:\Windows\System32\Drivers\AppleCharger.sys [21104 2011-01-10] ()
    2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [25232 2012-07-03] (AVAST Software)
    2 aswMonFlt; C:\Windows\System32\Drivers\aswMonFlt.sys [71064 2012-07-03] (AVAST Software)
    1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [54072 2012-07-03] (AVAST Software)
    1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [958400 2012-07-03] (AVAST Software)
    1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [355856 2012-07-03] (AVAST Software)
    1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [59728 2012-07-03] (AVAST Software)
    3 gdrv; \??\C:\Windows\gdrv.sys [x]
    3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]

    ========================== NetSvcs (Whitelisted) ===========


    ============ One Month Created Files and Folders ==============

    2012-08-09 17:29 - 2012-08-09 17:29 - 00024552 ____A C:\ComboFix.txt
    2012-08-09 17:24 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
    2012-08-09 17:24 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
    2012-08-09 17:24 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
    2012-08-09 17:24 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
    2012-08-09 17:24 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
    2012-08-09 17:24 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
    2012-08-09 17:24 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
    2012-08-09 17:24 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
    2012-08-09 17:23 - 2012-08-09 17:29 - 00000000 ____D C:\Qoobox
    2012-08-09 17:23 - 2012-08-09 17:28 - 00000000 ____D C:\Windows\erdnt
    2012-08-09 09:34 - 2012-08-09 09:34 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
    2012-08-09 09:34 - 2012-08-09 09:34 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
    2012-08-09 09:33 - 2012-08-09 09:33 - 00000000 ____D C:\Program Files\Microsoft Sync Framework
    2012-08-09 09:33 - 2012-08-09 09:33 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
    2012-08-09 09:33 - 2012-08-09 09:33 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
    2012-08-09 09:33 - 2012-08-09 09:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
    2012-08-09 09:24 - 2012-08-09 09:28 - 00000000 ____D C:\MATS
    2012-08-05 09:40 - 2012-08-05 09:40 - 00955888 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
    2012-08-05 09:40 - 2012-08-05 09:40 - 00268784 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
    2012-08-05 09:40 - 2012-08-05 09:40 - 00189424 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
    2012-08-05 09:40 - 2012-08-05 09:40 - 00188912 ____A (Oracle Corporation) C:\Windows\System32\java.exe
    2012-08-05 09:40 - 2012-08-05 09:40 - 00000000 ____D C:\Program Files\Java
    2012-08-04 11:55 - 2012-08-04 11:55 - 00000000 ____D C:\Users\All Users\McAfee
    2012-07-29 09:50 - 2012-07-29 10:29 - 00000000 ____D C:\Program Files (x86)\Rosetta Stone
    2012-07-29 09:38 - 2012-07-29 09:49 - 00000000 ____D C:\Users\All Users\Rosetta Stone
    2012-07-28 10:36 - 2012-07-28 10:36 - 00001583 ____A C:\Users\Public\Desktop\iTunes.lnk
    2012-07-28 10:36 - 2012-07-28 10:36 - 00000000 ____D C:\Program Files\iTunes
    2012-07-28 10:36 - 2012-07-28 10:36 - 00000000 ____D C:\Program Files\iPod
    2012-07-28 10:30 - 2012-05-15 02:48 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
    2012-07-28 10:30 - 2012-05-15 02:48 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
    2012-07-28 10:30 - 2012-05-15 02:48 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2012-07-28 10:26 - 2012-07-28 10:26 - 00000000 ____D C:\Users\All Users\NVIDIA Corporation
    2012-07-28 10:26 - 2012-05-15 01:29 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
    2012-07-28 10:26 - 2012-05-15 01:29 - 02621723 ____A C:\Windows\System32\nvcoproc.bin
    2012-07-28 10:26 - 2012-05-15 01:29 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    2012-07-28 10:26 - 2012-05-15 01:29 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
    2012-07-28 10:26 - 2012-05-15 01:29 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
    2012-07-28 10:26 - 2012-05-15 01:28 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
    2012-07-28 09:57 - 2012-07-28 09:57 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
    2012-07-28 09:57 - 2012-07-28 09:57 - 00000000 ____D C:\Program Files (x86)\Adobe
    2012-07-27 14:14 - 2012-07-27 14:14 - 00000810 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2012-07-27 14:14 - 2012-07-27 14:14 - 00000000 ____D C:\Users\Reggin\Application Data\Mozilla
    2012-07-27 14:14 - 2012-07-27 14:14 - 00000000 ____D C:\Users\Reggin\AppData\Roaming\Mozilla
    2012-07-27 14:14 - 2012-07-27 14:14 - 00000000 ____D C:\Users\All Users\Mozilla
    2012-07-27 14:14 - 2012-07-27 14:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2012-07-27 14:01 - 2012-08-09 15:58 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-07-27 14:01 - 2012-08-02 20:58 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-07-27 14:01 - 2012-08-02 20:58 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-07-27 10:39 - 2012-07-03 00:13 - 57442464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe
    2012-07-27 10:38 - 2012-07-27 10:38 - 00000000 ____D C:\Windows\System32\appmgmt
    2012-07-27 10:07 - 2012-07-28 19:55 - 00001966 ____A C:\Users\Public\Desktop\avast! Free Antivirus.lnk
    2012-07-27 10:07 - 2012-07-03 08:21 - 00958400 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
    2012-07-27 10:07 - 2012-07-03 08:21 - 00355856 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
    2012-07-27 10:07 - 2012-07-03 08:21 - 00227648 ____A (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe
    2012-07-27 10:07 - 2012-07-03 08:21 - 00071064 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
    2012-07-27 10:07 - 2012-07-03 08:21 - 00059728 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
    2012-07-27 10:07 - 2012-07-03 08:21 - 00054072 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
    2012-07-27 10:07 - 2012-07-03 08:21 - 00041224 ____A (AVAST Software) C:\Windows\avastSS.scr
    2012-07-27 10:07 - 2012-07-03 08:21 - 00025232 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
    2012-07-27 10:00 - 2012-07-27 10:00 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-07-27 10:00 - 2012-07-27 10:00 - 00000000 ____D C:\Users\Reggin\Application Data\Malwarebytes
    2012-07-27 10:00 - 2012-07-27 10:00 - 00000000 ____D C:\Users\Reggin\AppData\Roaming\Malwarebytes
    2012-07-27 10:00 - 2012-07-27 10:00 - 00000000 ____D C:\Users\All Users\Malwarebytes
    2012-07-27 10:00 - 2012-07-27 10:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-07-27 10:00 - 2012-07-03 10:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-07-27 09:29 - 2012-07-27 09:29 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
    2012-07-27 09:24 - 2012-07-27 09:24 - 00000000 ____D C:\Users\Reggin\AppData\Local\{DB217A9F-D80F-11E1-8270-B8AC6F996F26}
    2012-07-27 09:23 - 2012-07-27 09:23 - 00000012 ____A C:\Windows\srun.log
    2012-07-19 15:29 - 2012-07-19 15:29 - 00000000 ____D C:\Users\Reggin\AppData\Local\SIX_Projects
    2012-07-19 14:56 - 2012-07-19 14:56 - 00000000 ____D C:\Users\Reggin\Application Data\gslist
    2012-07-19 14:56 - 2012-07-19 14:56 - 00000000 ____D C:\Users\Reggin\AppData\Roaming\gslist
    2012-07-19 14:56 - 2012-07-19 14:56 - 00000000 ____D C:\Users\Reggin\AppData\Local\DayZCommander
    2012-07-19 14:42 - 2012-07-19 14:42 - 00001076 ____A C:\Users\Public\Desktop\DayZ Commander.lnk
    2012-07-19 14:37 - 2012-07-19 15:32 - 00000000 ____D C:\Users\Reggin\Application Data\six-updater
    2012-07-19 14:37 - 2012-07-19 15:32 - 00000000 ____D C:\Users\Reggin\AppData\Roaming\six-updater
    2012-07-19 14:37 - 2012-07-19 14:37 - 00000000 ____D C:\Users\Reggin\Application Data\six-zsync
    2012-07-19 14:37 - 2012-07-19 14:37 - 00000000 ____D C:\Users\Reggin\AppData\Roaming\six-zsync
    2012-07-19 14:36 - 2012-07-19 14:36 - 00000000 ____D C:\Users\Reggin\AppData\Local\ArmA 2
    2012-07-19 14:34 - 2012-07-31 14:02 - 00002573 ____A C:\Users\Public\Desktop\Six Updater.lnk
    2012-07-19 14:34 - 2012-07-31 14:02 - 00002573 ____A C:\Users\Public\Desktop\Six Launcher.lnk
    2012-07-18 22:10 - 2012-08-03 12:23 - 00000000 ____D C:\Users\Reggin\AppData\Local\ArmA 2 OA
    2012-07-16 18:28 - 2012-07-16 18:28 - 00261590 ____A C:\Windows\msxml4-KB2721691-enu.LOG
    2012-07-16 18:28 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-07-16 18:26 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-07-16 18:26 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-07-16 18:26 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-07-16 18:26 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-07-16 18:26 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-07-16 18:26 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-07-16 18:26 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-07-16 18:26 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-07-16 18:26 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-07-16 18:26 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-07-16 18:26 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-07-16 18:26 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-07-16 18:26 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-07-16 18:26 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-07-16 18:26 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-07-16 18:26 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-07-16 18:26 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-07-16 18:26 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-07-16 18:26 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-07-16 18:26 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-07-16 18:26 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-07-16 18:26 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-07-16 18:26 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-07-16 18:26 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-07-16 18:26 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-07-16 18:26 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-07-16 18:26 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-07-16 18:26 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-07-16 18:23 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-07-16 18:23 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2012-07-16 18:23 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-07-16 18:23 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-07-16 18:23 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
    2012-07-16 18:23 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2012-07-16 18:23 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2012-07-16 18:23 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
    2012-07-16 18:23 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2012-07-16 18:23 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2012-07-16 18:23 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2012-07-16 18:23 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2012-07-16 18:23 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2012-07-16 18:23 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2012-07-16 18:23 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2012-07-16 18:23 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2012-07-16 18:23 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2012-07-16 18:23 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
    2012-07-16 18:23 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll


    ============ 3 Months Modified Files ========================

    2012-08-09 17:54 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-08-09 17:54 - 2009-07-13 20:51 - 00071860 ____A C:\Windows\setupact.log
    2012-08-09 17:53 - 2012-01-08 10:25 - 01221550 ____A C:\Windows\WindowsUpdate.log
    2012-08-09 17:35 - 2009-07-13 20:45 - 00023872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-08-09 17:35 - 2009-07-13 20:45 - 00023872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-08-09 17:29 - 2012-08-09 17:29 - 00024552 ____A C:\ComboFix.txt
    2012-08-09 17:28 - 2010-11-20 19:47 - 00060904 ____A C:\Windows\PFRO.log
    2012-08-09 17:28 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini
    2012-08-09 17:10 - 2009-07-13 21:13 - 00726186 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-08-09 15:58 - 2012-07-27 14:01 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-08-09 13:57 - 2012-06-21 21:28 - 00283304 ____A C:\Windows\SysWOW64\PnkBstrB.xtr
    2012-08-09 13:57 - 2012-04-29 19:23 - 00283304 ____A C:\Windows\SysWOW64\PnkBstrB.exe
    2012-08-09 11:47 - 2012-04-29 19:23 - 00283304 ____A C:\Windows\SysWOW64\PnkBstrB.ex0
    2012-08-09 10:43 - 2009-07-13 20:45 - 00415336 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-08-09 09:44 - 2012-01-08 13:13 - 00108824 ____A C:\Users\Reggin\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-08-09 09:36 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
    2012-08-05 09:40 - 2012-08-05 09:40 - 00955888 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
    2012-08-05 09:40 - 2012-08-05 09:40 - 00268784 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
    2012-08-05 09:40 - 2012-08-05 09:40 - 00189424 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
    2012-08-05 09:40 - 2012-08-05 09:40 - 00188912 ____A (Oracle Corporation) C:\Windows\System32\java.exe
    2012-08-05 09:40 - 2012-04-09 17:53 - 00839152 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
    2012-08-02 20:58 - 2012-07-27 14:01 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-08-02 20:58 - 2012-07-27 14:01 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-08-02 14:37 - 2009-07-13 21:08 - 00032532 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2012-07-31 14:02 - 2012-07-19 14:34 - 00002573 ____A C:\Users\Public\Desktop\Six Updater.lnk
    2012-07-31 14:02 - 2012-07-19 14:34 - 00002573 ____A C:\Users\Public\Desktop\Six Launcher.lnk
    2012-07-28 19:55 - 2012-07-27 10:07 - 00001966 ____A C:\Users\Public\Desktop\avast! Free Antivirus.lnk
    2012-07-28 10:36 - 2012-07-28 10:36 - 00001583 ____A C:\Users\Public\Desktop\iTunes.lnk
    2012-07-28 10:11 - 2012-01-08 17:05 - 00001170 ____A C:\Users\Public\Desktop\Battlefield 3.lnk
    2012-07-28 09:57 - 2012-07-28 09:57 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
    2012-07-27 20:17 - 2012-01-08 13:56 - 00000979 ____A C:\Users\Public\Desktop\Origin.lnk
    2012-07-27 14:14 - 2012-07-27 14:14 - 00000810 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2012-07-27 10:09 - 2012-01-08 13:28 - 00000000 ____A C:\Windows\SysWOW64\config.nt
    2012-07-27 10:05 - 2012-06-22 12:43 - 00001945 ____A C:\Windows\epplauncher.mif
    2012-07-27 10:00 - 2012-07-27 10:00 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-07-27 09:23 - 2012-07-27 09:23 - 00000012 ____A C:\Windows\srun.log
    2012-07-19 14:42 - 2012-07-19 14:42 - 00001076 ____A C:\Users\Public\Desktop\DayZ Commander.lnk
    2012-07-19 14:32 - 2012-01-08 17:04 - 00064984 ____A C:\Windows\DirectX.log
    2012-07-16 18:28 - 2012-07-16 18:28 - 00261590 ____A C:\Windows\msxml4-KB2721691-enu.LOG
    2012-07-04 18:40 - 2012-07-04 18:40 - 00001073 ____A C:\Users\Public\Desktop\ASUS Sync.lnk
    2012-07-03 10:46 - 2012-07-27 10:00 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-07-03 08:21 - 2012-07-27 10:07 - 00958400 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
    2012-07-03 08:21 - 2012-07-27 10:07 - 00355856 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
    2012-07-03 08:21 - 2012-07-27 10:07 - 00227648 ____A (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe
    2012-07-03 08:21 - 2012-07-27 10:07 - 00071064 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
    2012-07-03 08:21 - 2012-07-27 10:07 - 00059728 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
    2012-07-03 08:21 - 2012-07-27 10:07 - 00054072 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
    2012-07-03 08:21 - 2012-07-27 10:07 - 00041224 ____A (AVAST Software) C:\Windows\avastSS.scr
    2012-07-03 08:21 - 2012-07-27 10:07 - 00025232 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
    2012-07-03 08:21 - 2012-01-08 13:28 - 00285328 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
    2012-07-03 00:19 - 2012-01-08 12:19 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-07-03 00:13 - 2012-07-27 10:39 - 57442464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe
    2012-06-25 13:04 - 2012-06-25 13:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
    2012-06-22 12:43 - 2012-06-22 12:43 - 00743454 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-06-11 19:08 - 2012-07-16 18:28 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-06-08 21:43 - 2012-07-16 18:23 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-06-08 20:41 - 2012-07-16 18:23 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2012-06-05 22:06 - 2012-07-16 18:23 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-06-05 22:06 - 2012-07-16 18:23 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-06-05 22:02 - 2012-07-16 18:23 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
    2012-06-05 21:05 - 2012-07-16 18:23 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2012-06-05 21:05 - 2012-07-16 18:23 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2012-06-05 21:03 - 2012-07-16 18:23 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
    2012-06-02 14:19 - 2012-06-20 18:07 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-02 14:19 - 2012-06-20 18:07 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-02 14:19 - 2012-06-20 18:07 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-02 14:19 - 2012-06-20 18:07 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-02 14:19 - 2012-06-20 18:07 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-02 14:15 - 2012-06-20 18:07 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-02 14:15 - 2012-06-20 18:07 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-02 12:19 - 2012-06-20 18:07 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-02 12:15 - 2012-06-20 18:07 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-02 04:49 - 2012-07-16 18:26 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-02 04:17 - 2012-07-16 18:26 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-02 04:12 - 2012-07-16 18:26 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-02 04:05 - 2012-07-16 18:26 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-02 04:05 - 2012-07-16 18:26 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-02 04:04 - 2012-07-16 18:26 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-02 04:04 - 2012-07-16 18:26 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-02 04:03 - 2012-07-16 18:26 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-02 04:01 - 2012-07-16 18:26 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-02 04:00 - 2012-07-16 18:26 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-02 03:59 - 2012-07-16 18:26 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-02 03:57 - 2012-07-16 18:26 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-02 03:57 - 2012-07-16 18:26 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-02 03:54 - 2012-07-16 18:26 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-02 01:07 - 2012-07-16 18:26 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-02 00:43 - 2012-07-16 18:26 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-02 00:33 - 2012-07-16 18:26 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-02 00:26 - 2012-07-16 18:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-02 00:25 - 2012-07-16 18:26 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-02 00:25 - 2012-07-16 18:26 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-02 00:23 - 2012-07-16 18:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-02 00:21 - 2012-07-16 18:26 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-02 00:20 - 2012-07-16 18:26 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-02 00:19 - 2012-07-16 18:26 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-02 00:19 - 2012-07-16 18:26 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-02 00:17 - 2012-07-16 18:26 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-02 00:16 - 2012-07-16 18:26 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-02 00:14 - 2012-07-16 18:26 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-01 21:50 - 2012-07-16 18:23 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2012-06-01 21:48 - 2012-07-16 18:23 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2012-06-01 21:48 - 2012-07-16 18:23 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2012-06-01 21:45 - 2012-07-16 18:23 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2012-06-01 21:44 - 2012-07-16 18:23 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2012-06-01 20:40 - 2012-07-16 18:23 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2012-06-01 20:40 - 2012-07-16 18:23 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2012-06-01 20:39 - 2012-07-16 18:23 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2012-06-01 20:34 - 2012-07-16 18:23 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
    2012-05-15 02:48 - 2012-07-28 10:30 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
    2012-05-15 02:48 - 2012-07-28 10:30 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2012-05-15 02:48 - 2012-02-24 00:54 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
    2012-05-15 02:48 - 2012-02-24 00:54 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
    2012-05-15 02:48 - 2012-02-24 00:54 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
    2012-05-15 02:48 - 2012-02-24 00:54 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
    2012-05-15 02:48 - 2012-02-24 00:54 - 00949056 ____A (NVIDIA Corporation) C:\Windows\System32\nvumdshimx.dll
    2012-05-15 02:48 - 2012-02-24 00:54 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
    2012-05-15 02:48 - 2012-02-24 00:54 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2012-05-15 02:48 - 2012-02-24 00:54 - 00014324 ____A C:\Windows\System32\nvinfo.pb
    2012-05-15 01:29 - 2012-07-28 10:26 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
    2012-05-15 01:29 - 2012-07-28 10:26 - 02621723 ____A C:\Windows\System32\nvcoproc.bin
    2012-05-15 01:29 - 2012-07-28 10:26 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    2012-05-15 01:29 - 2012-07-28 10:26 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
    2012-05-15 01:29 - 2012-07-28 10:26 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
    2012-05-15 01:28 - 2012-07-28 10:26 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll


    ZeroAccess:
    C:\Users\Reggin\AppData\Local\{af70a4e2-dbb6-273b-1caf-d4176d30b398}
    C:\Users\Reggin\AppData\Local\{af70a4e2-dbb6-273b-1caf-d4176d30b398}\@
    C:\Users\Reggin\AppData\Local\{af70a4e2-dbb6-273b-1caf-d4176d30b398}\L
    C:\Users\Reggin\AppData\Local\{af70a4e2-dbb6-273b-1caf-d4176d30b398}\U

    ========================= Known DLLs (Whitelisted) ============


    ========================= Bamital & volsnap Check ============

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ========================= Memory info ======================

    Percentage of memory in use: 7%
    Total physical RAM: 16381.53 MB
    Available physical RAM: 15203.7 MB
    Total Pagefile: 16379.73 MB
    Available Pagefile: 15225.5 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.89 MB

    ======================= Partitions =========================

    2 Drive c: () (Fixed) (Total:111.69 GB) (Free:25.46 GB) NTFS
    3 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    7 Drive I: () (Removable) (Total:3.74 GB) (Free:2.5 GB) FAT32
    8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    9 Drive y: (Western Digital) (Fixed) (Total:465.76 GB) (Free:395.26 GB) NTFS

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 465 GB 1024 KB
    Disk 1 Online 111 GB 0 B
    Disk 2 Online 465 GB 0 B
    Disk 3 Online 3835 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 465 GB 1024 KB

    ==================================================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 Y Western Dig NTFS Partition 465 GB Healthy

    ==================================================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 100 MB 1024 KB
    Partition 2 Primary 111 GB 101 MB

    ==================================================================================

    Disk: 1
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 D System Rese NTFS Partition 100 MB Healthy

    ==================================================================================

    Disk: 1
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 C NTFS Partition 111 GB Healthy

    ==================================================================================

    Partitions of Disk 2:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 465 GB 31 KB

    ==================================================================================

    Disk: 2
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 5 E Partition 465 GB Healthy

    ==================================================================================

    Partitions of Disk 3:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 3827 MB 19 KB

    ==================================================================================

    Disk: 3
    Partition 1
    Type : 0B
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 6 I FAT32 Removable 3827 MB Healthy

    ==================================================================================

    Last Boot: 2012-07-28 11:47

    ======================= End Of Log ==========================
     
  19. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    Next...

    Restart normally and give me fresh Combofix file.
     

    Attached Files:

  20. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 09-08-2012
    Ran by SYSTEM at 2012-08-09 21:37:32 Run:1
    Running from I:\

    ==============================================

    HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows No ZeroAccess entry found.
    C:\Windows\System32\consrv.dll not found.
    C:\Users\Reggin\AppData\Local\{af70a4e2-dbb6-273b-1caf-d4176d30b398} moved successfully.

    ==== End of Fixlog ====
     
  21. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    ComboFix 12-08-09.01 - Reggin 08/09/2012 21:41:51.2.6 - x64
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16382.14772 [GMT -5:00]
    Running from: d:\users\Reggin\Desktop\ComboFix.exe
    AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-07-10 to 2012-08-10 )))))))))))))))))))))))))))))))
    .
    .
    2012-08-10 04:58 . 2012-08-10 04:58 -------- d-----w- C:\FRST
    2012-08-10 02:44 . 2012-08-10 02:44 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-08-09 17:34 . 2012-08-09 17:34 -------- d-----w- c:\program files\Common Files\DESIGNER
    2012-08-09 17:34 . 2012-08-09 17:34 -------- d-----w- c:\program files\Microsoft Synchronization Services
    2012-08-09 17:33 . 2012-08-09 17:33 -------- d-----w- c:\program files\Microsoft Sync Framework
    2012-08-09 17:33 . 2012-08-09 17:33 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
    2012-08-09 17:33 . 2012-08-09 17:33 -------- d-----w- c:\program files\Microsoft Analysis Services
    2012-08-09 17:24 . 2012-08-09 17:24 -------- d-----w- c:\users\Reggin\AppData\Local\ElevatedDiagnostics
    2012-08-09 17:24 . 2012-08-09 17:28 -------- d-----w- C:\MATS
    2012-08-05 17:40 . 2012-08-05 17:40 955888 ----a-w- c:\windows\system32\npDeployJava1.dll
    2012-08-05 17:40 . 2012-08-05 17:40 268784 ----a-w- c:\windows\system32\javaws.exe
    2012-08-05 17:40 . 2012-08-05 17:40 189424 ----a-w- c:\windows\system32\javaw.exe
    2012-08-05 17:40 . 2012-08-05 17:40 188912 ----a-w- c:\windows\system32\java.exe
    2012-08-05 17:40 . 2012-08-05 17:40 -------- d-----w- c:\program files\Java
    2012-08-04 19:55 . 2012-08-04 19:55 -------- d-----w- c:\programdata\McAfee
    2012-07-29 17:50 . 2012-07-29 18:29 -------- d-----w- c:\program files (x86)\Rosetta Stone
    2012-07-29 17:38 . 2012-07-29 17:38 -------- d-----w- c:\program files (x86)\Common Files\Macrovision Shared
    2012-07-29 17:38 . 2012-07-29 17:49 -------- d-----w- c:\programdata\Rosetta Stone
    2012-07-28 18:36 . 2012-07-28 18:36 -------- d-----w- c:\program files\iTunes
    2012-07-28 18:36 . 2012-07-28 18:36 -------- d-----w- c:\program files\iPod
    2012-07-28 18:26 . 2012-05-15 09:29 889664 ----a-w- c:\windows\system32\nvvsvc.exe
    2012-07-28 18:26 . 2012-05-15 09:29 63296 ----a-w- c:\windows\system32\nvshext.dll
    2012-07-28 18:26 . 2012-05-15 09:29 2621723 ----a-w- c:\windows\system32\nvcoproc.bin
    2012-07-28 18:26 . 2012-05-15 09:29 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
    2012-07-28 18:26 . 2012-05-15 09:28 6151488 ----a-w- c:\windows\system32\nvcpl.dll
    2012-07-28 18:26 . 2012-05-15 09:29 118080 ----a-w- c:\windows\system32\nvmctray.dll
    2012-07-28 18:26 . 2012-07-28 18:26 -------- d-----w- c:\programdata\NVIDIA Corporation
    2012-07-28 17:57 . 2012-07-28 17:57 -------- d-----w- c:\program files (x86)\Common Files\Adobe
    2012-07-27 22:14 . 2012-07-27 22:14 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
    2012-07-27 22:01 . 2012-08-03 04:58 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-07-27 22:01 . 2012-08-03 04:58 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2012-07-27 21:46 . 2012-08-09 17:37 -------- d-sh--w- c:\windows\Installer
    2012-07-27 18:38 . 2012-07-27 18:38 -------- d-----w- c:\windows\system32\appmgmt
    2012-07-27 18:07 . 2012-07-03 16:21 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2012-07-27 18:07 . 2012-07-03 16:21 958400 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2012-07-27 18:07 . 2012-07-03 16:21 71064 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2012-07-27 18:07 . 2012-07-03 16:21 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2012-07-27 18:07 . 2012-07-03 16:21 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
    2012-07-27 18:07 . 2012-07-03 16:21 355856 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2012-07-27 18:07 . 2012-07-03 16:21 41224 ----a-w- c:\windows\avastSS.scr
    2012-07-27 18:07 . 2012-07-03 16:21 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
    2012-07-27 18:00 . 2012-07-27 18:00 -------- d-----w- c:\users\Reggin\AppData\Roaming\Malwarebytes
    2012-07-27 18:00 . 2012-07-27 18:00 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-07-27 18:00 . 2012-07-27 18:00 -------- d-----w- c:\programdata\Malwarebytes
    2012-07-27 18:00 . 2012-07-03 18:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-07-27 17:29 . 2012-07-27 17:29 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
    2012-07-27 17:24 . 2012-07-27 17:24 -------- d-----w- c:\users\Reggin\AppData\Local\{DB217A9F-D80F-11E1-8270-B8AC6F996F26}
    2012-07-19 23:29 . 2012-07-19 23:29 -------- d-----w- c:\users\Reggin\AppData\Local\SIX_Projects
    2012-07-19 22:56 . 2012-07-19 22:56 -------- d-----w- c:\users\Reggin\AppData\Roaming\gslist
    2012-07-19 22:56 . 2012-07-19 22:56 -------- d-----w- c:\users\Reggin\AppData\Local\DayZCommander
    2012-07-19 22:37 . 2012-07-19 23:32 -------- d-----w- c:\users\Reggin\AppData\Roaming\six-updater
    2012-07-19 22:37 . 2012-07-19 22:37 -------- d-----w- c:\users\Reggin\AppData\Roaming\six-zsync
    2012-07-19 22:36 . 2012-07-19 22:36 -------- d-----w- c:\users\Reggin\AppData\Local\ArmA 2
    2012-07-19 06:10 . 2012-08-03 20:23 -------- d-----w- c:\users\Reggin\AppData\Local\ArmA 2 OA
    2012-07-17 02:28 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
    2012-07-17 02:23 . 2012-06-09 05:43 14172672 ----a-w- c:\windows\system32\shell32.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-08-09 21:57 . 2012-06-22 05:28 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
    2012-08-09 21:57 . 2012-04-30 03:23 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
    2012-08-09 19:47 . 2012-04-30 03:23 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
    2012-08-05 17:40 . 2012-04-10 01:53 839152 ----a-w- c:\windows\system32\deployJava1.dll
    2012-07-03 16:21 . 2012-01-08 21:28 285328 ----a-w- c:\windows\system32\aswBoot.exe
    2012-07-03 08:19 . 2012-01-08 20:19 59701280 ----a-w- c:\windows\system32\MRT.exe
    2012-06-25 21:04 . 2012-06-25 21:04 1394248 ----a-w- c:\windows\SysWow64\msxml4.dll
    2012-06-02 22:19 . 2012-06-21 02:07 38424 ----a-w- c:\windows\system32\wups.dll
    2012-06-02 22:19 . 2012-06-21 02:07 2428952 ----a-w- c:\windows\system32\wuaueng.dll
    2012-06-02 22:19 . 2012-06-21 02:07 57880 ----a-w- c:\windows\system32\wuauclt.exe
    2012-06-02 22:19 . 2012-06-21 02:07 44056 ----a-w- c:\windows\system32\wups2.dll
    2012-06-02 22:19 . 2012-06-21 02:07 701976 ----a-w- c:\windows\system32\wuapi.dll
    2012-06-02 22:15 . 2012-06-21 02:07 2622464 ----a-w- c:\windows\system32\wucltux.dll
    2012-06-02 22:15 . 2012-06-21 02:07 99840 ----a-w- c:\windows\system32\wudriver.dll
    2012-06-02 20:19 . 2012-06-21 02:07 186752 ----a-w- c:\windows\system32\wuwebv.dll
    2012-06-02 20:15 . 2012-06-21 02:07 36864 ----a-w- c:\windows\system32\wuapp.exe
    2012-05-31 04:04 . 2012-06-22 03:47 9013136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{19B2C92D-36EA-4CA9-A3E7-8268BD5B346E}\mpengine.dll
    2012-05-15 10:48 . 2012-02-24 08:54 949056 ----a-w- c:\windows\system32\nvumdshimx.dll
    2012-05-15 10:48 . 2012-02-24 08:54 68928 ----a-w- c:\windows\system32\OpenCL.dll
    2012-05-15 10:48 . 2012-02-24 08:54 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
    2012-05-15 10:48 . 2012-02-24 08:54 2741568 ----a-w- c:\windows\system32\nvapi64.dll
    2012-05-15 10:48 . 2012-02-24 08:54 25743168 ----a-w- c:\windows\system32\nvoglv64.dll
    2012-05-15 10:48 . 2012-02-24 08:54 1738048 ----a-w- c:\windows\system32\nvdispco64.dll
    2012-05-15 10:48 . 2012-02-24 08:54 1468224 ----a-w- c:\windows\system32\nvgenco64.dll
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2012-08-10_01.28.32 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2009-07-14 04:54 . 2012-08-10 01:28 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-07-14 04:54 . 2012-08-10 02:45 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-07-14 04:54 . 2012-08-10 01:28 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-07-14 04:54 . 2012-08-10 02:45 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2010-11-21 03:09 . 2012-08-10 02:40 32960 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 05:10 . 2012-08-10 02:40 41626 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2012-01-08 18:25 . 2012-08-10 02:40 5994 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2750489456-2038736500-569727775-1000_UserData.bin
    - 2012-08-10 01:28 . 2012-08-10 01:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2012-08-10 02:45 . 2012-08-10 02:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2009-07-14 04:54 . 2012-08-10 02:45 589824 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-07-14 04:54 . 2012-08-10 01:28 589824 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-07-14 02:36 . 2012-08-10 01:10 624126 c:\windows\system32\perfh009.dat
    + 2009-07-14 02:36 . 2012-08-10 02:11 624126 c:\windows\system32\perfh009.dat
    + 2009-07-14 02:36 . 2012-08-10 02:11 106502 c:\windows\system32\perfc009.dat
    - 2009-07-14 02:36 . 2012-08-10 01:10 106502 c:\windows\system32\perfc009.dat
    - 2009-07-14 05:01 . 2012-08-10 01:27 384992 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2009-07-14 05:01 . 2012-08-10 02:44 384992 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2012-01-08 21:02 . 2012-08-10 02:44 4218656 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2750489456-2038736500-569727775-1000-12288.dat
    - 2012-01-08 21:02 . 2012-08-10 01:27 4218656 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2750489456-2038736500-569727775-1000-12288.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files (x86)\Steam\steam.exe" [2012-08-04 1353080]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
    "ASUS Sync Loader"="c:\program files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe" [2012-06-15 638976]
    "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
    "iTunesHelper"="d:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-08 421776]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-03 250056]
    R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
    R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-12-28 51727736]
    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120]
    R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
    R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2011-10-04 80000]
    S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2011-10-04 40576]
    S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2011-01-11 21104]
    S1 aswSnx;aswSnx; [x]
    S1 aswSP;aswSP; [x]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
    S2 aswFsBlk;aswFsBlk; [x]
    S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-07-03 71064]
    S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2012-01-09 22408]
    S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2012-01-09 16008]
    S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-20 75776]
    S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-20 177152]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-11-09 187200]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-01-13 413800]
    S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2011-08-17 53376]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-08-09 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-27 04:58]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2012-07-03 16:21 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-09-29 110360]
    "Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
    TCP: DhcpNameServer = 192.168.1.254
    FF - ProfilePath - c:\users\Reggin\AppData\Roaming\Mozilla\Firefox\Profiles\n9jdz56u.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
    "value"="?\01\01\09\01\02\04¯"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    @Denied: (A) (Everyone)
    "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    @Denied: (A) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    "Key"="ActionsPane3"
    "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\AVAST Software\Avast\AvastSvc.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\windows\SysWOW64\PnkBstrA.exe
    .
    **************************************************************************
    .
    Completion time: 2012-08-09 21:46:59 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-08-10 02:46
    ComboFix2.txt 2012-08-10 01:29
    .
    Pre-Run: 27,286,061,056 bytes free
    Post-Run: 26,959,888,384 bytes free
    .
    - - End Of File - - AA5CD7381565EDE94EA24B2136360510
     
  22. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Looks good :)

    Any current issues?

    =============================

    Download Malwarebytes' Anti-Malware (MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop.
    NOTE. If you already have MBAM installed, update it before running the scan.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform quick scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    Be sure to restart the computer IF MBAM asks you to do so.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    =============================

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  23. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.08.10.01

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Reggin :: REGGIN-PC [administrator]

    8/9/2012 9:51:32 PM
    mbam-log-2012-08-09 (21-51-32).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 193666
    Time elapsed: 39 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  24. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    OTL logfile created on: 8/9/2012 9:54:13 PM - Run 1
    OTL by OldTimer - Version 3.2.56.0 Folder = D:\Users\Reggin\Desktop
    64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    16.00 Gb Total Physical Memory | 14.17 Gb Available Physical Memory | 88.58% Memory free
    16.00 Gb Paging File | 14.06 Gb Available in Paging File | 87.89% Paging File free
    Paging file location(s): [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 111.69 Gb Total Space | 25.17 Gb Free Space | 22.54% Space Free | Partition Type: NTFS
    Drive D: | 465.76 Gb Total Space | 395.26 Gb Free Space | 84.86% Space Free | Partition Type: NTFS
    Drive E: | 465.76 Gb Total Space | 257.63 Gb Free Space | 55.31% Space Free | Partition Type: NTFS
    Drive H: | 3.74 Gb Total Space | 2.50 Gb Free Space | 66.89% Space Free | Partition Type: FAT32

    Computer Name: REGGIN-PC | User Name: Reggin | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/08/09 21:52:22 | 000,596,480 | ---- | M] (OldTimer Tools) -- D:\Users\Reggin\Desktop\OTL.exe
    PRC - [2012/08/04 10:23:26 | 001,353,080 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe
    PRC - [2012/07/03 11:21:30 | 004,273,976 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
    PRC - [2012/07/03 11:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    PRC - [2012/06/15 11:01:00 | 000,638,976 | ---- | M] (Futuredial Inc.) -- C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe
    PRC - [2012/04/29 22:23:50 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
    PRC - [2012/04/04 00:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2009/11/20 06:17:54 | 000,106,496 | ---- | M] (NEC Electronics Corporation) -- C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/08/05 12:34:44 | 020,316,496 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll
    MOD - [2012/08/05 12:34:43 | 001,099,576 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-53.dll
    MOD - [2012/08/05 12:34:43 | 000,900,944 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.dll
    MOD - [2012/08/05 12:34:43 | 000,190,776 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-53.dll
    MOD - [2012/08/05 12:34:43 | 000,123,192 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-51.dll
    MOD - [2012/06/15 11:01:00 | 000,559,244 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Sync\sqlite3.7.dll
    MOD - [2012/06/15 11:01:00 | 000,516,599 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Sync\sqlite3.dll
    MOD - [2012/06/15 11:01:00 | 000,352,256 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Sync\asusDetect.dll
    MOD - [2012/06/15 11:01:00 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Sync\asusDetectLegend.dll
    MOD - [2012/06/15 11:01:00 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Sync\asusDisk.dll
    MOD - [2012/06/15 11:01:00 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Sync\fdHttpd.dll
    MOD - [2011/09/27 08:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/09/27 08:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll


    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2012/07/03 11:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
    SRV:64bit: - [2010/04/06 17:30:38 | 000,031,272 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\AppleChargerSrv.exe -- (AppleChargerSrv)
    SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
    SRV - [2012/08/02 23:58:12 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/07/29 12:38:23 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2012/07/27 13:17:53 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
    SRV - [2012/07/13 19:17:12 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2012/04/29 22:23:50 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
    SRV - [2012/04/04 00:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/07/03 11:21:52 | 000,958,400 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
    DRV:64bit: - [2012/07/03 11:21:52 | 000,355,856 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
    DRV:64bit: - [2012/07/03 11:21:52 | 000,071,064 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
    DRV:64bit: - [2012/07/03 11:21:52 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
    DRV:64bit: - [2012/07/03 11:21:52 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
    DRV:64bit: - [2012/07/03 11:21:51 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
    DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/02/15 12:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2012/01/08 20:13:21 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
    DRV:64bit: - [2012/01/08 20:13:21 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
    DRV:64bit: - [2011/11/09 09:21:39 | 000,187,200 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
    DRV:64bit: - [2011/10/04 16:29:28 | 000,040,576 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
    DRV:64bit: - [2011/10/04 16:29:26 | 000,080,000 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
    DRV:64bit: - [2011/08/17 16:44:46 | 000,053,376 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
    DRV:64bit: - [2011/01/13 06:58:30 | 000,413,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
    DRV:64bit: - [2011/01/10 19:16:08 | 000,021,104 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AppleCharger.sys -- (AppleCharger)
    DRV:64bit: - [2010/11/20 22:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
    DRV:64bit: - [2010/11/20 22:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
    DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/20 22:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
    DRV:64bit: - [2010/04/27 17:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
    DRV:64bit: - [2010/04/27 17:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
    DRV:64bit: - [2010/04/27 15:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
    DRV:64bit: - [2010/04/27 15:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
    DRV:64bit: - [2009/11/20 06:16:02 | 000,177,152 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
    DRV:64bit: - [2009/11/20 06:15:58 | 000,075,776 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
    DRV:64bit: - [2009/10/07 05:13:34 | 000,070,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2009/10/07 05:13:34 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2009/07/26 21:54:30 | 000,090,544 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
    DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/05/04 20:00:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie)
    DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-2750489456-2038736500-569727775-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
    IE - HKU\S-1-5-21-2750489456-2038736500-569727775-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9D FB 62 59 4A CE CC 01 [binary data]
    IE - HKU\S-1-5-21-2750489456-2038736500-569727775-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKU\S-1-5-21-2750489456-2038736500-569727775-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-2750489456-2038736500-569727775-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-2750489456-2038736500-569727775-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
    FF - user.js - File not found

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_270.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
    FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.116.0: C:\Program Files (x86)\Battlelog Web Plugins\1.116.0\npesnlaunch.dll File not found
    FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/07/27 13:07:37 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: D:\Program Files (x86)\Mozilla Firefox\components [2012/07/27 17:14:24 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: D:\Program Files (x86)\Mozilla Firefox\plugins
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: D:\Program Files (x86)\Mozilla Firefox\components [2012/07/27 17:14:24 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: D:\Program Files (x86)\Mozilla Firefox\plugins
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{DB217A9F-D80F-11E1-8270-B8AC6F996F26}: C:\Users\Reggin\AppData\Local\{DB217A9F-D80F-11E1-8270-B8AC6F996F26}\ [2012/07/27 12:24:09 | 000,000,000 | ---D | M]

    [2012/07/27 17:14:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Reggin\AppData\Roaming\Mozilla\Extensions

    ========== Chrome ==========

    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - homepage: http://www.google.com
    CHR - Extension: YouTube = C:\Users\Reggin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
    CHR - Extension: Google Search = C:\Users\Reggin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
    CHR - Extension: avast! WebRep = C:\Users\Reggin\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1367_0\
    CHR - Extension: Gmail = C:\Users\Reggin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\

    O1 HOSTS File: ([2012/08/09 21:45:45 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
    O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
    O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
    O4:64bit: - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [ASUS Sync Loader] C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe (Futuredial Inc.)
    O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
    O4 - HKU\S-1-5-21-2750489456-2038736500-569727775-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2750489456-2038736500-569727775-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2750489456-2038736500-569727775-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-2750489456-2038736500-569727775-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
    O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BA9BFBC8-4B24-41AC-8E49-FD11A10D1D95}: DhcpNameServer = 192.168.1.254
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll File not found
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2008/03/05 20:33:27 | 000,000,000 | ---- | M] () - E:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/08/09 23:58:34 | 000,000,000 | ---D | C] -- C:\FRST
    [2012/08/09 21:52:22 | 000,596,480 | ---- | C] (OldTimer Tools) -- D:\Users\Reggin\Desktop\OTL.exe
    [2012/08/09 21:44:50 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/08/09 20:24:00 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/08/09 20:24:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/08/09 20:24:00 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/08/09 20:23:57 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/08/09 20:23:52 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
    [2012/08/09 20:19:17 | 004,728,003 | R--- | C] (Swearware) -- D:\Users\Reggin\Desktop\ComboFix.exe
    [2012/08/09 18:29:11 | 001,118,624 | ---- | C] (Bleeping Computer, LLC) -- D:\Users\Reggin\Desktop\rkill.exe
    [2012/08/09 17:43:17 | 000,607,260 | R--- | C] (Swearware) -- D:\Users\Reggin\Desktop\dds.com
    [2012/08/09 14:20:36 | 000,000,000 | ---D | C] -- D:\Users\Reggin\Desktop\bootkit_remover
    [2012/08/09 14:16:34 | 004,731,392 | ---- | C] (AVAST Software) -- D:\Users\Reggin\Desktop\aswMBR.exe
    [2012/08/09 13:58:22 | 000,000,000 | ---D | C] -- D:\Users\Reggin\Desktop\RK_Quarantine
    [2012/08/09 12:38:08 | 000,000,000 | ---D | C] -- D:\Users\Reggin\Desktop\Resumes
    [2012/08/09 12:34:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
    [2012/08/09 12:34:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services
    [2012/08/09 12:33:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
    [2012/08/09 12:33:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
    [2012/08/09 12:33:22 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
    [2012/08/09 12:33:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
    [2012/08/09 12:24:41 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Local\ElevatedDiagnostics
    [2012/08/09 12:24:36 | 000,000,000 | ---D | C] -- C:\MATS
    [2012/08/05 12:40:12 | 000,000,000 | ---D | C] -- C:\Program Files\Java
    [2012/08/04 14:55:14 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
    [2012/07/29 12:54:51 | 000,000,000 | ---D | C] -- D:\Users\Reggin\Documents\RosettaStone Content
    [2012/07/29 12:50:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rosetta Stone
    [2012/07/29 12:38:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
    [2012/07/29 12:38:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Rosetta Stone
    [2012/07/28 13:36:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2012/07/28 13:36:09 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2012/07/28 13:36:09 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2012/07/28 13:26:08 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
    [2012/07/28 12:57:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
    [2012/07/28 12:57:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
    [2012/07/27 17:14:28 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Roaming\Mozilla
    [2012/07/27 17:14:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
    [2012/07/27 17:14:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
    [2012/07/27 16:46:29 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
    [2012/07/27 13:38:32 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
    [2012/07/27 13:38:28 | 000,000,000 | R--D | C] -- C:\Users\Reggin\Documents
    [2012/07/27 13:07:42 | 000,025,232 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
    [2012/07/27 13:07:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
    [2012/07/27 13:07:41 | 000,958,400 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
    [2012/07/27 13:07:41 | 000,355,856 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
    [2012/07/27 13:07:41 | 000,071,064 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
    [2012/07/27 13:07:41 | 000,059,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
    [2012/07/27 13:07:41 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
    [2012/07/27 13:07:28 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
    [2012/07/27 13:07:28 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
    [2012/07/27 13:00:40 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Roaming\Malwarebytes
    [2012/07/27 13:00:29 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/07/27 13:00:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/07/27 13:00:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/07/27 13:00:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2012/07/27 12:29:22 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
    [2012/07/27 12:24:09 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Local\{DB217A9F-D80F-11E1-8270-B8AC6F996F26}
    [2012/07/19 18:29:18 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Local\SIX_Projects
    [2012/07/19 17:56:54 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Roaming\gslist
    [2012/07/19 17:56:54 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Local\DayZCommander
    [2012/07/19 17:47:57 | 000,000,000 | ---D | C] -- D:\Users\Reggin\Documents\ArmA 2 Other Profiles
    [2012/07/19 17:37:08 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Roaming\six-updater
    [2012/07/19 17:37:07 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Roaming\six-zsync
    [2012/07/19 17:36:33 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Local\ArmA 2
    [2012/07/19 17:34:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Six Projects
    [2012/07/19 01:10:12 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Local\ArmA 2 OA
    [2012/07/19 01:10:12 | 000,000,000 | ---D | C] -- D:\Users\Reggin\Documents\ArmA 2
    [2012/07/19 01:10:10 | 000,000,000 | ---D | C] -- C:\Users\Reggin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    [2012/07/19 01:10:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive

    ========== Files - Modified Within 30 Days ==========

    [2012/08/09 21:52:42 | 000,023,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/08/09 21:52:42 | 000,023,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/08/09 21:52:22 | 000,596,480 | ---- | M] (OldTimer Tools) -- D:\Users\Reggin\Desktop\OTL.exe
    [2012/08/09 21:45:45 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/08/09 21:45:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/08/09 21:45:36 | 4293,668,863 | -HS- | M] () -- C:\hiberfil.sys
    [2012/08/09 21:11:09 | 000,726,186 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/08/09 21:11:09 | 000,624,126 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/08/09 21:11:09 | 000,106,502 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/08/09 20:19:21 | 004,728,003 | R--- | M] (Swearware) -- D:\Users\Reggin\Desktop\ComboFix.exe
    [2012/08/09 18:58:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/08/09 18:36:42 | 000,000,512 | ---- | M] () -- D:\Users\Reggin\Desktop\MBR.dat
    [2012/08/09 18:29:11 | 001,118,624 | ---- | M] (Bleeping Computer, LLC) -- D:\Users\Reggin\Desktop\rkill.exe
    [2012/08/09 17:43:18 | 000,607,260 | R--- | M] (Swearware) -- D:\Users\Reggin\Desktop\dds.com
    [2012/08/09 17:38:16 | 000,302,592 | ---- | M] () -- D:\Users\Reggin\Desktop\lf326uoe.exe
    [2012/08/09 16:57:50 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
    [2012/08/09 16:57:50 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
    [2012/08/09 14:47:40 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
    [2012/08/09 14:20:07 | 000,044,607 | ---- | M] () -- D:\Users\Reggin\Desktop\bootkit_remover.zip
    [2012/08/09 14:17:04 | 004,731,392 | ---- | M] (AVAST Software) -- D:\Users\Reggin\Desktop\aswMBR.exe
    [2012/08/09 13:43:42 | 000,415,336 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2012/08/03 14:03:11 | 000,001,736 | ---- | M] () -- D:\Users\Reggin\Desktop\RosettaStoneVersion3.exe - Shortcut.lnk
    [2012/07/31 17:02:35 | 000,002,573 | ---- | M] () -- C:\Users\Public\Desktop\Six Updater.lnk
    [2012/07/31 17:02:35 | 000,002,573 | ---- | M] () -- C:\Users\Public\Desktop\Six Launcher.lnk
    [2012/07/28 22:55:23 | 000,001,966 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
    [2012/07/28 13:36:20 | 000,001,583 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2012/07/28 13:11:30 | 000,001,170 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
    [2012/07/28 12:57:17 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
    [2012/07/27 23:17:05 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
    [2012/07/27 23:15:44 | 000,000,735 | ---- | M] () -- D:\Users\Reggin\Desktop\Ventrilo.lnk
    [2012/07/27 17:14:26 | 000,000,810 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
    [2012/07/27 16:09:15 | 000,000,189 | ---- | M] () -- D:\Users\Reggin\Desktop\register.bat
    [2012/07/27 13:09:23 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
    [2012/07/27 13:05:19 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
    [2012/07/27 13:00:29 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/07/19 17:42:36 | 000,001,076 | ---- | M] () -- C:\Users\Public\Desktop\DayZ Commander.lnk
    [2012/07/17 19:53:33 | 000,061,639 | ---- | M] () -- D:\Users\Reggin\Desktop\impbanner.png

    ========== Files Created - No Company Name ==========

    [2012/08/09 20:24:00 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/08/09 20:24:00 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/08/09 20:24:00 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/08/09 20:24:00 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/08/09 20:24:00 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/08/09 17:38:16 | 000,302,592 | ---- | C] () -- D:\Users\Reggin\Desktop\lf326uoe.exe
    [2012/08/09 14:20:06 | 000,044,607 | ---- | C] () -- D:\Users\Reggin\Desktop\bootkit_remover.zip
    [2012/08/09 14:19:40 | 000,000,512 | ---- | C] () -- D:\Users\Reggin\Desktop\MBR.dat
    [2012/08/03 14:03:13 | 000,001,736 | ---- | C] () -- D:\Users\Reggin\Desktop\RosettaStoneVersion3.exe - Shortcut.lnk
    [2012/07/28 13:36:20 | 000,001,583 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2012/07/28 13:26:20 | 002,621,723 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
    [2012/07/28 12:57:17 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
    [2012/07/28 12:57:17 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
    [2012/07/27 17:14:26 | 000,000,810 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
    [2012/07/27 17:14:26 | 000,000,810 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    [2012/07/27 17:01:24 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/07/27 16:09:15 | 000,000,189 | ---- | C] () -- D:\Users\Reggin\Desktop\register.bat
    [2012/07/27 13:07:42 | 000,001,966 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
    [2012/07/27 13:00:29 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/07/19 17:42:36 | 000,001,076 | ---- | C] () -- C:\Users\Public\Desktop\DayZ Commander.lnk
    [2012/07/19 17:34:11 | 000,002,573 | ---- | C] () -- C:\Users\Public\Desktop\Six Updater.lnk
    [2012/07/19 17:34:11 | 000,002,573 | ---- | C] () -- C:\Users\Public\Desktop\Six Launcher.lnk
    [2012/07/17 19:53:32 | 000,061,639 | ---- | C] () -- D:\Users\Reggin\Desktop\impbanner.png
    [2012/06/22 15:43:42 | 000,743,454 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/04/29 22:23:59 | 000,283,304 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
    [2012/04/29 22:23:50 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
    [2012/02/29 13:26:56 | 000,416,064 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
    [2012/02/05 23:47:21 | 000,000,262 | ---- | C] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
    [2012/01/08 14:05:36 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini

    ========== LOP Check ==========

    [2012/08/01 21:03:05 | 000,000,000 | ---D | M] -- C:\Users\Reggin\AppData\Roaming\.minecraft
    [2012/01/09 01:48:47 | 000,000,000 | ---D | M] -- C:\Users\Reggin\AppData\Roaming\ASUS
    [2012/01/09 01:49:19 | 000,000,000 | ---D | M] -- C:\Users\Reggin\AppData\Roaming\ASUS.AF361EFD06694D11175EA8BF6E21597A36AD9F1D.1
    [2012/08/09 12:07:29 | 000,000,000 | ---D | M] -- C:\Users\Reggin\AppData\Roaming\Azureus
    [2012/07/19 17:56:55 | 000,000,000 | ---D | M] -- C:\Users\Reggin\AppData\Roaming\gslist
    [2012/08/08 20:23:46 | 000,000,000 | ---D | M] -- C:\Users\Reggin\AppData\Roaming\Origin
    [2012/02/27 20:37:16 | 000,000,000 | ---D | M] -- C:\Users\Reggin\AppData\Roaming\Outlook
    [2012/07/19 18:32:39 | 000,000,000 | ---D | M] -- C:\Users\Reggin\AppData\Roaming\six-updater
    [2012/07/19 17:37:07 | 000,000,000 | ---D | M] -- C:\Users\Reggin\AppData\Roaming\six-zsync
    [2012/08/02 17:37:46 | 000,032,532 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    < End of report >
     
  25. Housez71

    Housez71 TS Rookie Topic Starter Posts: 28

    OTL Extras logfile created on: 8/9/2012 9:54:13 PM - Run 1
    OTL by OldTimer - Version 3.2.56.0 Folder = D:\Users\Reggin\Desktop
    64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    16.00 Gb Total Physical Memory | 14.17 Gb Available Physical Memory | 88.58% Memory free
    16.00 Gb Paging File | 14.06 Gb Available in Paging File | 87.89% Paging File free
    Paging file location(s): [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 111.69 Gb Total Space | 25.17 Gb Free Space | 22.54% Space Free | Partition Type: NTFS
    Drive D: | 465.76 Gb Total Space | 395.26 Gb Free Space | 84.86% Space Free | Partition Type: NTFS
    Drive E: | 465.76 Gb Total Space | 257.63 Gb Free Space | 55.31% Space Free | Partition Type: NTFS
    Drive H: | 3.74 Gb Total Space | 2.50 Gb Free Space | 66.89% Space Free | Partition Type: FAT32

    Computer Name: REGGIN-PC | User Name: Reggin | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .html [@ = htmlfile] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
    .html [@ = htmlfile] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome

    [HKEY_USERS\S-1-5-21-2750489456-2038736500-569727775-1000\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- D:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
    htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
    https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
    htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
    http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
    https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |
    "{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |
    "{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |
    "{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
    "{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |
    "{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |
    "{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |
    "{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |
    "{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |
    "{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |
    "{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "TCP Query User{61C66C1B-EC29-4DBC-BE4F-96CD7B983459}C:\program files (x86)\asus\asus sync\asusupctloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\asus\asus sync\asusupctloader.exe |
    "UDP Query User{402DC5C6-EF5D-4811-A49F-0DD61911A3F5}C:\program files (x86)\asus\asus sync\asusupctloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\asus\asus sync\asusupctloader.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{1444D2EE-C7AD-44A8-844F-2634B49353D1}" = Logitech Gaming Software 5.10
    "{2664F434-0AFE-1084-136E-FCC87BDF43AD}" = AMD Catalyst Install Manager
    "{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java(TM) 7 Update 5 (64-bit)
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software 8.12
    "{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
    "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
    "{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
    "{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
    "{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
    "{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
    "{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
    "{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
    "{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
    "{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
    "{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
    "{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUS_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
    "{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
    "{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUS_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
    "{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
    "{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUS_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
    "{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
    "{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
    "{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
    "{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
    "{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
    "{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
    "{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 301.42
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 301.42
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0213
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{D3A8B9D5-EEE5-4F2A-9EDE-7EC3AADDA5D4}" = ASUS Android USB Drivers
    "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
    "{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Office14.PROPLUS" = Microsoft Office Professional Plus 2010
    "TeamSpeak 3 Client" = TeamSpeak 3 Client

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{020C4F3D-DCEA-4E4F-9921-CCE666B2C0CD}" = DayZ Commander
    "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
    "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
    "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
    "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
    "{2D8CED57-CCDB-4D86-9087-3BBCAE8F8F22}" = Six Updater
    "{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B11.0110.1
    "{3EE1008C-11A1-4F4F-8DB7-27573924DE78}" = DMIView B8.0717.01
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{6C2CB5E8-B928-4954-BEBB-A7C973ACC73C}" = ASUS Sync
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
    "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
    "{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
    "{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
    "{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
    "{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
    "{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
    "{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
    "{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
    "{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
    "{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
    "{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
    "{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
    "{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
    "{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
    "{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
    "{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{987B04C4-B5AC-4AD6-A7E9-8D681085B850}" = AMD USB Filter Driver
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
    "{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @Bios
    "{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
    "{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
    "8461-7759-5462-8226" = Vuze
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "avast" = avast! Free Antivirus
    "Battlelog Web Plugins" = Battlelog Web Plugins
    "BattlEye for A2" = BattlEye Uninstall
    "BattlEye for OA" = BattlEye for OA Uninstall
    "ESN Sonar-0.70.4" = ESN Sonar
    "InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
    "Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service
    "Natural Selection_is1" = Natural Selection 3.2
    "Origin" = Origin
    "PowerISO" = PowerISO
    "Steam App 33900" = ARMA 2
    "Steam App 33930" = ARMA 2: Operation Arrowhead
    "Steam App 65800" = Dungeon Defenders
    "Steam App 70" = Half-Life
    "WinAce Archiver" = WinAce Archiver

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 8/9/2012 1:24:22 PM | Computer Name = Reggin-PC | Source = VSS | ID = 8194
    Description =

    Error - 8/9/2012 1:32:51 PM | Computer Name = Reggin-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 8/9/2012 1:35:15 PM | Computer Name = Reggin-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 8/9/2012 2:45:27 PM | Computer Name = Reggin-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 8/9/2012 7:31:23 PM | Computer Name = Reggin-PC | Source = Application Error | ID = 1000
    Description = Faulting application name: rkill64.exe, version: 2.1.0.0, time stamp:
    0x501c066c Faulting module name: rkill64.exe, version: 2.1.0.0, time stamp: 0x501c066c
    Exception
    code: 0xc0000417 Fault offset: 0x0000000000031e88 Faulting process id: 0x1608 Faulting
    application start time: 0x01cd768714de8220 Faulting application path: D:\Users\Reggin\Desktop\rkill64.exe
    Faulting
    module path: D:\Users\Reggin\Desktop\rkill64.exe Report Id: 54436b93-e27a-11e1-a089-1c6f65d5f3ea

    Error - 8/9/2012 9:05:44 PM | Computer Name = Reggin-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 8/9/2012 9:30:09 PM | Computer Name = Reggin-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 8/9/2012 10:06:01 PM | Computer Name = Reggin-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 8/9/2012 10:40:20 PM | Computer Name = Reggin-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 8/9/2012 10:47:27 PM | Computer Name = Reggin-PC | Source = WinMgmt | ID = 10
    Description =

    [ System Events ]
    Error - 8/9/2012 9:03:57 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7024
    Description = The Windows Firewall service terminated with service-specific error
    %%5.

    Error - 8/9/2012 9:03:57 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7023
    Description = The Windows Defender service terminated with the following error:
    %%126

    Error - 8/9/2012 9:04:05 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7023
    Description = The Function Discovery Resource Publication service terminated with
    the following error: %%-2147024891

    Error - 8/9/2012 9:04:05 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7001
    Description = The HomeGroup Provider service depends on the Function Discovery Resource
    Publication service which failed to start because of the following error: %%-2147024891

    Error - 8/9/2012 9:26:00 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/9/2012 9:27:35 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/9/2012 9:28:23 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7023
    Description = The Windows Defender service terminated with the following error:
    %%126

    Error - 8/9/2012 10:43:17 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/9/2012 10:44:52 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/9/2012 10:45:40 PM | Computer Name = Reggin-PC | Source = Service Control Manager | ID = 7023
    Description = The Windows Defender service terminated with the following error:
    %%126


    < End of report >
     

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...