Alistair Wilson
Posts: 35 +0
Help!
Like many others I clicked on some Adobe Flash update and ended up with Sirefef and a machine that reboot every minute. Any assistance from the experts here appreciated.
My FRST logs is attached ... Thanks in advance
Scan result of Farbar Recovery Scan Tool Version: 09-08-2012
Ran by SYSTEM at 10-08-2012 16:53:54
Running from H:\
Windows 7 Enterprise Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [617120 2011-03-13] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [379552 2011-03-13] (Atheros Commnucations)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [LifeChat] "C:\Program Files\Microsoft LifeChat\LifeChat.exe" [371712 2009-09-24] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [x]
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [446392 2012-04-03] (Adobe Systems Incorporated)
HKLM\...\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" [1873256 2011-08-10] (Microsoft Corporation)
HKLM\...\Run: [VIRTU] C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.Exe /hide [2593568 2012-04-22] ()
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [170264 2012-03-19] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [398616 2012-03-19] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [439064 2012-03-19] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [6548112 2012-06-12] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORDTSUPTBT [1212560 2012-06-13] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [MSUTray] C:\Program Files (x86)\Marvell\storage\tray\MarvellTray.exe [1199144 2010-11-18] ()
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-10-17] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [115048 2011-09-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] ()
HKLM-x32\...\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [375000 2009-10-26] (DeviceVM, Inc.)
HKLM-x32\...\Run: [ASUS ShellProcess Execute] C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe [252544 2011-06-14] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 10\MMReminderService.exe [37728 2011-09-14] (Mindjet)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-07-15] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [azontop100analyzer] C:\Program Files (x86)\AzonTop100Analyzer\azontop100analyzer.exe [44474097 2012-06-09] ()
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM-x32\...\Run: [DNS7reminder] "C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini [330 2012-08-10] ()
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103576 2012-06-08] (VMware, Inc.)
HKLM-x32\...\Run: [PowerSEORanker] "C:\Program Files (x86)\Power SEO Ranker\PowerSEORanker.exe" [1222144 2012-07-29] (Evergreen Internet Marketers)
HKLM-x32\...\Run: [Everything] "C:\Program Files (x86)\Everything\Everything.exe" -startup [602624 2009-03-12] ()
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-04-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun [143360 2012-06-14] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN [2629632 2011-05-18] (Brother Industries, Ltd.)
HKU\Alistair\...\Run: [IBP] [x]
HKU\Alistair\...\Run: [InputDirector] "C:\Program Files (x86)\Input Director\InputDirector.exe" /hide [593920 2011-12-14] (Imperative Software Pty Ltd)
HKU\Alistair\...\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot [3491264 2012-06-06] (Tonec Inc.)
HKU\Alistair\...\Run: [Ditto] C:\Program Files\Ditto\Ditto.exe [1620480 2012-01-03] ()
HKU\Alistair\...\Run: [X1FileMonitor.exe] C:\PROGRA~2\X1\X1FileMonitor.exe [400024 2012-06-06] (X1 Technologies, Inc.)
HKU\Alistair\...\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-07-15] ()
HKU\Alistair\...\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload [975800 2012-07-15] (Samsung)
HKU\Alistair\...\Run: [AdobeBridge] [x]
HKU\Alistair\...\Run: [rkisc] rundll32.exe "C:\Users\Alistair\AppData\Roaming\rkisc.dll",Backup [161792 2012-08-10] (Crytek)
HKU\UpdatusUser\...\Run: [Antivirus] C:\Cache\checker.exe [x]
HKU\UpdatusUser\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized [17417392 2012-07-03] (Skype Technologies S.A.)
HKU\UpdatusUser\...\Run: [BandwidthMonitor] C:\Program Files (x86)\BandwidthMonitor\BWMonitor.exe [585728 2011-01-18] (BWMONITOR.COM)
HKU\UpdatusUser\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [880496 2012-05-11] (BitTorrent, Inc.)
HKU\UpdatusUser\...\Run: [InputDirector] "C:\Program Files (x86)\Input Director\InputDirector.exe" /hide [593920 2011-12-14] (Imperative Software Pty Ltd)
HKU\UpdatusUser\...\Run: [NetLimiter] C:\Program Files\NetLimiter 3\NLClientApp.exe /tray [x]
HKU\UpdatusUser\...\Run: [Actual Window Manager] "C:\Program Files (x86)\Actual Window Manager\ActualWindowManagerCenter.exe" [x]
HKU\UpdatusUser\...\Run: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [109336 2012-06-15] (Siber Systems)
HKU\UpdatusUser\...\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot [3491264 2012-06-06] (Tonec Inc.)
HKU\UpdatusUser\...\Run: [IBP] [x]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
AppInit_DLLs: C:\Windows\system32\appinit_dll.dll
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\CaptchaInfinity.exe - Shortcut.lnk
ShortcutTarget: CaptchaInfinity.exe - Shortcut.lnk -> C:\Program Files (x86)\CaptchaInfinity\CaptchaInfinity.exe (Asta Services)
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\HMA Pro VPN 2.0.lnk
ShortcutTarget: HMA Pro VPN 2.0.lnk -> C:\Program Files (x86)\HMA! Pro VPN\bin\HMA! Pro VPN.exe (NetcoSolutions)
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\X1 System Tray.lnk
ShortcutTarget: X1 System Tray.lnk -> C:\Program Files (x86)\X1\X1Systray.exe (X1 Technologies, Inc.)
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\X1.lnk
ShortcutTarget: X1.lnk -> C:\Program Files (x86)\X1\X1.exe (X1 Technologies, Inc.)
==================== Services (Whitelisted) ======
2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [918144 2010-11-03] ()
2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [915584 2011-06-10] ()
2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [586880 2011-06-14] ()
2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Commnucations)
2 BCUService; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [223464 2009-10-26] (DeviceVM, Inc.)
2 DragonSvc; C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe [296808 2010-07-23] (Nuance Communications, Inc.)
2 DTSAudioService; "C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe" [210024 2011-05-30] (DTS)
3 Futuremark SystemInfo Service; "C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe" [130976 2011-03-01] (Futuremark Corporation)
3 IDVistaService; C:\Program Files (x86)\Input Director\IDVistaService.exe [13824 2010-07-20] ()
2 InputDirector; C:\Program Files (x86)\Input Director\IDWinService.exe [36864 2011-12-14] ()
2 IxiaEndpoint; "C:\Program Files\Ixia\Endpoint\endpoint.exe" [481280 2010-11-14] (Ixia)
2 Marvell Storage Management; C:\Program Files (x86)\Marvell\storage\svc\mvraidsvc.exe [345640 2010-11-24] (Marvell)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 MSUWebService; "C:\Program Files (x86)\Marvell\storage\Apache2\bin\httpd.exe" -k runservice [24645 2010-09-01] (Apache Software Foundation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 OpenVPNService; "C:\Program Files (x86)\HMA! Pro VPN\bin\openvpnserv.exe" [36352 2011-07-13] ()
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [225672 2007-05-31] (Microsoft Corporation)
3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2011.SP2b\RpcAgentSrv.exe [93848 2009-08-10] (SiSoftware)
2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe [186760 2012-07-19] ()
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-07-24] ()
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [443784 2007-05-31] (Microsoft Corporation)
2 WuerthUpdateSvc; C:\Program Files (x86)\Würth Bemessung\Würth Update\WuerthUpdateService.exe [3333296 2012-05-23] ()
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
========================== Drivers (Whitelisted) =============
1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [13440 2011-06-14] ()
1 AsUpIO; C:\Windows\SysWow64\Drivers\AsUpIO.sys [14464 2011-06-14] ()
3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [36000 2011-03-13] (Atheros)
3 ATHDFU; C:\Windows\System32\Drivers\ATHDFU.sys [51872 2011-03-13] (Windows (R) Win 7 DDK provider)
3 BTATH_A2DP; C:\Windows\System32\Drivers\BTATH_A2DP.sys [298656 2011-03-13] (Atheros)
3 BTATH_BUS; C:\Windows\System32\Drivers\BTATH_BUS.sys [28832 2011-03-13] (Atheros)
3 BTATH_HCRP; C:\Windows\System32\Drivers\BTATH_HCRP.sys [201376 2011-03-13] (Atheros)
3 BTATH_LWFLT; C:\Windows\System32\Drivers\BTATH_LWFLT.sys [55456 2011-03-13] (Atheros)
3 BTATH_RCP; C:\Windows\System32\Drivers\BTATH_RCP.sys [154272 2011-03-13] (Atheros)
3 BtFilter; C:\Windows\System32\Drivers\BtFilter.sys [280224 2011-03-13] (Atheros)
2 CipcCdp; C:\Windows\System32\Drivers\CipcCdp.sys [27392 2011-01-24] (Cisco Systems)
1 HCW88AUD; C:\Windows\System32\Drivers\HCW88AUD.sys [16128 2010-08-16] (Hauppauge Computer Works, Inc)
3 HCW88BDA; C:\Windows\System32\Drivers\HCW88BDA.sys [259456 2010-08-16] (Hauppauge Computer Works, Inc)
3 HCW88TSE; C:\Windows\System32\Drivers\HCW88TSE.sys [339968 2010-08-16] (Hauppauge Computer Works, Inc)
3 HCW88TUNE; C:\Windows\System32\drivers\hcw88tun.sys [110592 2010-08-16] (Hauppauge Computer Works, Inc.)
3 hcw88vid; C:\Windows\System32\Drivers\hcw88vid.sys [440064 2010-08-16] (Hauppauge Computer Works, Inc)
3 HCW88XBAR; C:\Windows\System32\drivers\HCW88BAR.sys [21632 2010-08-16] (Hauppauge Computer Works, Inc.)
2 IDMWFP; C:\Windows\System32\Drivers\IDMWFP.sys [154272 2012-04-23] (Tonec Inc.)
3 ivusb; C:\Windows\System32\Drivers\ivusb.sys [29720 2010-07-28] (Initio Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()
0 mv91cons; C:\Windows\System32\Drivers\mv91cons.sys [24880 2011-06-16] (Marvell Semiconductor Inc.)
0 mvs91xx; C:\Windows\System32\Drivers\mvs91xx.sys [313136 2011-06-16] (Marvell Semiconductor, Inc.)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [35344 2011-02-11] (CACE Technologies, Inc.)
3 PcaSp60; C:\Windows\System32\Drivers\PcaSp60.sys [38912 2010-09-07] (Printing Communications Assoc., Inc. (PCAUSA))
3 PcaSp60; C:\Windows\SysWow64\Drivers\PcaSp60.sys [38912 2010-09-07] (Printing Communications Assoc., Inc. (PCAUSA))
2 RtDashPt; C:\Windows\System32\Drivers\RtDashPt.sys [38504 2011-09-19] (Windows (R) Codename Longhorn DDK provider)
3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2011.SP2b\WNt500x64\Sandra.sys [23112 2009-08-07] (SiSoftware)
3 VirtuWDDM; C:\Windows\System32\Drivers\VirtuWDDM.sys [75552 2012-04-22] (Lucidlogix Inc.)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-27] ()
2 iPodDrv; \??\C:\Windows\system32\drivers\iPodDrv.sys [x]
3 NLNdisMP; C:\Windows\System32\DRIVERS\nlndis.sys [x]
3 NLNdisPT; C:\Windows\System32\DRIVERS\nlndis.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
3 WinRing0_1_2_0; \??\C:\Users\Alistair\Desktop\RealTemp_360\WinRing0x64.sys [x]
========================== NetSvcs (Whitelisted) ===========
Like many others I clicked on some Adobe Flash update and ended up with Sirefef and a machine that reboot every minute. Any assistance from the experts here appreciated.
My FRST logs is attached ... Thanks in advance
Scan result of Farbar Recovery Scan Tool Version: 09-08-2012
Ran by SYSTEM at 10-08-2012 16:53:54
Running from H:\
Windows 7 Enterprise Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [617120 2011-03-13] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [379552 2011-03-13] (Atheros Commnucations)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [LifeChat] "C:\Program Files\Microsoft LifeChat\LifeChat.exe" [371712 2009-09-24] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [x]
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [446392 2012-04-03] (Adobe Systems Incorporated)
HKLM\...\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" [1873256 2011-08-10] (Microsoft Corporation)
HKLM\...\Run: [VIRTU] C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.Exe /hide [2593568 2012-04-22] ()
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [170264 2012-03-19] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [398616 2012-03-19] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [439064 2012-03-19] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [6548112 2012-06-12] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORDTSUPTBT [1212560 2012-06-13] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [MSUTray] C:\Program Files (x86)\Marvell\storage\tray\MarvellTray.exe [1199144 2010-11-18] ()
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-10-17] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [115048 2011-09-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] ()
HKLM-x32\...\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [375000 2009-10-26] (DeviceVM, Inc.)
HKLM-x32\...\Run: [ASUS ShellProcess Execute] C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe [252544 2011-06-14] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 10\MMReminderService.exe [37728 2011-09-14] (Mindjet)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-07-15] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [azontop100analyzer] C:\Program Files (x86)\AzonTop100Analyzer\azontop100analyzer.exe [44474097 2012-06-09] ()
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM-x32\...\Run: [DNS7reminder] "C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini [330 2012-08-10] ()
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103576 2012-06-08] (VMware, Inc.)
HKLM-x32\...\Run: [PowerSEORanker] "C:\Program Files (x86)\Power SEO Ranker\PowerSEORanker.exe" [1222144 2012-07-29] (Evergreen Internet Marketers)
HKLM-x32\...\Run: [Everything] "C:\Program Files (x86)\Everything\Everything.exe" -startup [602624 2009-03-12] ()
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-04-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun [143360 2012-06-14] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN [2629632 2011-05-18] (Brother Industries, Ltd.)
HKU\Alistair\...\Run: [IBP] [x]
HKU\Alistair\...\Run: [InputDirector] "C:\Program Files (x86)\Input Director\InputDirector.exe" /hide [593920 2011-12-14] (Imperative Software Pty Ltd)
HKU\Alistair\...\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot [3491264 2012-06-06] (Tonec Inc.)
HKU\Alistair\...\Run: [Ditto] C:\Program Files\Ditto\Ditto.exe [1620480 2012-01-03] ()
HKU\Alistair\...\Run: [X1FileMonitor.exe] C:\PROGRA~2\X1\X1FileMonitor.exe [400024 2012-06-06] (X1 Technologies, Inc.)
HKU\Alistair\...\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-07-15] ()
HKU\Alistair\...\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload [975800 2012-07-15] (Samsung)
HKU\Alistair\...\Run: [AdobeBridge] [x]
HKU\Alistair\...\Run: [rkisc] rundll32.exe "C:\Users\Alistair\AppData\Roaming\rkisc.dll",Backup [161792 2012-08-10] (Crytek)
HKU\UpdatusUser\...\Run: [Antivirus] C:\Cache\checker.exe [x]
HKU\UpdatusUser\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized [17417392 2012-07-03] (Skype Technologies S.A.)
HKU\UpdatusUser\...\Run: [BandwidthMonitor] C:\Program Files (x86)\BandwidthMonitor\BWMonitor.exe [585728 2011-01-18] (BWMONITOR.COM)
HKU\UpdatusUser\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [880496 2012-05-11] (BitTorrent, Inc.)
HKU\UpdatusUser\...\Run: [InputDirector] "C:\Program Files (x86)\Input Director\InputDirector.exe" /hide [593920 2011-12-14] (Imperative Software Pty Ltd)
HKU\UpdatusUser\...\Run: [NetLimiter] C:\Program Files\NetLimiter 3\NLClientApp.exe /tray [x]
HKU\UpdatusUser\...\Run: [Actual Window Manager] "C:\Program Files (x86)\Actual Window Manager\ActualWindowManagerCenter.exe" [x]
HKU\UpdatusUser\...\Run: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [109336 2012-06-15] (Siber Systems)
HKU\UpdatusUser\...\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot [3491264 2012-06-06] (Tonec Inc.)
HKU\UpdatusUser\...\Run: [IBP] [x]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
AppInit_DLLs: C:\Windows\system32\appinit_dll.dll
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\CaptchaInfinity.exe - Shortcut.lnk
ShortcutTarget: CaptchaInfinity.exe - Shortcut.lnk -> C:\Program Files (x86)\CaptchaInfinity\CaptchaInfinity.exe (Asta Services)
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\HMA Pro VPN 2.0.lnk
ShortcutTarget: HMA Pro VPN 2.0.lnk -> C:\Program Files (x86)\HMA! Pro VPN\bin\HMA! Pro VPN.exe (NetcoSolutions)
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\X1 System Tray.lnk
ShortcutTarget: X1 System Tray.lnk -> C:\Program Files (x86)\X1\X1Systray.exe (X1 Technologies, Inc.)
Startup: C:\Users\Alistair\Start Menu\Programs\Startup\X1.lnk
ShortcutTarget: X1.lnk -> C:\Program Files (x86)\X1\X1.exe (X1 Technologies, Inc.)
==================== Services (Whitelisted) ======
2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [918144 2010-11-03] ()
2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [915584 2011-06-10] ()
2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [586880 2011-06-14] ()
2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Commnucations)
2 BCUService; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [223464 2009-10-26] (DeviceVM, Inc.)
2 DragonSvc; C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe [296808 2010-07-23] (Nuance Communications, Inc.)
2 DTSAudioService; "C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe" [210024 2011-05-30] (DTS)
3 Futuremark SystemInfo Service; "C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe" [130976 2011-03-01] (Futuremark Corporation)
3 IDVistaService; C:\Program Files (x86)\Input Director\IDVistaService.exe [13824 2010-07-20] ()
2 InputDirector; C:\Program Files (x86)\Input Director\IDWinService.exe [36864 2011-12-14] ()
2 IxiaEndpoint; "C:\Program Files\Ixia\Endpoint\endpoint.exe" [481280 2010-11-14] (Ixia)
2 Marvell Storage Management; C:\Program Files (x86)\Marvell\storage\svc\mvraidsvc.exe [345640 2010-11-24] (Marvell)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 MSUWebService; "C:\Program Files (x86)\Marvell\storage\Apache2\bin\httpd.exe" -k runservice [24645 2010-09-01] (Apache Software Foundation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 OpenVPNService; "C:\Program Files (x86)\HMA! Pro VPN\bin\openvpnserv.exe" [36352 2011-07-13] ()
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [225672 2007-05-31] (Microsoft Corporation)
3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2011.SP2b\RpcAgentSrv.exe [93848 2009-08-10] (SiSoftware)
2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe [186760 2012-07-19] ()
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-07-24] ()
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [443784 2007-05-31] (Microsoft Corporation)
2 WuerthUpdateSvc; C:\Program Files (x86)\Würth Bemessung\Würth Update\WuerthUpdateService.exe [3333296 2012-05-23] ()
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
========================== Drivers (Whitelisted) =============
1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [13440 2011-06-14] ()
1 AsUpIO; C:\Windows\SysWow64\Drivers\AsUpIO.sys [14464 2011-06-14] ()
3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [36000 2011-03-13] (Atheros)
3 ATHDFU; C:\Windows\System32\Drivers\ATHDFU.sys [51872 2011-03-13] (Windows (R) Win 7 DDK provider)
3 BTATH_A2DP; C:\Windows\System32\Drivers\BTATH_A2DP.sys [298656 2011-03-13] (Atheros)
3 BTATH_BUS; C:\Windows\System32\Drivers\BTATH_BUS.sys [28832 2011-03-13] (Atheros)
3 BTATH_HCRP; C:\Windows\System32\Drivers\BTATH_HCRP.sys [201376 2011-03-13] (Atheros)
3 BTATH_LWFLT; C:\Windows\System32\Drivers\BTATH_LWFLT.sys [55456 2011-03-13] (Atheros)
3 BTATH_RCP; C:\Windows\System32\Drivers\BTATH_RCP.sys [154272 2011-03-13] (Atheros)
3 BtFilter; C:\Windows\System32\Drivers\BtFilter.sys [280224 2011-03-13] (Atheros)
2 CipcCdp; C:\Windows\System32\Drivers\CipcCdp.sys [27392 2011-01-24] (Cisco Systems)
1 HCW88AUD; C:\Windows\System32\Drivers\HCW88AUD.sys [16128 2010-08-16] (Hauppauge Computer Works, Inc)
3 HCW88BDA; C:\Windows\System32\Drivers\HCW88BDA.sys [259456 2010-08-16] (Hauppauge Computer Works, Inc)
3 HCW88TSE; C:\Windows\System32\Drivers\HCW88TSE.sys [339968 2010-08-16] (Hauppauge Computer Works, Inc)
3 HCW88TUNE; C:\Windows\System32\drivers\hcw88tun.sys [110592 2010-08-16] (Hauppauge Computer Works, Inc.)
3 hcw88vid; C:\Windows\System32\Drivers\hcw88vid.sys [440064 2010-08-16] (Hauppauge Computer Works, Inc)
3 HCW88XBAR; C:\Windows\System32\drivers\HCW88BAR.sys [21632 2010-08-16] (Hauppauge Computer Works, Inc.)
2 IDMWFP; C:\Windows\System32\Drivers\IDMWFP.sys [154272 2012-04-23] (Tonec Inc.)
3 ivusb; C:\Windows\System32\Drivers\ivusb.sys [29720 2010-07-28] (Initio Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()
0 mv91cons; C:\Windows\System32\Drivers\mv91cons.sys [24880 2011-06-16] (Marvell Semiconductor Inc.)
0 mvs91xx; C:\Windows\System32\Drivers\mvs91xx.sys [313136 2011-06-16] (Marvell Semiconductor, Inc.)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [35344 2011-02-11] (CACE Technologies, Inc.)
3 PcaSp60; C:\Windows\System32\Drivers\PcaSp60.sys [38912 2010-09-07] (Printing Communications Assoc., Inc. (PCAUSA))
3 PcaSp60; C:\Windows\SysWow64\Drivers\PcaSp60.sys [38912 2010-09-07] (Printing Communications Assoc., Inc. (PCAUSA))
2 RtDashPt; C:\Windows\System32\Drivers\RtDashPt.sys [38504 2011-09-19] (Windows (R) Codename Longhorn DDK provider)
3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2011.SP2b\WNt500x64\Sandra.sys [23112 2009-08-07] (SiSoftware)
3 VirtuWDDM; C:\Windows\System32\Drivers\VirtuWDDM.sys [75552 2012-04-22] (Lucidlogix Inc.)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-27] ()
2 iPodDrv; \??\C:\Windows\system32\drivers\iPodDrv.sys [x]
3 NLNdisMP; C:\Windows\System32\DRIVERS\nlndis.sys [x]
3 NLNdisPT; C:\Windows\System32\DRIVERS\nlndis.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
3 WinRing0_1_2_0; \??\C:\Users\Alistair\Desktop\RealTemp_360\WinRing0x64.sys [x]
========================== NetSvcs (Whitelisted) ===========