Hi,
I've had a go at resolving this myself but without success. Having looked around a few sites, you lovely people look to be extremely helpful and polite so I was hoping you could offer some assistance.
Symptoms: Google searches in IE9 and Firefox4 get normal results, but clicking any of the results gets redirected. Windows Firewall disabled and unable to start. Scans in Avast, Spybot S&D, ESET online all negative. Found a suspect reg entry but unable to delete it. The machine is a new laptop for web dev with a ton of software just installed so I'm loathe to reinstall without attempting a cleanup first.
So to business. Here are the logs:
MalwareBytes:
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6705
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
03/06/2011 18:27:18
mbam-log-2011-06-03 (18-27-18).txt
Scan type: Quick scan
Objects scanned: 189745
Time elapsed: 3 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER:
GMER 1.0.15.15640 - http://www.gmer.net
Rootkit scan 2011-06-03 18:31:26
Windows 6.1.7601 Service Pack 1
Running: r625u0sh.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77370a60e4
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77370a60e4 (not active ControlSet)
---- EOF - GMER 1.0.15 ----
DS.txt:
.
DDS (Ver_2011-06-03.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Harv at 17:42:45 on 2011-06-03
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8106.5893 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Fast Access\FATrayMon.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Fast Access\FATrayAlert.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\EditPlus 3\editplus.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Users\Harv\Downloads\r625u0sh.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: FAIESSOHelper Class: {a2f122da-055f-4df7-8f24-7354dbdba85b} - C:\Program Files (x86)\Fast Access\FAIESSO.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [FATrayAlert] C:\Program Files (x86)\Fast Access\FATrayMon.exe
mRun: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [FAStartup]
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
LSP: mswsock.dll
LSP: C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll
TCP: Interfaces\{46456BFF-F1C6-493B-9BA7-CF0BE2077C29}\244584F6D65684572623D2841627675697 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{46456BFF-F1C6-493B-9BA7-CF0BE2077C29}\55E637563657275646 : DhcpNameServer = 10.203.65.68 10.203.65.68 8.8.8.8
TCP: Interfaces\{46456BFF-F1C6-493B-9BA7-CF0BE2077C29}\759664162747 : DhcpNameServer = 10.203.65.68 10.203.65.68 8.8.8.8
TCP: Interfaces\{46456BFF-F1C6-493B-9BA7-CF0BE2077C29}\F42377962756C656373713233343536373 : DhcpNameServer = 192.168.1.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - C:\Program Files (x86)\Fast Access\FALogNot.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64: Search Helper - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: FAIESSOHelper Class: {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - C:\Program Files (x86)\Fast Access\FAIESSO.dll
BHO-X64: FAIESSO Helper Object - No File
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB-X64: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - No File
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun-x64: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun-x64: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun-x64: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [FATrayAlert] C:\Program Files (x86)\Fast Access\FATrayMon.exe
mRun-x64: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [FAStartup]
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Harv\AppData\Roaming\Mozilla\Firefox\Profiles\5w2695nz.default\
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdcfltn.sys --> C:\Windows\system32\DRIVERS\stdcfltn.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-4-20 98208]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-6-3 42184]
R2 FAService;FAService;C:\Program Files (x86)\Fast Access\FAService.exe [2010-4-4 2409800]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-5-7 2218600]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-4-7 378472]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-3-25 539248]
R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys --> C:\Windows\system32\DRIVERS\Accelern.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 FACAP;facap, FastAccess Video Capture;C:\Windows\system32\DRIVERS\facap.sys --> C:\Windows\system32\DRIVERS\facap.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 qicflt;upper Device Filter Driver;C:\Windows\system32\DRIVERS\qicflt.sys --> C:\Windows\system32\DRIVERS\qicflt.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-20 136176]
S3 athrusb6;Atheros Wireless LAN USB device driver 6 Series;C:\Windows\system32\DRIVERS\athrxu6.sys --> C:\Windows\system32\DRIVERS\athrxu6.sys [?]
S3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-06-03 14:16:32 -------- d-----w- C:\Program Files (x86)\ESET
2011-06-03 12:06:54 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-06-03 12:06:51 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-06-03 11:49:49 64344 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-06-03 11:49:49 600920 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-06-03 11:49:42 40112 ----a-w- C:\Windows\avastSS.scr
2011-06-03 11:49:38 -------- d-----w- C:\ProgramData\AVAST Software
2011-06-03 11:49:38 -------- d-----w- C:\Program Files\AVAST Software
2011-06-03 11:48:08 -------- d-sh--w- C:\$RECYCLE.BIN
2011-06-03 11:27:36 8802128 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-06-03 11:27:34 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6CDBAEBB-A408-4547-846C-4EB2DDFA924B}\mpengine.dll
2011-05-31 01:04:43 35712 ----a-w- C:\Windows\SysWow64\drivers\new.sys
2011-05-31 01:03:49 35712 ----a-w- C:\Windows\SysWow64\drivers\BlackBox.sys
2011-05-30 23:42:37 -------- d-----w- C:\Users\Harv\AppData\Roaming\Malwarebytes
2011-05-30 23:42:32 -------- d-----w- C:\ProgramData\Malwarebytes
2011-05-30 23:42:29 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-05-30 15:07:36 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-05-30 15:07:22 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2011-05-26 22:45:51 -------- d-----w- C:\Program Files\CCleaner
2011-05-24 22:09:05 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2011-05-24 00:37:56 -------- d-----w- C:\Program Files (x86)\Common Files\Nikon
2011-05-24 00:37:55 -------- d-----w- C:\Program Files (x86)\Nikon
2011-05-20 22:34:59 -------- d-----w- C:\ProgramData\Skype Extras
2011-05-20 22:33:51 -------- d-----r- C:\Program Files (x86)\Skype
2011-05-20 19:10:56 -------- d-----w- C:\Program Files (x86)\Logitech Touch Mouse Server
2011-05-19 21:14:22 -------- d-----w- C:\Program Files\PowerPlanAssistant
2011-05-16 22:31:59 519000 ----a-w- C:\Windows\System32\d3dx10_40.dll
2011-05-16 22:27:16 -------- d--h--w- C:\Windows\msdownld.tmp
2011-05-16 22:27:04 -------- d-----w- C:\Windows\SysWow64\directx
2011-05-16 22:24:09 -------- d-----w- C:\Users\Harv\AppData\Local\FalloutNV
2011-05-16 22:16:22 -------- d-----w- C:\Program Files (x86)\Fallout New Vegas
2011-05-15 21:33:54 -------- d-----w- C:\Program Files\iPod
2011-05-15 21:33:52 -------- d-----w- C:\Program Files\iTunes
2011-05-15 21:33:52 -------- d-----w- C:\Program Files (x86)\iTunes
2011-05-15 21:23:49 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2011-05-15 21:23:49 126312 ----a-w- C:\Windows\System32\GEARAspi64.dll
2011-05-15 21:23:49 107368 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2011-05-15 20:30:04 -------- d-----w- C:\Users\Harv\AppData\Local\Apple Computer
2011-05-15 20:29:23 -------- d-----w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2011-05-15 20:28:12 -------- d-----w- C:\Users\Harv\AppData\Local\Apple
2011-05-15 20:27:37 -------- d-----w- C:\Program Files\Bonjour
2011-05-15 20:27:37 -------- d-----w- C:\Program Files (x86)\Bonjour
2011-05-15 13:47:42 -------- d-----w- C:\Users\Harv\AppData\Local\{DE2B8C94-F699-4A5A-B289-42E8DE420D62}
2011-05-15 13:47:42 -------- d-----w- C:\Users\Harv\AppData\Local\{95BDD6BE-1F5D-41D1-B64F-6CACE13A0CA3}
2011-05-15 13:47:28 -------- d-----w- C:\Users\Harv\AppData\Local\Windows Live Writer
2011-05-13 15:21:42 -------- d-----w- C:\Users\Harv\AppData\Local\ElevatedDiagnostics
2011-05-12 19:18:25 -------- d-----w- C:\Users\Harv\AppData\Local\Mozilla
2011-05-12 18:51:39 -------- d-----w- C:\Users\Harv\AppData\Local\VMware
2011-05-12 18:20:37 81008 ----a-w- C:\Windows\System32\drivers\vmci.sys
2011-05-12 18:20:33 68720 ----a-w- C:\Windows\System32\drivers\vmx86.sys
2011-05-12 18:19:59 334448 ----a-w- C:\Windows\SysWow64\vmnetdhcp.exe
2011-05-12 18:19:55 404080 ----a-w- C:\Windows\SysWow64\vmnat.exe
2011-05-12 18:19:54 30320 ----a-w- C:\Windows\System32\drivers\vmnetuserif.sys
2011-05-12 18:19:49 968816 ----a-w- C:\Windows\System32\vnetlib64.dll
2011-05-12 18:19:27 31856 ----a-w- C:\Windows\System32\drivers\VMkbd.sys
2011-05-12 18:19:22 38512 ----a-w- C:\Windows\System32\drivers\hcmon.sys
2011-05-12 18:18:27 -------- d-----w- C:\Program Files (x86)\Common Files\VMware
2011-05-12 18:17:31 -------- d-----w- C:\Program Files (x86)\VMware
2011-05-11 00:05:35 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2011-05-11 00:05:34 -------- d-----w- C:\Program Files (x86)\Steam
2011-05-10 23:31:05 -------- d-----w- C:\Users\Harv\AppData\Local\Google
2011-05-10 23:31:04 -------- d-----w- C:\Users\Harv\AppData\Local\Adobe
2011-05-10 23:29:29 -------- d-----w- C:\Users\Harv\AppData\Local\Temp
2011-05-10 23:29:29 -------- d-----w- C:\Users\Harv\AppData\Local\Microsoft
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\AppData\Roaming\Windows Live Writer
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\AppData\Roaming\Reallusion
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\AppData\Roaming\Patches
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\AppData\Roaming\EditPlus 3
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\Adobe Flash Builder 4
2011-05-10 22:00:01 -------- d-----w- C:\Program Files (x86)\EditPlus 3
2011-05-10 20:39:43 -------- d-----w- C:\Program Files (x86)\Common Files\Intel
2011-05-10 20:37:12 509976 ----a-w- C:\Windows\System32\igfxsrvc.exe
2011-05-10 20:37:12 4370456 ----a-w- C:\Windows\System32\GfxUI.exe
2011-05-10 20:37:12 418840 ----a-w- C:\Windows\System32\igfxpers.exe
2011-05-10 20:37:12 391704 ----a-w- C:\Windows\System32\hkcmd.exe
2011-05-10 20:37:12 239128 ----a-w- C:\Windows\System32\igfxext.exe
2011-05-10 20:37:12 167960 ----a-w- C:\Windows\System32\igfxtray.exe
2011-05-10 20:37:11 179736 ----a-w- C:\Windows\System32\difx64.exe
2011-05-10 20:28:57 -------- d-----w- C:\Program Files (x86)\Realtek
2011-05-10 19:08:04 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-05-10 19:08:04 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-05-10 18:01:21 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-05-10 18:01:19 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-05-10 18:01:18 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-05-10 18:01:17 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-05-10 18:01:17 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2011-05-10 18:01:17 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2011-05-10 18:01:17 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2011-05-10 18:01:17 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2011-05-10 18:01:17 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2011-05-10 18:01:17 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2011-05-07 13:48:51 -------- d-----w- C:\Program Files (x86)\Fast Access
2011-05-07 13:48:23 28672 ----a-w- C:\Windows\32761
2011-05-07 13:24:32 -------- d-----w- C:\Windows\System32\SPReview
2011-05-07 13:24:23 -------- d-----w- C:\Windows\System32\EventProviders
2011-05-07 13:22:59 833024 ----a-w- C:\Windows\SysWow64\user32.dll
2011-05-07 13:21:56 6144 ----a-w- C:\Windows\System32\drivers\en-US\IPMIDrv.sys.mui
2011-05-07 13:05:52 197120 ----a-w- C:\Windows\System32\d3d10_1.dll
2011-05-07 13:05:51 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
2011-05-07 12:51:07 -------- d-----w- C:\Windows\en
2011-05-07 12:48:35 69464 ----a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2011-05-07 12:48:35 515416 ----a-w- C:\Windows\SysWow64\XAudio2_5.dll
2011-05-07 12:48:34 523088 ----a-w- C:\Windows\System32\d3dx10_42.dll
2011-05-07 12:48:34 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-05-07 12:40:16 469256 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\e98817be1cc0cb32d\InstallManager_WLE_WLE.exe
2011-05-07 12:39:51 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\dbbf4bc31cc0cb321\MeshBetaRemover.exe
2011-05-07 12:39:30 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cedc76551cc0cb31a\DSETUP.dll
2011-05-07 12:39:30 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cedc76551cc0cb31a\DXSETUP.exe
2011-05-07 12:39:30 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cedc76551cc0cb31a\dsetup32.dll
2011-05-07 12:39:29 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cd5c39551cc0cb319\DXSETUP.exe
2011-05-07 12:39:28 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cd5c39551cc0cb319\DSETUP.dll
2011-05-07 12:39:28 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cd5c39551cc0cb319\dsetup32.dll
2011-05-07 12:32:56 -------- d-----w- C:\ProgramData\Roaming
2011-05-07 12:32:08 -------- d-----w- C:\Program Files\Common Files\Intel
2011-05-07 08:05:46 -------- d-----w- C:\Program Files (x86)\VideoLAN
2011-05-07 07:33:55 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2011-05-07 06:52:03 -------- d-----w- C:\ProgramData\ALM
2011-05-07 02:07:25 -------- d-----w- C:\NVIDIA
2011-05-06 19:21:50 -------- d-----w- C:\Program Files (x86)\Elaborate Bytes
2011-05-06 19:11:42 2414360 ----a-w- C:\Windows\SysWow64\d3dx9_31.dll
2011-05-06 19:11:42 1892184 ----a-w- C:\Windows\SysWow64\D3DX9_42.dll
2011-05-06 12:51:40 902656 ----a-w- C:\Windows\System32\d2d1.dll
2011-05-06 12:51:40 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2011-05-06 12:51:40 1544192 ----a-w- C:\Windows\System32\DWrite.dll
2011-05-06 12:51:40 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2011-05-06 12:51:40 1076736 ----a-w- C:\Windows\SysWow64\DWrite.dll
2011-05-06 12:24:13 -------- d-----w- C:\Windows\SysWow64\Wat
2011-05-06 12:24:13 -------- d-----w- C:\Windows\System32\Wat
2011-05-06 12:12:34 294912 ----a-w- C:\Windows\System32\browserchoice.exe
2011-05-06 12:05:27 715776 ----a-w- C:\Windows\System32\kerberos.dll
2011-05-06 12:05:27 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
2011-05-06 12:05:20 2871808 ----a-w- C:\Windows\explorer.exe
2011-05-06 12:05:20 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2011-05-06 11:59:01 270720 ------w- C:\Windows\System32\MpSigStub.exe
.
==================== Find3M ====================
.
2011-05-07 13:26:54 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-05-07 13:26:54 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-04-20 10:29:36 29480 ----a-w- C:\Windows\SysWow64\msxml3a.dll
2011-04-20 10:26:32 75 --sh--r- C:\Windows\CT4CET.bin
2011-04-07 22:19:16 849092 ----a-w- C:\Windows\System32\nvcoproc.bin
2011-04-07 22:19:16 797800 ----a-w- C:\Windows\System32\nv3dappshext.dll
2011-04-07 22:19:16 53864 ----a-w- C:\Windows\System32\nv3dappshextr.dll
2011-04-07 22:19:16 318056 ----a-w- C:\Windows\System32\nvhotkey.dll
2011-04-07 22:19:16 2582120 ----a-w- C:\Windows\System32\nvsvcr.dll
2011-04-07 22:19:16 117864 ----a-w- C:\Windows\System32\nvmctray.dll
2011-04-07 22:19:16 1012328 ----a-w- C:\Windows\System32\nvvsvc.exe
2011-04-07 22:19:14 797288 ----a-w- C:\Windows\System32\easyUpdatusAPIU64.dll
2011-04-07 22:19:06 6338152 ----a-w- C:\Windows\System32\nvcpl.dll
2011-04-07 22:18:42 3041384 ----a-w- C:\Windows\System32\nvsvc64.dll
2011-04-06 15:26:58 96544 ----a-w- C:\Windows\System32\dnssd.dll
2011-04-06 15:26:58 69408 ----a-w- C:\Windows\System32\jdns_sd.dll
2011-04-06 15:26:58 237856 ----a-w- C:\Windows\System32\dnssdX.dll
2011-04-06 15:26:58 119584 ----a-w- C:\Windows\System32\dns-sd.exe
2011-04-06 15:20:16 91424 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-04-06 15:20:16 75040 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
2011-04-06 15:20:16 197920 ----a-w- C:\Windows\SysWow64\dnssdX.dll
2011-04-06 15:20:16 107808 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-03-26 00:24:18 90112 ----a-w- C:\Windows\System32\igfxCoIn_v2342.dll
2011-03-26 00:17:50 12262336 ----a-w- C:\Windows\System32\drivers\igdkmd64.sys
2011-03-26 00:17:48 7473664 ----a-w- C:\Windows\System32\igdumd64.dll
2011-03-26 00:16:10 963116 ----a-w- C:\Windows\SysWow64\igkrng600.bin
2011-03-26 00:16:10 963116 ----a-w- C:\Windows\System32\igkrng600.bin
2011-03-26 00:16:10 216876 ----a-w- C:\Windows\SysWow64\igfcg600m.bin
2011-03-26 00:16:10 216876 ----a-w- C:\Windows\System32\igfcg600m.bin
2011-03-26 00:12:06 5692416 ----a-w- C:\Windows\SysWow64\igdumd32.dll
2011-03-26 00:08:46 575488 ----a-w- C:\Windows\SysWow64\igdumdx32.dll
2011-03-26 00:05:34 7386624 ----a-w- C:\Windows\System32\igd10umd64.dll
2011-03-26 00:02:08 6068736 ----a-w- C:\Windows\SysWow64\igd10umd32.dll
2011-03-25 23:54:14 19592704 ----a-w- C:\Windows\System32\ig4icd64.dll
2011-03-25 23:45:16 14294016 ----a-w- C:\Windows\SysWow64\ig4icd32.dll
2011-03-25 23:39:48 335872 ----a-w- C:\Windows\System32\igfxpph.dll
2011-03-25 23:39:44 380928 ----a-w- C:\Windows\System32\igfxTMM.dll
2011-03-25 23:39:38 28672 ----a-w- C:\Windows\System32\igfxexps.dll
2011-03-25 23:39:26 62464 ----a-w- C:\Windows\System32\igfxsrvc.dll
2011-03-25 23:39:00 109056 ----a-w- C:\Windows\System32\hccutils.dll
2011-03-25 23:38:52 144896 ----a-w- C:\Windows\System32\gfxSrvc.dll
2011-03-25 23:38:50 4096 ----a-w- C:\Windows\System32\IGFXDEVLib.dll
2011-03-25 23:38:50 385024 ----a-w- C:\Windows\System32\igfxdev.dll
2011-03-25 23:38:18 285696 ----a-w- C:\Windows\System32\igfxrenu.lrc
2011-03-25 23:38:12 142336 ----a-w- C:\Windows\System32\igfxdo.dll
2011-03-25 23:38:10 9014784 ----a-w- C:\Windows\System32\igfxress.dll
2011-03-25 23:34:40 24576 ----a-w- C:\Windows\SysWow64\igfxexps32.dll
2011-03-25 23:33:50 288768 ----a-w- C:\Windows\SysWow64\igfxdv32.dll
2011-03-25 23:28:24 142848 ----a-w- C:\Windows\SysWow64\igfxcmrt32.dll
2011-03-25 23:28:24 122368 ----a-w- C:\Windows\System32\igfxcmrt64.dll
2011-03-25 21:00:54 252528 ----a-w- C:\Windows\SysWow64\vmnc.dll
2011-03-25 19:05:00 37680 ----a-w- C:\Windows\System32\drivers\vmusb.sys
2011-03-25 19:04:58 56880 ----a-w- C:\Windows\System32\vmnetbridge.dll
2011-03-25 19:04:58 55344 ----a-w- C:\Windows\System32\vnetinst.dll
2011-03-25 19:04:58 45104 ----a-w- C:\Windows\System32\drivers\vmnetbridge.sys
2011-03-25 19:04:58 24112 ----a-w- C:\Windows\System32\drivers\vmnet.sys
2011-03-25 19:04:58 20016 ----a-w- C:\Windows\System32\drivers\vmnetadapter.sys
2011-03-21 12:22:06 74272 ----a-w- C:\Windows\System32\RtNicProp64.dll
2011-03-21 12:22:06 452200 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2011-03-21 12:22:06 107552 ----a-w- C:\Windows\System32\RTNUninst64.dll
2011-03-12 12:08:49 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 11:23:45 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-11 06:41:37 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 06:33:29 2565632 ----a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 ----a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-11 05:33:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-07 02:08:13 93552 ----a-w- C:\Windows\SysWow64\ElbyCDIO.dll
2011-03-07 00:52:09 134512 ----a-w- C:\Windows\SysWow64\ElbyVCD.dll
.
============= FINISH: 17:49:11.83 ===============
Attatch.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-03.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 05/05/2011 20:03:44
System Uptime: 03/06/2011 16:17:08 (1 hours ago)
.
Motherboard: Dell Inc. | | 0NJT03
Processor: Intel(R) Core(TM) i7-2820QM CPU @ 2.30GHz | CPU | 782/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 452 GiB total, 324.444 GiB free.
D: is FIXED (NTFS) - 14 GiB total, 7.456 GiB free.
E: is CDROM ()
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: Windows Firewall Authorization Driver
Device ID: ROOT\LEGACY_MPSDRV\0000
Manufacturer:
Name: Windows Firewall Authorization Driver
PNP Device ID: ROOT\LEGACY_MPSDRV\0000
Service: mpsdrv
.
==== System Restore Points ===================
.
RP1: 03/06/2011 15:58:46 - ComboFix created restore point
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Community Help
Adobe Creative Suite 5 Master Collection
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Advanced Audio FX Engine
Apple Application Support
Apple Software Update
avast! Free Antivirus
Camera Control Pro 2
CyberLink PowerDVD 9.5
D3DX10
Dell Webcam Central
EditPlus 3
Fallout New Vegas
FileZilla Client 3.4.0
Google Chrome
Google Update Helper
Intel(R) Processor Graphics
Junk Mail filter update
Live! Cam Avatar Creator
Logitech Touch Mouse Server 1.0
Malwarebytes' Anti-Malware version 1.51.0.1200
Microsoft Office 2010
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox 4.0.1 (x86 en-GB)
MSVCRT
MSVCRT_amd64
NVIDIA 3D Vision Controller Driver
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
PDF Settings CS5
QuickTime
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Roxio Burn
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Skype™ 5.3
Steam
tools-freebsd
tools-linux
tools-netware
tools-solaris
tools-windows
tools-winPre2k
VirtualCloneDrive
VLC media player 1.1.9
VMware Workstation
Winamp
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
31/05/2011 01:35:01, Error: Microsoft Antimalware [3002] -
31/05/2011 01:23:07, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache ElbyCDIO MpFilter spldr Wanarpv6
31/05/2011 01:02:19, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
31/05/2011 00:52:18, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service NVSvc with arguments "" in order to run the server: {DCAB0989-1301-4319-BE5F-ADE89F88581C}
31/05/2011 00:50:53, Error: Service Control Manager [7023] - The Server service terminated with the following error: The service has not been started.
31/05/2011 00:50:46, Error: Service Control Manager [7023] - The Security Center service terminated with the following error: The authentication service is unknown.
31/05/2011 00:31:25, Error: Service Control Manager [7031] - The VMware vCenter Converter Standalone Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
31/05/2011 00:31:20, Error: Service Control Manager [7034] - The VMware vCenter Converter Standalone Worker service terminated unexpectedly. It has done this 1 time(s).
30/05/2011 16:15:27, Error: Service Control Manager [7034] - The FAService service terminated unexpectedly. It has done this 1 time(s).
03/06/2011 15:28:44, Error: Service Control Manager [7001] - The Windows Firewall service depends on the Windows Firewall Authorization Driver service which failed to start because of the following error: Cannot create a file when that file already exists.
03/06/2011 15:28:44, Error: Service Control Manager [7000] - The Windows Firewall Authorization Driver service failed to start due to the following error: Cannot create a file when that file already exists.
03/06/2011 15:09:42, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 126
03/06/2011 13:10:27, Error: BTHUSB [17] - The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.
03/06/2011 13:06:42, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
03/06/2011 12:18:03, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
03/06/2011 11:30:21, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
03/06/2011 11:30:21, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
03/06/2011 11:20:56, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
03/06/2011 11:20:56, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
03/06/2011 11:20:55, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
03/06/2011 11:20:50, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
03/06/2011 11:20:36, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
03/06/2011 11:20:18, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache ElbyCDIO spldr Wanarpv6
03/06/2011 11:03:38, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
03/06/2011 09:40:00, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service VSS with arguments "" in order to run the server: {E579AB5F-1CC4-44B4-BED9-DE0991FF0623}
.
==== End Of File ===========================
All and any help appreciated - I have most tools at the ready.
RVee
I've had a go at resolving this myself but without success. Having looked around a few sites, you lovely people look to be extremely helpful and polite so I was hoping you could offer some assistance.
Symptoms: Google searches in IE9 and Firefox4 get normal results, but clicking any of the results gets redirected. Windows Firewall disabled and unable to start. Scans in Avast, Spybot S&D, ESET online all negative. Found a suspect reg entry but unable to delete it. The machine is a new laptop for web dev with a ton of software just installed so I'm loathe to reinstall without attempting a cleanup first.
So to business. Here are the logs:
MalwareBytes:
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6705
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
03/06/2011 18:27:18
mbam-log-2011-06-03 (18-27-18).txt
Scan type: Quick scan
Objects scanned: 189745
Time elapsed: 3 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER:
GMER 1.0.15.15640 - http://www.gmer.net
Rootkit scan 2011-06-03 18:31:26
Windows 6.1.7601 Service Pack 1
Running: r625u0sh.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77370a60e4
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77370a60e4 (not active ControlSet)
---- EOF - GMER 1.0.15 ----
DS.txt:
.
DDS (Ver_2011-06-03.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Harv at 17:42:45 on 2011-06-03
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8106.5893 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Fast Access\FATrayMon.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Fast Access\FATrayAlert.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\EditPlus 3\editplus.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Users\Harv\Downloads\r625u0sh.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: FAIESSOHelper Class: {a2f122da-055f-4df7-8f24-7354dbdba85b} - C:\Program Files (x86)\Fast Access\FAIESSO.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [FATrayAlert] C:\Program Files (x86)\Fast Access\FATrayMon.exe
mRun: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [FAStartup]
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
LSP: mswsock.dll
LSP: C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll
TCP: Interfaces\{46456BFF-F1C6-493B-9BA7-CF0BE2077C29}\244584F6D65684572623D2841627675697 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{46456BFF-F1C6-493B-9BA7-CF0BE2077C29}\55E637563657275646 : DhcpNameServer = 10.203.65.68 10.203.65.68 8.8.8.8
TCP: Interfaces\{46456BFF-F1C6-493B-9BA7-CF0BE2077C29}\759664162747 : DhcpNameServer = 10.203.65.68 10.203.65.68 8.8.8.8
TCP: Interfaces\{46456BFF-F1C6-493B-9BA7-CF0BE2077C29}\F42377962756C656373713233343536373 : DhcpNameServer = 192.168.1.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - C:\Program Files (x86)\Fast Access\FALogNot.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64: Search Helper - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: FAIESSOHelper Class: {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - C:\Program Files (x86)\Fast Access\FAIESSO.dll
BHO-X64: FAIESSO Helper Object - No File
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB-X64: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - No File
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun-x64: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun-x64: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun-x64: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [FATrayAlert] C:\Program Files (x86)\Fast Access\FATrayMon.exe
mRun-x64: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [FAStartup]
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Harv\AppData\Roaming\Mozilla\Firefox\Profiles\5w2695nz.default\
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdcfltn.sys --> C:\Windows\system32\DRIVERS\stdcfltn.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-4-20 98208]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-6-3 42184]
R2 FAService;FAService;C:\Program Files (x86)\Fast Access\FAService.exe [2010-4-4 2409800]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-5-7 2218600]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-4-7 378472]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-3-25 539248]
R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys --> C:\Windows\system32\DRIVERS\Accelern.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 FACAP;facap, FastAccess Video Capture;C:\Windows\system32\DRIVERS\facap.sys --> C:\Windows\system32\DRIVERS\facap.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 qicflt;upper Device Filter Driver;C:\Windows\system32\DRIVERS\qicflt.sys --> C:\Windows\system32\DRIVERS\qicflt.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-20 136176]
S3 athrusb6;Atheros Wireless LAN USB device driver 6 Series;C:\Windows\system32\DRIVERS\athrxu6.sys --> C:\Windows\system32\DRIVERS\athrxu6.sys [?]
S3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-06-03 14:16:32 -------- d-----w- C:\Program Files (x86)\ESET
2011-06-03 12:06:54 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-06-03 12:06:51 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-06-03 11:49:49 64344 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-06-03 11:49:49 600920 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-06-03 11:49:42 40112 ----a-w- C:\Windows\avastSS.scr
2011-06-03 11:49:38 -------- d-----w- C:\ProgramData\AVAST Software
2011-06-03 11:49:38 -------- d-----w- C:\Program Files\AVAST Software
2011-06-03 11:48:08 -------- d-sh--w- C:\$RECYCLE.BIN
2011-06-03 11:27:36 8802128 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-06-03 11:27:34 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6CDBAEBB-A408-4547-846C-4EB2DDFA924B}\mpengine.dll
2011-05-31 01:04:43 35712 ----a-w- C:\Windows\SysWow64\drivers\new.sys
2011-05-31 01:03:49 35712 ----a-w- C:\Windows\SysWow64\drivers\BlackBox.sys
2011-05-30 23:42:37 -------- d-----w- C:\Users\Harv\AppData\Roaming\Malwarebytes
2011-05-30 23:42:32 -------- d-----w- C:\ProgramData\Malwarebytes
2011-05-30 23:42:29 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-05-30 15:07:36 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-05-30 15:07:22 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2011-05-26 22:45:51 -------- d-----w- C:\Program Files\CCleaner
2011-05-24 22:09:05 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2011-05-24 00:37:56 -------- d-----w- C:\Program Files (x86)\Common Files\Nikon
2011-05-24 00:37:55 -------- d-----w- C:\Program Files (x86)\Nikon
2011-05-20 22:34:59 -------- d-----w- C:\ProgramData\Skype Extras
2011-05-20 22:33:51 -------- d-----r- C:\Program Files (x86)\Skype
2011-05-20 19:10:56 -------- d-----w- C:\Program Files (x86)\Logitech Touch Mouse Server
2011-05-19 21:14:22 -------- d-----w- C:\Program Files\PowerPlanAssistant
2011-05-16 22:31:59 519000 ----a-w- C:\Windows\System32\d3dx10_40.dll
2011-05-16 22:27:16 -------- d--h--w- C:\Windows\msdownld.tmp
2011-05-16 22:27:04 -------- d-----w- C:\Windows\SysWow64\directx
2011-05-16 22:24:09 -------- d-----w- C:\Users\Harv\AppData\Local\FalloutNV
2011-05-16 22:16:22 -------- d-----w- C:\Program Files (x86)\Fallout New Vegas
2011-05-15 21:33:54 -------- d-----w- C:\Program Files\iPod
2011-05-15 21:33:52 -------- d-----w- C:\Program Files\iTunes
2011-05-15 21:33:52 -------- d-----w- C:\Program Files (x86)\iTunes
2011-05-15 21:23:49 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2011-05-15 21:23:49 126312 ----a-w- C:\Windows\System32\GEARAspi64.dll
2011-05-15 21:23:49 107368 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2011-05-15 20:30:04 -------- d-----w- C:\Users\Harv\AppData\Local\Apple Computer
2011-05-15 20:29:23 -------- d-----w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2011-05-15 20:29:01 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2011-05-15 20:28:12 -------- d-----w- C:\Users\Harv\AppData\Local\Apple
2011-05-15 20:27:37 -------- d-----w- C:\Program Files\Bonjour
2011-05-15 20:27:37 -------- d-----w- C:\Program Files (x86)\Bonjour
2011-05-15 13:47:42 -------- d-----w- C:\Users\Harv\AppData\Local\{DE2B8C94-F699-4A5A-B289-42E8DE420D62}
2011-05-15 13:47:42 -------- d-----w- C:\Users\Harv\AppData\Local\{95BDD6BE-1F5D-41D1-B64F-6CACE13A0CA3}
2011-05-15 13:47:28 -------- d-----w- C:\Users\Harv\AppData\Local\Windows Live Writer
2011-05-13 15:21:42 -------- d-----w- C:\Users\Harv\AppData\Local\ElevatedDiagnostics
2011-05-12 19:18:25 -------- d-----w- C:\Users\Harv\AppData\Local\Mozilla
2011-05-12 18:51:39 -------- d-----w- C:\Users\Harv\AppData\Local\VMware
2011-05-12 18:20:37 81008 ----a-w- C:\Windows\System32\drivers\vmci.sys
2011-05-12 18:20:33 68720 ----a-w- C:\Windows\System32\drivers\vmx86.sys
2011-05-12 18:19:59 334448 ----a-w- C:\Windows\SysWow64\vmnetdhcp.exe
2011-05-12 18:19:55 404080 ----a-w- C:\Windows\SysWow64\vmnat.exe
2011-05-12 18:19:54 30320 ----a-w- C:\Windows\System32\drivers\vmnetuserif.sys
2011-05-12 18:19:49 968816 ----a-w- C:\Windows\System32\vnetlib64.dll
2011-05-12 18:19:27 31856 ----a-w- C:\Windows\System32\drivers\VMkbd.sys
2011-05-12 18:19:22 38512 ----a-w- C:\Windows\System32\drivers\hcmon.sys
2011-05-12 18:18:27 -------- d-----w- C:\Program Files (x86)\Common Files\VMware
2011-05-12 18:17:31 -------- d-----w- C:\Program Files (x86)\VMware
2011-05-11 00:05:35 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2011-05-11 00:05:34 -------- d-----w- C:\Program Files (x86)\Steam
2011-05-10 23:31:05 -------- d-----w- C:\Users\Harv\AppData\Local\Google
2011-05-10 23:31:04 -------- d-----w- C:\Users\Harv\AppData\Local\Adobe
2011-05-10 23:29:29 -------- d-----w- C:\Users\Harv\AppData\Local\Temp
2011-05-10 23:29:29 -------- d-----w- C:\Users\Harv\AppData\Local\Microsoft
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\AppData\Roaming\Windows Live Writer
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\AppData\Roaming\Reallusion
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\AppData\Roaming\Patches
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\AppData\Roaming\EditPlus 3
2011-05-10 23:26:28 -------- d-----w- C:\Users\Harv\Adobe Flash Builder 4
2011-05-10 22:00:01 -------- d-----w- C:\Program Files (x86)\EditPlus 3
2011-05-10 20:39:43 -------- d-----w- C:\Program Files (x86)\Common Files\Intel
2011-05-10 20:37:12 509976 ----a-w- C:\Windows\System32\igfxsrvc.exe
2011-05-10 20:37:12 4370456 ----a-w- C:\Windows\System32\GfxUI.exe
2011-05-10 20:37:12 418840 ----a-w- C:\Windows\System32\igfxpers.exe
2011-05-10 20:37:12 391704 ----a-w- C:\Windows\System32\hkcmd.exe
2011-05-10 20:37:12 239128 ----a-w- C:\Windows\System32\igfxext.exe
2011-05-10 20:37:12 167960 ----a-w- C:\Windows\System32\igfxtray.exe
2011-05-10 20:37:11 179736 ----a-w- C:\Windows\System32\difx64.exe
2011-05-10 20:28:57 -------- d-----w- C:\Program Files (x86)\Realtek
2011-05-10 19:08:04 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-05-10 19:08:04 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-05-10 18:01:21 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-05-10 18:01:19 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-05-10 18:01:18 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-05-10 18:01:17 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-05-10 18:01:17 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2011-05-10 18:01:17 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2011-05-10 18:01:17 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2011-05-10 18:01:17 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2011-05-10 18:01:17 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2011-05-10 18:01:17 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2011-05-07 13:48:51 -------- d-----w- C:\Program Files (x86)\Fast Access
2011-05-07 13:48:23 28672 ----a-w- C:\Windows\32761
2011-05-07 13:24:32 -------- d-----w- C:\Windows\System32\SPReview
2011-05-07 13:24:23 -------- d-----w- C:\Windows\System32\EventProviders
2011-05-07 13:22:59 833024 ----a-w- C:\Windows\SysWow64\user32.dll
2011-05-07 13:21:56 6144 ----a-w- C:\Windows\System32\drivers\en-US\IPMIDrv.sys.mui
2011-05-07 13:05:52 197120 ----a-w- C:\Windows\System32\d3d10_1.dll
2011-05-07 13:05:51 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
2011-05-07 12:51:07 -------- d-----w- C:\Windows\en
2011-05-07 12:48:35 69464 ----a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2011-05-07 12:48:35 515416 ----a-w- C:\Windows\SysWow64\XAudio2_5.dll
2011-05-07 12:48:34 523088 ----a-w- C:\Windows\System32\d3dx10_42.dll
2011-05-07 12:48:34 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-05-07 12:40:16 469256 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\e98817be1cc0cb32d\InstallManager_WLE_WLE.exe
2011-05-07 12:39:51 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\dbbf4bc31cc0cb321\MeshBetaRemover.exe
2011-05-07 12:39:30 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cedc76551cc0cb31a\DSETUP.dll
2011-05-07 12:39:30 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cedc76551cc0cb31a\DXSETUP.exe
2011-05-07 12:39:30 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cedc76551cc0cb31a\dsetup32.dll
2011-05-07 12:39:29 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cd5c39551cc0cb319\DXSETUP.exe
2011-05-07 12:39:28 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cd5c39551cc0cb319\DSETUP.dll
2011-05-07 12:39:28 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cd5c39551cc0cb319\dsetup32.dll
2011-05-07 12:32:56 -------- d-----w- C:\ProgramData\Roaming
2011-05-07 12:32:08 -------- d-----w- C:\Program Files\Common Files\Intel
2011-05-07 08:05:46 -------- d-----w- C:\Program Files (x86)\VideoLAN
2011-05-07 07:33:55 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2011-05-07 06:52:03 -------- d-----w- C:\ProgramData\ALM
2011-05-07 02:07:25 -------- d-----w- C:\NVIDIA
2011-05-06 19:21:50 -------- d-----w- C:\Program Files (x86)\Elaborate Bytes
2011-05-06 19:11:42 2414360 ----a-w- C:\Windows\SysWow64\d3dx9_31.dll
2011-05-06 19:11:42 1892184 ----a-w- C:\Windows\SysWow64\D3DX9_42.dll
2011-05-06 12:51:40 902656 ----a-w- C:\Windows\System32\d2d1.dll
2011-05-06 12:51:40 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2011-05-06 12:51:40 1544192 ----a-w- C:\Windows\System32\DWrite.dll
2011-05-06 12:51:40 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2011-05-06 12:51:40 1076736 ----a-w- C:\Windows\SysWow64\DWrite.dll
2011-05-06 12:24:13 -------- d-----w- C:\Windows\SysWow64\Wat
2011-05-06 12:24:13 -------- d-----w- C:\Windows\System32\Wat
2011-05-06 12:12:34 294912 ----a-w- C:\Windows\System32\browserchoice.exe
2011-05-06 12:05:27 715776 ----a-w- C:\Windows\System32\kerberos.dll
2011-05-06 12:05:27 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
2011-05-06 12:05:20 2871808 ----a-w- C:\Windows\explorer.exe
2011-05-06 12:05:20 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2011-05-06 11:59:01 270720 ------w- C:\Windows\System32\MpSigStub.exe
.
==================== Find3M ====================
.
2011-05-07 13:26:54 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-05-07 13:26:54 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-04-20 10:29:36 29480 ----a-w- C:\Windows\SysWow64\msxml3a.dll
2011-04-20 10:26:32 75 --sh--r- C:\Windows\CT4CET.bin
2011-04-07 22:19:16 849092 ----a-w- C:\Windows\System32\nvcoproc.bin
2011-04-07 22:19:16 797800 ----a-w- C:\Windows\System32\nv3dappshext.dll
2011-04-07 22:19:16 53864 ----a-w- C:\Windows\System32\nv3dappshextr.dll
2011-04-07 22:19:16 318056 ----a-w- C:\Windows\System32\nvhotkey.dll
2011-04-07 22:19:16 2582120 ----a-w- C:\Windows\System32\nvsvcr.dll
2011-04-07 22:19:16 117864 ----a-w- C:\Windows\System32\nvmctray.dll
2011-04-07 22:19:16 1012328 ----a-w- C:\Windows\System32\nvvsvc.exe
2011-04-07 22:19:14 797288 ----a-w- C:\Windows\System32\easyUpdatusAPIU64.dll
2011-04-07 22:19:06 6338152 ----a-w- C:\Windows\System32\nvcpl.dll
2011-04-07 22:18:42 3041384 ----a-w- C:\Windows\System32\nvsvc64.dll
2011-04-06 15:26:58 96544 ----a-w- C:\Windows\System32\dnssd.dll
2011-04-06 15:26:58 69408 ----a-w- C:\Windows\System32\jdns_sd.dll
2011-04-06 15:26:58 237856 ----a-w- C:\Windows\System32\dnssdX.dll
2011-04-06 15:26:58 119584 ----a-w- C:\Windows\System32\dns-sd.exe
2011-04-06 15:20:16 91424 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-04-06 15:20:16 75040 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
2011-04-06 15:20:16 197920 ----a-w- C:\Windows\SysWow64\dnssdX.dll
2011-04-06 15:20:16 107808 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-03-26 00:24:18 90112 ----a-w- C:\Windows\System32\igfxCoIn_v2342.dll
2011-03-26 00:17:50 12262336 ----a-w- C:\Windows\System32\drivers\igdkmd64.sys
2011-03-26 00:17:48 7473664 ----a-w- C:\Windows\System32\igdumd64.dll
2011-03-26 00:16:10 963116 ----a-w- C:\Windows\SysWow64\igkrng600.bin
2011-03-26 00:16:10 963116 ----a-w- C:\Windows\System32\igkrng600.bin
2011-03-26 00:16:10 216876 ----a-w- C:\Windows\SysWow64\igfcg600m.bin
2011-03-26 00:16:10 216876 ----a-w- C:\Windows\System32\igfcg600m.bin
2011-03-26 00:12:06 5692416 ----a-w- C:\Windows\SysWow64\igdumd32.dll
2011-03-26 00:08:46 575488 ----a-w- C:\Windows\SysWow64\igdumdx32.dll
2011-03-26 00:05:34 7386624 ----a-w- C:\Windows\System32\igd10umd64.dll
2011-03-26 00:02:08 6068736 ----a-w- C:\Windows\SysWow64\igd10umd32.dll
2011-03-25 23:54:14 19592704 ----a-w- C:\Windows\System32\ig4icd64.dll
2011-03-25 23:45:16 14294016 ----a-w- C:\Windows\SysWow64\ig4icd32.dll
2011-03-25 23:39:48 335872 ----a-w- C:\Windows\System32\igfxpph.dll
2011-03-25 23:39:44 380928 ----a-w- C:\Windows\System32\igfxTMM.dll
2011-03-25 23:39:38 28672 ----a-w- C:\Windows\System32\igfxexps.dll
2011-03-25 23:39:26 62464 ----a-w- C:\Windows\System32\igfxsrvc.dll
2011-03-25 23:39:00 109056 ----a-w- C:\Windows\System32\hccutils.dll
2011-03-25 23:38:52 144896 ----a-w- C:\Windows\System32\gfxSrvc.dll
2011-03-25 23:38:50 4096 ----a-w- C:\Windows\System32\IGFXDEVLib.dll
2011-03-25 23:38:50 385024 ----a-w- C:\Windows\System32\igfxdev.dll
2011-03-25 23:38:18 285696 ----a-w- C:\Windows\System32\igfxrenu.lrc
2011-03-25 23:38:12 142336 ----a-w- C:\Windows\System32\igfxdo.dll
2011-03-25 23:38:10 9014784 ----a-w- C:\Windows\System32\igfxress.dll
2011-03-25 23:34:40 24576 ----a-w- C:\Windows\SysWow64\igfxexps32.dll
2011-03-25 23:33:50 288768 ----a-w- C:\Windows\SysWow64\igfxdv32.dll
2011-03-25 23:28:24 142848 ----a-w- C:\Windows\SysWow64\igfxcmrt32.dll
2011-03-25 23:28:24 122368 ----a-w- C:\Windows\System32\igfxcmrt64.dll
2011-03-25 21:00:54 252528 ----a-w- C:\Windows\SysWow64\vmnc.dll
2011-03-25 19:05:00 37680 ----a-w- C:\Windows\System32\drivers\vmusb.sys
2011-03-25 19:04:58 56880 ----a-w- C:\Windows\System32\vmnetbridge.dll
2011-03-25 19:04:58 55344 ----a-w- C:\Windows\System32\vnetinst.dll
2011-03-25 19:04:58 45104 ----a-w- C:\Windows\System32\drivers\vmnetbridge.sys
2011-03-25 19:04:58 24112 ----a-w- C:\Windows\System32\drivers\vmnet.sys
2011-03-25 19:04:58 20016 ----a-w- C:\Windows\System32\drivers\vmnetadapter.sys
2011-03-21 12:22:06 74272 ----a-w- C:\Windows\System32\RtNicProp64.dll
2011-03-21 12:22:06 452200 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2011-03-21 12:22:06 107552 ----a-w- C:\Windows\System32\RTNUninst64.dll
2011-03-12 12:08:49 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 11:23:45 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-11 06:41:37 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 06:33:29 2565632 ----a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 ----a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-11 05:33:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-07 02:08:13 93552 ----a-w- C:\Windows\SysWow64\ElbyCDIO.dll
2011-03-07 00:52:09 134512 ----a-w- C:\Windows\SysWow64\ElbyVCD.dll
.
============= FINISH: 17:49:11.83 ===============
Attatch.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-03.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 05/05/2011 20:03:44
System Uptime: 03/06/2011 16:17:08 (1 hours ago)
.
Motherboard: Dell Inc. | | 0NJT03
Processor: Intel(R) Core(TM) i7-2820QM CPU @ 2.30GHz | CPU | 782/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 452 GiB total, 324.444 GiB free.
D: is FIXED (NTFS) - 14 GiB total, 7.456 GiB free.
E: is CDROM ()
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: Windows Firewall Authorization Driver
Device ID: ROOT\LEGACY_MPSDRV\0000
Manufacturer:
Name: Windows Firewall Authorization Driver
PNP Device ID: ROOT\LEGACY_MPSDRV\0000
Service: mpsdrv
.
==== System Restore Points ===================
.
RP1: 03/06/2011 15:58:46 - ComboFix created restore point
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Community Help
Adobe Creative Suite 5 Master Collection
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Advanced Audio FX Engine
Apple Application Support
Apple Software Update
avast! Free Antivirus
Camera Control Pro 2
CyberLink PowerDVD 9.5
D3DX10
Dell Webcam Central
EditPlus 3
Fallout New Vegas
FileZilla Client 3.4.0
Google Chrome
Google Update Helper
Intel(R) Processor Graphics
Junk Mail filter update
Live! Cam Avatar Creator
Logitech Touch Mouse Server 1.0
Malwarebytes' Anti-Malware version 1.51.0.1200
Microsoft Office 2010
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox 4.0.1 (x86 en-GB)
MSVCRT
MSVCRT_amd64
NVIDIA 3D Vision Controller Driver
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
PDF Settings CS5
QuickTime
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Roxio Burn
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Skype™ 5.3
Steam
tools-freebsd
tools-linux
tools-netware
tools-solaris
tools-windows
tools-winPre2k
VirtualCloneDrive
VLC media player 1.1.9
VMware Workstation
Winamp
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
31/05/2011 01:35:01, Error: Microsoft Antimalware [3002] -
31/05/2011 01:23:07, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache ElbyCDIO MpFilter spldr Wanarpv6
31/05/2011 01:02:19, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
31/05/2011 00:52:18, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service NVSvc with arguments "" in order to run the server: {DCAB0989-1301-4319-BE5F-ADE89F88581C}
31/05/2011 00:50:53, Error: Service Control Manager [7023] - The Server service terminated with the following error: The service has not been started.
31/05/2011 00:50:46, Error: Service Control Manager [7023] - The Security Center service terminated with the following error: The authentication service is unknown.
31/05/2011 00:31:25, Error: Service Control Manager [7031] - The VMware vCenter Converter Standalone Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
31/05/2011 00:31:20, Error: Service Control Manager [7034] - The VMware vCenter Converter Standalone Worker service terminated unexpectedly. It has done this 1 time(s).
30/05/2011 16:15:27, Error: Service Control Manager [7034] - The FAService service terminated unexpectedly. It has done this 1 time(s).
03/06/2011 15:28:44, Error: Service Control Manager [7001] - The Windows Firewall service depends on the Windows Firewall Authorization Driver service which failed to start because of the following error: Cannot create a file when that file already exists.
03/06/2011 15:28:44, Error: Service Control Manager [7000] - The Windows Firewall Authorization Driver service failed to start due to the following error: Cannot create a file when that file already exists.
03/06/2011 15:09:42, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 126
03/06/2011 13:10:27, Error: BTHUSB [17] - The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.
03/06/2011 13:06:42, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
03/06/2011 12:18:03, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
03/06/2011 11:30:21, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
03/06/2011 11:30:21, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
03/06/2011 11:20:56, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
03/06/2011 11:20:56, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
03/06/2011 11:20:55, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
03/06/2011 11:20:50, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
03/06/2011 11:20:36, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
03/06/2011 11:20:18, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache ElbyCDIO spldr Wanarpv6
03/06/2011 11:03:38, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
03/06/2011 09:40:00, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service VSS with arguments "" in order to run the server: {E579AB5F-1CC4-44B4-BED9-DE0991FF0623}
.
==== End Of File ===========================
All and any help appreciated - I have most tools at the ready.
RVee