I seem to have removed the Google redirect problem from my system by editing my Host file. I removed an extra line that reads ":: 1" and my redirect problem went away. But my CPU usage seems high when the computer is at rest and the cooling fan is always on which uses up battery life quickly. This is markedly different behavior for this computer than before I had the google redirect problem. I followed the 5 step instructions and here are my logs. I very much appreciate any help you can provide me. Thank you.
Malwarebytes log:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.11.06
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Evan :: NETBOOK [administrator]
1/11/2012 6:54:10 PM
mbam-log-2012-01-11 (18-54-10).txt
Scan type: Custom scan
Scan options enabled: File System | Heuristics/Shuriken | PUP | PUM
Scan options disabled: Memory | Startup | Registry | Heuristics/Extra | P2P
Objects scanned: 1
Time elapsed: 16 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
-------------------------------------
GMER log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-12 11:30:50
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 TOSHIBA_ rev.GJ00
Running: dl67e973.exe; Driver: C:\Users\Evan\AppData\Local\Temp\fxrdqpog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x8682CF68]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x8682D230]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x8682D52C]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x8682C9D8]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 81A47369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81A80D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11E3 81A87E98 4 Bytes [68, CF, 82, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11E8 81A87E9D 3 Bytes [D2, 82, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 121B 81A87ED0 4 Bytes [2C, D5, 82, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 166F 81A88324 4 Bytes [D8, C9, 82, 86]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\PCTSDInjDriver32 \Device\PCTSDInjDriver32 PCTSDInj32.sys
Device \Driver\ACPI_HAL \Device\0000004f halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB59561$\261678897 0 bytes
File C:\Windows\$NtUninstallKB59561$\261678897\cfg.ini 206 bytes
File C:\Windows\$NtUninstallKB59561$\261678897\U 0 bytes
File C:\Windows\$NtUninstallKB59561$\3897946129 0 bytes
---- EOF - GMER 1.0.15 ----
---------------------------------------------------
DDS log:
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Evan at 11:56:23 on 2012-01-12
Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.1013.169 [GMT -7:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe
C:\windows\system32\taskhost.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\windows\Explorer.EXE
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\igfxext.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://start.toshiba.com/g/
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [<NO NAME>]
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [HWSetup] c:\program files\toshiba\utilities\HWSetup.exe hwSetUP
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [RtHDVBg] c:\program files\realtek\audio\hda\RtHDVBg.exe /FORPCEE3
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TWebCamera] "c:\program files\toshiba\toshiba web camera application\TWebCamera.exe" autorun
mRun: [ToshibaAppPlace] "c:\program files\toshiba\toshiba app place\ToshibaAppPlace.exe"
mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TOBuActivation.exe" UNATTENDED
mRun: [TosVolRegulator] c:\program files\toshiba\tosvolregulator\TosVolRegulator.exe
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
TCP: DhcpNameServer = 75.75.75.75 75.75.75.75 75.75.76.76
TCP: Interfaces\{0E28DF56-F86F-418B-83B5-069A24F29196} : DhcpNameServer = 75.75.75.75 75.75.75.75 75.75.76.76
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2012-1-11 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2012-1-11 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2012-1-11 656320]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2010-10-20 821664]
R2 IconMan_R;IconMan_R;c:\program files\realtek\realtek usb 2.0 card reader\RIconMan.exe [2011-12-6 1809920]
R2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files\norton pc checkup\engine\2.0.6.22\SymcPCCULaunchSvc.exe [2011-12-6 115056]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\engine\2.0.6.22\ccSvcHst.exe [2011-12-6 126392]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2011-12-6 24064]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-6-10 394856]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\drivers\rtl8192ce.sys [2011-12-6 999016]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-9-14 577384]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-9-14 194408]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-9-14 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-9-14 19304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-4 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-11-4 136176]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2011-12-6 194664]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-12-19 52224]
.
=============== Created Last 30 ================
.
2012-01-12 17:16:44 0 ----a-w- c:\windows\system32\shoFC3A.tmp
2012-01-12 01:30:41 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{09dee56e-8103-47c7-b9b3-2c487f38b099}\offreg.dll
2012-01-12 01:04:49 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-12 01:04:49 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-12 01:04:49 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-12 01:04:48 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-12 01:04:48 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-12 01:04:48 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-12 01:04:47 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-12 01:04:47 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-12 01:04:46 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-12 01:04:46 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-12 00:24:23 28552 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
2012-01-12 00:24:23 28040 ----a-w- c:\windows\system32\mdimon.dll
2012-01-12 00:21:32 -------- d-----w- c:\program files\common files\L&H
2012-01-12 00:21:15 -------- d-----w- c:\program files\Microsoft ActiveSync
2012-01-12 00:20:26 -------- d-----w- c:\windows\SHELLNEW
2012-01-11 23:50:05 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-11 23:43:18 -------- d-----w- c:\program files\CCleaner
2012-01-11 23:38:41 23624 ----a-w- c:\windows\system32\drivers\hitmanpro36.sys
2012-01-11 23:38:10 -------- d-----w- c:\programdata\HitmanPro
2012-01-11 21:40:52 6823496 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{09dee56e-8103-47c7-b9b3-2c487f38b099}\mpengine.dll
2012-01-11 21:37:54 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2012-01-11 21:37:54 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2012-01-11 21:37:53 249616 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2012-01-11 21:37:53 102184 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2012-01-11 21:37:50 239168 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2012-01-11 21:37:50 160448 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2012-01-11 21:37:42 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2012-01-11 21:22:41 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 21:22:40 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 21:22:28 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 21:22:20 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 18:06:06 -------- d-----w- c:\users\evan\appdata\local\CrashDumps
2012-01-11 17:58:09 -------- d-----w- c:\users\evan\appdata\roaming\PC Tools
2012-01-11 17:58:09 -------- d-----w- c:\programdata\PC Tools
2012-01-11 17:58:09 -------- d-----w- c:\program files\PC Tools Security
2012-01-11 17:58:09 -------- d-----w- c:\program files\common files\PC Tools
2012-01-10 04:47:42 -------- d-----w- c:\users\evan\appdata\roaming\Malwarebytes
2012-01-10 04:47:23 -------- d-----w- c:\programdata\Malwarebytes
2012-01-10 04:47:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-05 16:07:44 -------- d-----w- c:\users\evan\appdata\local\Adobe
2011-12-30 15:43:59 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2011-12-30 15:40:07 -------- d-----w- c:\windows\system32\directx
2011-12-30 15:37:20 -------- d-----w- c:\program files\Media Player Classic - Home Cinema
2011-12-30 04:42:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-30 02:38:19 -------- d-----w- c:\windows\system32\SPReview
2011-12-30 02:13:12 -------- d-----w- c:\windows\system32\EventProviders
2011-12-21 06:07:28 0 ----a-w- c:\windows\system32\sho967A.tmp
2011-12-21 01:17:04 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-12-21 01:17:03 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-12-21 01:17:02 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-12-21 01:04:00 0 ----a-w- c:\windows\system32\sho1F2C.tmp
2011-12-19 14:43:58 1019904 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-12-19 14:42:59 854016 ----a-w- c:\windows\system32\dbghelp.dll
2011-12-19 14:41:59 352768 ----a-w- c:\windows\system32\termmgr.dll
2011-12-19 14:40:59 196608 ----a-w- c:\windows\system32\wwanconn.dll
2011-12-19 14:39:58 11264 ----a-w- c:\windows\system32\wshirda.dll
2011-12-19 14:38:45 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-12-19 14:38:45 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2011-12-18 02:45:49 -------- d-----w- c:\programdata\VirtualizedApplications
2011-12-18 00:15:40 -------- d-----w- c:\users\evan\appdata\local\SoftGrid Client
2011-12-18 00:15:36 -------- d-----w- c:\users\evan\appdata\roaming\SoftGrid Client
2011-12-18 00:13:21 -------- d-----w- c:\program files\Microsoft Application Virtualization Client
2011-12-18 00:12:52 -------- d-----w- c:\users\evan\appdata\roaming\TP
2011-12-15 18:02:10 748336 ----a-w- c:\program files\internet explorer\iexplore.exe
2011-12-15 17:45:27 -------- d-----w- c:\users\evan\appdata\local\Tific
2011-12-15 17:45:25 -------- d-----w- c:\users\evan\appdata\roaming\Tific
2011-12-14 21:03:20 534528 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 21:03:12 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-14 21:02:55 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 21:02:53 38912 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 21:02:51 3967856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 21:02:50 3912560 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 15:40:12 -------- d-----w- c:\program files\VideoLAN
.
==================== Find3M ====================
.
2011-12-30 03:32:36 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-12-11 00:11:15 13 --sh--r- c:\windows\system32\drivers\fbd.sys
2011-11-15 21:29:56 222080 ------w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 11:58:31.20 ===============
----------------------------------------------------------------
DDS Attach:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows 7 Starter
Boot Device: \Device\HarddiskVolume1
Install Date: 12/10/2011 2:17:01 PM
System Uptime: 1/12/2012 10:17:49 AM (1 hours ago)
.
Motherboard: TOSHIBA | | PBU00
Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz | U2E1 | 1667/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 223 GiB total, 194.841 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsld21c3acf
Device ID: ROOT\LEGACY_MPKSLD21C3ACF\0000
Manufacturer:
Name: MpKsld21c3acf
PNP Device ID: ROOT\LEGACY_MPKSLD21C3ACF\0000
Service: MpKsld21c3acf
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsld4d09d5d
Device ID: ROOT\LEGACY_MPKSLD4D09D5D\0000
Manufacturer:
Name: MpKsld4d09d5d
PNP Device ID: ROOT\LEGACY_MPKSLD4D09D5D\0000
Service: MpKsld4d09d5d
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsle57a2de5
Device ID: ROOT\LEGACY_MPKSLE57A2DE5\0000
Manufacturer:
Name: MpKsle57a2de5
PNP Device ID: ROOT\LEGACY_MPKSLE57A2DE5\0000
Service: MpKsle57a2de5
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsl7ba6b06b
Device ID: ROOT\LEGACY_MPKSL7BA6B06B\0000
Manufacturer:
Name: MpKsl7ba6b06b
PNP Device ID: ROOT\LEGACY_MPKSL7BA6B06B\0000
Service: MpKsl7ba6b06b
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsla259bee7
Device ID: ROOT\LEGACY_MPKSLA259BEE7\0000
Manufacturer:
Name: MpKsla259bee7
PNP Device ID: ROOT\LEGACY_MPKSLA259BEE7\0000
Service: MpKsla259bee7
.
==== System Restore Points ===================
.
RP21: 12/29/2011 7:37:58 PM - Windows 7 Service Pack 1
RP23: 12/30/2011 8:42:36 AM - Installed DirectX
RP25: 1/1/2012 9:43:57 AM - Windows Update
RP26: 1/3/2012 10:48:07 AM - Windows Update
RP27: 1/7/2012 10:17:25 AM - Windows Update
RP28: 1/10/2012 2:17:51 PM - Windows Update
RP29: 1/11/2012 9:09:39 AM - Windows Update
RP30: 1/11/2012 2:00:37 PM - Restore Operation
RP31: 1/11/2012 2:13:22 PM - Windows Update
RP32: 1/11/2012 5:18:50 PM - Installed Microsoft Office Standard Edition 2003
RP33: 1/11/2012 5:26:58 PM - Windows Update
RP34: 1/11/2012 6:05:01 PM - Windows Update
.
==== Installed Programs ======================
.
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Adobe Reader 9.3.4
Bejeweled 2 Deluxe
CCleaner
Chuzzle Deluxe
D3DX10
FATE - The Traitor Soul
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Governor of Poker 2 Premium Edition
Intel(R) Graphics Media Accelerator Driver
Intel(R) Rapid Storage Technology
Java Auto Updater
Java(TM) 6 Update 20
Jewel Quest - Heritage
Junk Mail filter update
Malwarebytes Anti-Malware version 1.60.0.1800
Media Player Classic - Home Cinema v1.5.2.3456
Mesh Runtime
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Standard Edition 2003
Microsoft Office Starter 2010 - English
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MSVCRT
Mystery P.I. - The London Caper
Plants vs. Zombies - Game of the Year
PlayReady PC Runtime x86
Polar Bowler
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Realtek WLAN Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Skype Launcher
Slingo Supreme
Spyware Doctor 8.0
Synaptics Pointing Device Driver
Toshiba App Place
TOSHIBA Application and Driver Installer
TOSHIBA Assist
Toshiba Book Place
TOSHIBA Bulletin Board
TOSHIBA Disc Creator
TOSHIBA eco Utility
TOSHIBA Flash Cards Support Utility
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
Toshiba Laptop Checkup
TOSHIBA Media Controller
Toshiba Online Backup
TOSHIBA Quality Application
TOSHIBA Recovery Media Creator
TOSHIBA ReelTime
TOSHIBA Service Station
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
TOSHIBA Web Camera Application
ToshibaRegistration
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Utility Common Driver
VLC media player 1.1.11
WeatherBug
WildTangent Games
WildTangent ORB Game Console
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
1/9/2012 9:45:05 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2.
1/9/2012 8:42:53 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR3.
1/9/2012 5:57:42 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} and APPID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user Netbook\Evan SID (S-1-5-21-3793523996-3693569771-4273842782-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
1/9/2012 5:57:42 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} and APPID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user Netbook\Evan SID (S-1-5-21-3793523996-3693569771-4273842782-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
1/9/2012 5:47:43 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR5.
1/12/2012 7:55:30 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
1/12/2012 10:18:27 AM, Error: RTL8192Ce [0] -
1/11/2012 8:55:42 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the PCCUJobMgr service.
1/11/2012 7:53:38 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
1/11/2012 5:24:43 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {0C0A3666-30C9-11D0-8F20-00805F2CD064} and APPID {9209B1A6-964A-11D0-9372-00A0C9034910} to the user Netbook\Evan SID (S-1-5-21-3793523996-3693569771-4273842782-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
1/11/2012 5:24:34 PM, Error: Service Control Manager [7030] - The Machine Debug Manager service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
1/11/2012 2:21:58 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB2644615).
1/11/2012 2:17:18 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB2631813).
1/11/2012 2:17:18 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB2584146).
1/11/2012 2:03:52 PM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
1/11/2012 11:35:33 AM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
1/11/2012 11:35:32 AM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
1/11/2012 11:35:31 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7034] - The Application Information service terminated unexpectedly. It has done this 1 time(s).
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/10/2012 8:32:54 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Schedule service.
1/10/2012 7:30:51 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the BITS service.
1/10/2012 7:30:51 AM, Error: Service Control Manager [7000] - The Background Intelligent Transfer Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:29:51 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the wuauserv service.
1/10/2012 7:29:51 AM, Error: Service Control Manager [7000] - The Windows Update service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:29:21 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
1/10/2012 7:27:19 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Microsoft Network Inspection service to connect.
1/10/2012 7:27:19 AM, Error: Service Control Manager [7000] - The Microsoft Network Inspection service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:26:49 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AeLookupSvc service.
1/10/2012 7:26:49 AM, Error: Service Control Manager [7000] - The Application Experience service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:26:19 AM, Error: Service Control Manager [7022] - The Application Virtualization Client service hung on starting.
1/10/2012 7:26:19 AM, Error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: After starting, the service hung in a start-pending state.
1/10/2012 7:25:48 AM, Error: Service Control Manager [7022] - The Common Client Job Manager Service service hung on starting.
1/10/2012 7:25:43 AM, Error: Service Control Manager [7022] - The Diagnostic Policy Service service hung on starting.
1/10/2012 7:24:23 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Winmgmt service.
1/10/2012 7:24:23 AM, Error: Service Control Manager [7001] - The TOSHIBA eco Utility Service service depends on the Windows Management Instrumentation service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:23:52 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Toshiba Laptop Checkup Application Launcher service to connect.
1/10/2012 7:23:52 AM, Error: Service Control Manager [7000] - The Toshiba Laptop Checkup Application Launcher service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:23:21 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service.
1/10/2012 7:23:21 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:23:21 AM, Error: Service Control Manager [7000] - The Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:22:50 AM, Error: Service Control Manager [7000] - The Task Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:22:20 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
1/10/2012 7:21:50 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the EapHost service.
1/10/2012 7:21:50 AM, Error: Service Control Manager [7001] - The WLAN AutoConfig service depends on the Extensible Authentication Protocol service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:21:50 AM, Error: Service Control Manager [7000] - The Extensible Authentication Protocol service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:21:23 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x816cc348, 0x00000002, 0x00000000, 0x81c6cefd). A dump was saved in: C:\windows\MEMORY.DMP. Report Id: 011012-38906-01.
.
==== End Of File ===========================
Malwarebytes log:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.11.06
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Evan :: NETBOOK [administrator]
1/11/2012 6:54:10 PM
mbam-log-2012-01-11 (18-54-10).txt
Scan type: Custom scan
Scan options enabled: File System | Heuristics/Shuriken | PUP | PUM
Scan options disabled: Memory | Startup | Registry | Heuristics/Extra | P2P
Objects scanned: 1
Time elapsed: 16 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
-------------------------------------
GMER log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-12 11:30:50
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 TOSHIBA_ rev.GJ00
Running: dl67e973.exe; Driver: C:\Users\Evan\AppData\Local\Temp\fxrdqpog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x8682CF68]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x8682D230]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x8682D52C]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x8682C9D8]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 81A47369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81A80D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11E3 81A87E98 4 Bytes [68, CF, 82, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11E8 81A87E9D 3 Bytes [D2, 82, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 121B 81A87ED0 4 Bytes [2C, D5, 82, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 166F 81A88324 4 Bytes [D8, C9, 82, 86]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe[1784] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [7547FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\PCTSDInjDriver32 \Device\PCTSDInjDriver32 PCTSDInj32.sys
Device \Driver\ACPI_HAL \Device\0000004f halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB59561$\261678897 0 bytes
File C:\Windows\$NtUninstallKB59561$\261678897\cfg.ini 206 bytes
File C:\Windows\$NtUninstallKB59561$\261678897\U 0 bytes
File C:\Windows\$NtUninstallKB59561$\3897946129 0 bytes
---- EOF - GMER 1.0.15 ----
---------------------------------------------------
DDS log:
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Evan at 11:56:23 on 2012-01-12
Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.1013.169 [GMT -7:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\SymcPCCULaunchSvc.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe
C:\windows\system32\taskhost.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\windows\Explorer.EXE
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\igfxext.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://start.toshiba.com/g/
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [<NO NAME>]
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [HWSetup] c:\program files\toshiba\utilities\HWSetup.exe hwSetUP
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [RtHDVBg] c:\program files\realtek\audio\hda\RtHDVBg.exe /FORPCEE3
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TWebCamera] "c:\program files\toshiba\toshiba web camera application\TWebCamera.exe" autorun
mRun: [ToshibaAppPlace] "c:\program files\toshiba\toshiba app place\ToshibaAppPlace.exe"
mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TOBuActivation.exe" UNATTENDED
mRun: [TosVolRegulator] c:\program files\toshiba\tosvolregulator\TosVolRegulator.exe
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
TCP: DhcpNameServer = 75.75.75.75 75.75.75.75 75.75.76.76
TCP: Interfaces\{0E28DF56-F86F-418B-83B5-069A24F29196} : DhcpNameServer = 75.75.75.75 75.75.75.75 75.75.76.76
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2012-1-11 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2012-1-11 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2012-1-11 656320]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2010-10-20 821664]
R2 IconMan_R;IconMan_R;c:\program files\realtek\realtek usb 2.0 card reader\RIconMan.exe [2011-12-6 1809920]
R2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files\norton pc checkup\engine\2.0.6.22\SymcPCCULaunchSvc.exe [2011-12-6 115056]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\engine\2.0.6.22\ccSvcHst.exe [2011-12-6 126392]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2011-12-6 24064]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-6-10 394856]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\drivers\rtl8192ce.sys [2011-12-6 999016]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-9-14 577384]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-9-14 194408]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-9-14 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-9-14 19304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-4 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-11-4 136176]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2011-12-6 194664]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-12-19 52224]
.
=============== Created Last 30 ================
.
2012-01-12 17:16:44 0 ----a-w- c:\windows\system32\shoFC3A.tmp
2012-01-12 01:30:41 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{09dee56e-8103-47c7-b9b3-2c487f38b099}\offreg.dll
2012-01-12 01:04:49 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-12 01:04:49 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-12 01:04:49 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-12 01:04:48 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-12 01:04:48 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-12 01:04:48 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-12 01:04:47 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-12 01:04:47 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-12 01:04:46 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-12 01:04:46 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-12 00:24:23 28552 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
2012-01-12 00:24:23 28040 ----a-w- c:\windows\system32\mdimon.dll
2012-01-12 00:21:32 -------- d-----w- c:\program files\common files\L&H
2012-01-12 00:21:15 -------- d-----w- c:\program files\Microsoft ActiveSync
2012-01-12 00:20:26 -------- d-----w- c:\windows\SHELLNEW
2012-01-11 23:50:05 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-11 23:43:18 -------- d-----w- c:\program files\CCleaner
2012-01-11 23:38:41 23624 ----a-w- c:\windows\system32\drivers\hitmanpro36.sys
2012-01-11 23:38:10 -------- d-----w- c:\programdata\HitmanPro
2012-01-11 21:40:52 6823496 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{09dee56e-8103-47c7-b9b3-2c487f38b099}\mpengine.dll
2012-01-11 21:37:54 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2012-01-11 21:37:54 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2012-01-11 21:37:53 249616 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2012-01-11 21:37:53 102184 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2012-01-11 21:37:50 239168 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2012-01-11 21:37:50 160448 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2012-01-11 21:37:42 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2012-01-11 21:22:41 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 21:22:40 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 21:22:28 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 21:22:20 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 18:06:06 -------- d-----w- c:\users\evan\appdata\local\CrashDumps
2012-01-11 17:58:09 -------- d-----w- c:\users\evan\appdata\roaming\PC Tools
2012-01-11 17:58:09 -------- d-----w- c:\programdata\PC Tools
2012-01-11 17:58:09 -------- d-----w- c:\program files\PC Tools Security
2012-01-11 17:58:09 -------- d-----w- c:\program files\common files\PC Tools
2012-01-10 04:47:42 -------- d-----w- c:\users\evan\appdata\roaming\Malwarebytes
2012-01-10 04:47:23 -------- d-----w- c:\programdata\Malwarebytes
2012-01-10 04:47:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-05 16:07:44 -------- d-----w- c:\users\evan\appdata\local\Adobe
2011-12-30 15:43:59 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2011-12-30 15:40:07 -------- d-----w- c:\windows\system32\directx
2011-12-30 15:37:20 -------- d-----w- c:\program files\Media Player Classic - Home Cinema
2011-12-30 04:42:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-30 02:38:19 -------- d-----w- c:\windows\system32\SPReview
2011-12-30 02:13:12 -------- d-----w- c:\windows\system32\EventProviders
2011-12-21 06:07:28 0 ----a-w- c:\windows\system32\sho967A.tmp
2011-12-21 01:17:04 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-12-21 01:17:03 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-12-21 01:17:02 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-12-21 01:04:00 0 ----a-w- c:\windows\system32\sho1F2C.tmp
2011-12-19 14:43:58 1019904 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-12-19 14:42:59 854016 ----a-w- c:\windows\system32\dbghelp.dll
2011-12-19 14:41:59 352768 ----a-w- c:\windows\system32\termmgr.dll
2011-12-19 14:40:59 196608 ----a-w- c:\windows\system32\wwanconn.dll
2011-12-19 14:39:58 11264 ----a-w- c:\windows\system32\wshirda.dll
2011-12-19 14:38:45 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-12-19 14:38:45 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2011-12-18 02:45:49 -------- d-----w- c:\programdata\VirtualizedApplications
2011-12-18 00:15:40 -------- d-----w- c:\users\evan\appdata\local\SoftGrid Client
2011-12-18 00:15:36 -------- d-----w- c:\users\evan\appdata\roaming\SoftGrid Client
2011-12-18 00:13:21 -------- d-----w- c:\program files\Microsoft Application Virtualization Client
2011-12-18 00:12:52 -------- d-----w- c:\users\evan\appdata\roaming\TP
2011-12-15 18:02:10 748336 ----a-w- c:\program files\internet explorer\iexplore.exe
2011-12-15 17:45:27 -------- d-----w- c:\users\evan\appdata\local\Tific
2011-12-15 17:45:25 -------- d-----w- c:\users\evan\appdata\roaming\Tific
2011-12-14 21:03:20 534528 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 21:03:12 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-14 21:02:55 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 21:02:53 38912 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 21:02:51 3967856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 21:02:50 3912560 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 15:40:12 -------- d-----w- c:\program files\VideoLAN
.
==================== Find3M ====================
.
2011-12-30 03:32:36 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-12-11 00:11:15 13 --sh--r- c:\windows\system32\drivers\fbd.sys
2011-11-15 21:29:56 222080 ------w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 11:58:31.20 ===============
----------------------------------------------------------------
DDS Attach:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows 7 Starter
Boot Device: \Device\HarddiskVolume1
Install Date: 12/10/2011 2:17:01 PM
System Uptime: 1/12/2012 10:17:49 AM (1 hours ago)
.
Motherboard: TOSHIBA | | PBU00
Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz | U2E1 | 1667/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 223 GiB total, 194.841 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsld21c3acf
Device ID: ROOT\LEGACY_MPKSLD21C3ACF\0000
Manufacturer:
Name: MpKsld21c3acf
PNP Device ID: ROOT\LEGACY_MPKSLD21C3ACF\0000
Service: MpKsld21c3acf
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsld4d09d5d
Device ID: ROOT\LEGACY_MPKSLD4D09D5D\0000
Manufacturer:
Name: MpKsld4d09d5d
PNP Device ID: ROOT\LEGACY_MPKSLD4D09D5D\0000
Service: MpKsld4d09d5d
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsle57a2de5
Device ID: ROOT\LEGACY_MPKSLE57A2DE5\0000
Manufacturer:
Name: MpKsle57a2de5
PNP Device ID: ROOT\LEGACY_MPKSLE57A2DE5\0000
Service: MpKsle57a2de5
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsl7ba6b06b
Device ID: ROOT\LEGACY_MPKSL7BA6B06B\0000
Manufacturer:
Name: MpKsl7ba6b06b
PNP Device ID: ROOT\LEGACY_MPKSL7BA6B06B\0000
Service: MpKsl7ba6b06b
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsla259bee7
Device ID: ROOT\LEGACY_MPKSLA259BEE7\0000
Manufacturer:
Name: MpKsla259bee7
PNP Device ID: ROOT\LEGACY_MPKSLA259BEE7\0000
Service: MpKsla259bee7
.
==== System Restore Points ===================
.
RP21: 12/29/2011 7:37:58 PM - Windows 7 Service Pack 1
RP23: 12/30/2011 8:42:36 AM - Installed DirectX
RP25: 1/1/2012 9:43:57 AM - Windows Update
RP26: 1/3/2012 10:48:07 AM - Windows Update
RP27: 1/7/2012 10:17:25 AM - Windows Update
RP28: 1/10/2012 2:17:51 PM - Windows Update
RP29: 1/11/2012 9:09:39 AM - Windows Update
RP30: 1/11/2012 2:00:37 PM - Restore Operation
RP31: 1/11/2012 2:13:22 PM - Windows Update
RP32: 1/11/2012 5:18:50 PM - Installed Microsoft Office Standard Edition 2003
RP33: 1/11/2012 5:26:58 PM - Windows Update
RP34: 1/11/2012 6:05:01 PM - Windows Update
.
==== Installed Programs ======================
.
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Adobe Reader 9.3.4
Bejeweled 2 Deluxe
CCleaner
Chuzzle Deluxe
D3DX10
FATE - The Traitor Soul
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Governor of Poker 2 Premium Edition
Intel(R) Graphics Media Accelerator Driver
Intel(R) Rapid Storage Technology
Java Auto Updater
Java(TM) 6 Update 20
Jewel Quest - Heritage
Junk Mail filter update
Malwarebytes Anti-Malware version 1.60.0.1800
Media Player Classic - Home Cinema v1.5.2.3456
Mesh Runtime
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Standard Edition 2003
Microsoft Office Starter 2010 - English
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MSVCRT
Mystery P.I. - The London Caper
Plants vs. Zombies - Game of the Year
PlayReady PC Runtime x86
Polar Bowler
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Realtek WLAN Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Skype Launcher
Slingo Supreme
Spyware Doctor 8.0
Synaptics Pointing Device Driver
Toshiba App Place
TOSHIBA Application and Driver Installer
TOSHIBA Assist
Toshiba Book Place
TOSHIBA Bulletin Board
TOSHIBA Disc Creator
TOSHIBA eco Utility
TOSHIBA Flash Cards Support Utility
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
Toshiba Laptop Checkup
TOSHIBA Media Controller
Toshiba Online Backup
TOSHIBA Quality Application
TOSHIBA Recovery Media Creator
TOSHIBA ReelTime
TOSHIBA Service Station
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
TOSHIBA Web Camera Application
ToshibaRegistration
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Utility Common Driver
VLC media player 1.1.11
WeatherBug
WildTangent Games
WildTangent ORB Game Console
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
1/9/2012 9:45:05 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2.
1/9/2012 8:42:53 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR3.
1/9/2012 5:57:42 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} and APPID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user Netbook\Evan SID (S-1-5-21-3793523996-3693569771-4273842782-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
1/9/2012 5:57:42 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} and APPID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user Netbook\Evan SID (S-1-5-21-3793523996-3693569771-4273842782-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
1/9/2012 5:47:43 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR5.
1/12/2012 7:55:30 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
1/12/2012 10:18:27 AM, Error: RTL8192Ce [0] -
1/11/2012 8:55:42 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the PCCUJobMgr service.
1/11/2012 7:53:38 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
1/11/2012 5:24:43 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {0C0A3666-30C9-11D0-8F20-00805F2CD064} and APPID {9209B1A6-964A-11D0-9372-00A0C9034910} to the user Netbook\Evan SID (S-1-5-21-3793523996-3693569771-4273842782-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
1/11/2012 5:24:34 PM, Error: Service Control Manager [7030] - The Machine Debug Manager service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
1/11/2012 2:21:58 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB2644615).
1/11/2012 2:17:18 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB2631813).
1/11/2012 2:17:18 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB2584146).
1/11/2012 2:03:52 PM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
1/11/2012 11:35:33 AM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
1/11/2012 11:35:32 AM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
1/11/2012 11:35:31 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7034] - The Application Information service terminated unexpectedly. It has done this 1 time(s).
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/11/2012 11:05:46 AM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/10/2012 8:32:54 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Schedule service.
1/10/2012 7:30:51 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the BITS service.
1/10/2012 7:30:51 AM, Error: Service Control Manager [7000] - The Background Intelligent Transfer Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:29:51 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the wuauserv service.
1/10/2012 7:29:51 AM, Error: Service Control Manager [7000] - The Windows Update service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:29:21 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
1/10/2012 7:27:19 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Microsoft Network Inspection service to connect.
1/10/2012 7:27:19 AM, Error: Service Control Manager [7000] - The Microsoft Network Inspection service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:26:49 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AeLookupSvc service.
1/10/2012 7:26:49 AM, Error: Service Control Manager [7000] - The Application Experience service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:26:19 AM, Error: Service Control Manager [7022] - The Application Virtualization Client service hung on starting.
1/10/2012 7:26:19 AM, Error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: After starting, the service hung in a start-pending state.
1/10/2012 7:25:48 AM, Error: Service Control Manager [7022] - The Common Client Job Manager Service service hung on starting.
1/10/2012 7:25:43 AM, Error: Service Control Manager [7022] - The Diagnostic Policy Service service hung on starting.
1/10/2012 7:24:23 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Winmgmt service.
1/10/2012 7:24:23 AM, Error: Service Control Manager [7001] - The TOSHIBA eco Utility Service service depends on the Windows Management Instrumentation service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:23:52 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Toshiba Laptop Checkup Application Launcher service to connect.
1/10/2012 7:23:52 AM, Error: Service Control Manager [7000] - The Toshiba Laptop Checkup Application Launcher service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:23:21 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service.
1/10/2012 7:23:21 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:23:21 AM, Error: Service Control Manager [7000] - The Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:22:50 AM, Error: Service Control Manager [7000] - The Task Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:22:20 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
1/10/2012 7:21:50 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the EapHost service.
1/10/2012 7:21:50 AM, Error: Service Control Manager [7001] - The WLAN AutoConfig service depends on the Extensible Authentication Protocol service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:21:50 AM, Error: Service Control Manager [7000] - The Extensible Authentication Protocol service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/10/2012 7:21:23 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x816cc348, 0x00000002, 0x00000000, 0x81c6cefd). A dump was saved in: C:\windows\MEMORY.DMP. Report Id: 011012-38906-01.
.
==== End Of File ===========================