Solved Trojan.Inject.ED and Rootkit fun...

OTL Extras logfile created on: 2/24/2014 1:10:58 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Sederien\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16750)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

15.91 Gb Total Physical Memory | 13.11 Gb Available Physical Memory | 82.39% Memory free
31.83 Gb Paging File | 28.86 Gb Available in Paging File | 90.69% Paging File free
Paging file location(s): c:\pagefile.sys 16296 16296 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 238.47 Gb Total Space | 58.38 Gb Free Space | 24.48% Space Free | Partition Type: NTFS
Drive D: | 238.47 Gb Total Space | 23.32 Gb Free Space | 9.78% Space Free | Partition Type: NTFS
Drive F: | 2794.39 Gb Total Space | 414.67 Gb Free Space | 14.84% Space Free | Partition Type: NTFS

Computer Name: KAESIA | User Name: Sederien | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{086F7DDC-C5D8-46D8-B1FF-0D039B027D7E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2367FB9D-7709-4135-856E-E17E2045E58E}" = lport=445 | protocol=6 | dir=in | app=system |
"{289AAC39-F723-47F7-8110-E0D5EA00470A}" = lport=139 | protocol=6 | dir=in | app=system |
"{2CE0E23F-6CDC-4846-9AFC-A0005526815D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{58486348-0835-4478-A408-9880D50A28AA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6BB215F1-7E61-4230-BC1E-A7347AC5D80D}" = lport=137 | protocol=17 | dir=in | app=system |
"{7CAF155C-F19C-4ECB-ABB5-7AD9ADAAF249}" = rport=138 | protocol=17 | dir=out | app=system |
"{C50675B7-9850-476E-85BD-C6CEF5026DAB}" = rport=445 | protocol=6 | dir=out | app=system |
"{CDFC1F36-478E-43DD-A528-ADCE0B274650}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D049BCD6-4598-463D-9178-C41E7E550FCA}" = rport=139 | protocol=6 | dir=out | app=system |
"{D68742C9-725F-45EB-9065-084337F7977A}" = lport=138 | protocol=17 | dir=in | app=system |
"{E89010C8-FAA2-4605-A618-A33E90C3401D}" = rport=137 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0EF4358D-9E27-4D69-9225-DCC65335D48D}" = protocol=17 | dir=in | app=d:\steam\steam.exe |
"{1F5E9FE6-A664-4BBE-9454-AF65E2454827}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2F5E32B5-F5DB-4263-9D11-57E8642D8D23}" = protocol=6 | dir=in | app=d:\steam\steam.exe |
"{9FDB30E4-059E-4F6D-911B-720BC8BD450B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{CB898FFE-7A4A-4440-96C2-BA48EE65287E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{FB352301-01FE-4AF7-AE14-E2B3C7ADDC09}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"TCP Query User{0B53FC34-123C-44DF-8548-BBFF21CD4E4E}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{2B96A5B2-5506-494C-ACFE-EE17F177E453}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86417045FF}" = Java 7 Update 45 (64-bit)
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5182C87B-E21F-4191-A22F-7A7FF46405CC}" = AmrAddonInstall
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{61271900-d6b0-4da5-801b-7127a8713df1}.sdb" = Thief 3 Sneaky Upgrade SDB
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 RC
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 331.93
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 331.93
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 331.93
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.8.2
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 331.93
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.13.0725
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 11.10.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamC" = GeForce Experience NvStream Client Components
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.24.2
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 11.10.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.20
"{D9C50188-12D5-4D3E-8F00-682346C2AA5F}" = Microsoft Xbox 360 Accessories 1.2
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{E102B843-786A-4F58-AF75-6504570E207B}" = Microsoft Security Client
"{E70808B9-78FE-3081-9658-A3C9DBC9A798}" = Microsoft .NET Framework 4.5.1 RC
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F680D3CF-B171-45C7-A150-B000708117D2}" = Ask Mr. Robot
"CDisplayEx_is1" = CDisplayEx 1.10.2
"C-Media Oxygen HD Audio Driver" = ASUS Xonar Essence STX Audio Driver
"Explorer Suite_is1" = Explorer Suite III
"Microsoft Security Client" = Microsoft Security Essentials
"Newsbin6" = Newsbin Pro
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"VLC media player" = VLC media player 2.1.3
"WinRAR archiver" = WinRAR 5.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{2205B8AE-490E-43F2-AB43-C13C2BEC86A7}" = DDS Thumbnail Viewer
"{23D683DD-93C6-48E6-B84E-78B57778F126}" = Oblivion - Construction Set
"{2687340C-C114-47DC-9F0E-C1BA85FEB001}" = POWERPREP II
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 45
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}" = Brother MFL-Pro Suite DCP-7065DN
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1" = CloudReading
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.7
"{64963F0E-03F2-4B59-8D1B-1806545E7092}" = NVIDIA DDS Utilities
"{6787B847-DE1D-4B75-AF7F-9F0B0FF9E59E}_is1" = Thief 3 Sneaky Upgrade version 1.1.2.1
"{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1" = Auslogics Duplicate File Finder
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B5AA67E-FEA0-40BB-BAB5-CA56645A589C}" = NVIDIA PhysX
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{859A0578-D1B9-41FC-863C-636140BF0089}" = MPGUI
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{998C9435-DAF8-4BDF-B9A5-F844B01D524C}_is1" = TCPEye 1.0
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ae5d246d-bfd3-485c-b4f4-3e2bfa07f706}" = Ask Mr. Robot
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{E0955568-4353-4C85-8988-285A8C0F5E87}" = Mumble 1.2.4
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F187D064-F101-4E95-8D05-4027809AA0F8}" = Avid License Control
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Battle.net" = Battle.net
"Cantabile 2.0 Lite (x64)" = Cantabile 2.0 Lite (x64)
"DAEMON Tools Lite" = DAEMON Tools Lite
"F-Gen Drivers 1.0.0.0 1.0.0.0 " = F-Gen Drivers 1.0.0.0
"Foxit Reader_is1" = Foxit Reader
"Google Chrome" = Google Chrome
"GPL Ghostscript 8.56" = GPL Ghostscript 8.56
"GPL Ghostscript Fonts" = GPL Ghostscript Fonts
"Hearthstone" = Hearthstone
"HOD" = HOD
"Ivellon_is1" = Ivellon 1.5 English
"MakeMKV" = MakeMKV v1.8.8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Mozilla Firefox 27.0.1 (x86 en-US)" = Mozilla Firefox 27.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MuseScore" = MuseScore 1.3
"Neuratron PhotoScore Ultimate" = Neuratron PhotoScore Ultimate
"NifSkope" = NifSkope (remove only)
"Notepad++" = Notepad++
"Novint - Deus Ex: Human Revolution F-Gen Profile" = Novint - Deus Ex: Human Revolution F-Gen Profile
"Novint - Falcon" = Novint - Falcon
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Oblivion mod manager_is1" = Oblivion mod manager 1.1.12
"OpenAL" = OpenAL
"Origin" = Origin
"RADVideo" = RAD Video Tools
"Razer Game Booster_is1" = Razer Game Booster
"Steam App 105600" = Terraria
"Steam App 107100" = Bastion
"Steam App 109200" = Legend of Fae
"Steam App 111800" = Blocks That Matter
"Steam App 200510" = XCOM: Enemy Unknown
"Steam App 200710" = Torchlight II
"Steam App 206190" = Gunpoint
"Steam App 207610" = The Walking Dead
"Steam App 207750" = Symphony
"Steam App 209000" = Batman™: Arkham Origins
"Steam App 209190" = Stealth Bastard Deluxe
"Steam App 209370" = Analogue: A Hate Story
"Steam App 213850" = Magic 2014
"Steam App 214250" = I Am Alive
"Steam App 216250" = Dead Island Riptide
"Steam App 221040" = Resident Evil 6 / Biohazard 6
"Steam App 221260" = Little Inferno
"Steam App 221640" = Super Hexagon
"Steam App 22330" = The Elder Scrolls IV: Oblivion
"Steam App 230780" = articy:draft SE
"Steam App 238010" = Deus Ex: Human Revolution - Director's Cut
"Steam App 238960" = Path of Exile
"Steam App 239030" = Papers, Please
"Steam App 239350" = Spelunky
"Steam App 241600" = Rogue Legacy
"Steam App 248820" = Risk of Rain
"Steam App 249990" = FORCED
"Steam App 253570" = Gentlemen!
"Steam App 33230" = Assassin's Creed II
"Steam App 43110" = Metro 2033
"Steam App 4540" = Titan Quest
"Steam App 4550" = Titan Quest: Immortal Throne
"Steam App 45500" = Clickr
"Steam App 49520" = Borderlands 2
"Steam App 9200" = RAGE
"Steam App 98800" = Dungeons of Dredmor
"Synthesia" = Synthesia
"Transcribe!_is1" = Transcribe! 8.31
"Uplay" = Uplay
"Windows Grep_is1" = Windows Grep 2.3
"World of Warcraft" = World of Warcraft
"Wrye Bash" = Wrye Bash

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"101a9f93b8f0bb6f" = Curse Client
"DMG Extractor" = DMG Extractor

< End of report >
 
All processes killed
========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\zh_TW folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\zh_CN folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\vi folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\ur folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\uk folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\tr folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\th folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\sv folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\sr folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\sl folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\sk folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\ru folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\ro folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\pt_PT folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\pt_BR folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\pl folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\nl folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\nb folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\ms folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\lv folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\lt folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\ko folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\ja folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\it folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\id folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\hu folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\hr folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\hi folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\he folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\fr folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\fi folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\fa folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\et folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\es folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\en_GB folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\en folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\el folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\de folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\da folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\cs folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\ca folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\bn folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\bg folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\be folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales\ar folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\_locales folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\scripts folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\common\skin\img folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\common\skin\css folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\common\skin folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\common\scripts folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\common\mocks folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\common\libs folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\common folder moved successfully.
C:\Users\Sederien\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0 folder moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Nvtmru deleted successfully.
C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs folder moved successfully.
C:\ProgramData\AVAST Software\Persistent Data\Avast folder moved successfully.
C:\ProgramData\AVAST Software\Persistent Data folder moved successfully.
C:\ProgramData\AVAST Software folder moved successfully.
ADS C:\Windows\Deus Ex: Human Revolution F-Gen Profile Setup Log.txt deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File\Folder C:\FRST not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
User: Sederien
->Temp folder emptied: 2222098 bytes
->Temporary Internet Files folder emptied: 25574579 bytes
->Java cache emptied: 2096414 bytes
->FireFox cache emptied: 423815786 bytes
->Google Chrome cache emptied: 27397065 bytes
->Flash cache emptied: 266095 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 602112 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6580 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33298 bytes
RecycleBin emptied: 140162 bytes
Total Files Cleaned = 460.00 mb
[EMPTYJAVA]
User: All Users
User: Default
User: Default User
User: Public
User: Sederien
->Java cache emptied: 0 bytes
Total Java Files Cleaned = 0.00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: Public
User: Sederien
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 02242014_133704

Files\Folders moved on Reboot...
C:\Users\Sederien\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
 
Results of screen317's Security Check version 0.99.79
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Windows Firewall Disabled!
Microsoft Security Essentials
(On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 45
Java version out of Date!
Adobe Flash Player 11.9.900.152
Mozilla Firefox (27.0.1)
Google Chrome 32.0.1700.107
Google Chrome 33.0.1750.117
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 44% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
 
Farbar Service Scanner Version: 16-02-2014
Ran by Sederien (administrator) on 24-02-2014 at 13:45:13
Running from "C:\Users\Sederien\Desktop"
Microsoft Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
 
ESET is still scanning, but likely to take >12 hours at the rate it's going.

No threats detected on either of the main drives. Only going through the 3TB backup drive now with too many archives to count. Likely to find a couple of inert threats considering the age of the drive, but I don't expect any problems dealing with them.

The computer is back on the net and TCPEye is reporting no additional strange connections aside from one or two explorer.exe to the Netherlands in the initial hour, but nothing since. (Those may be legit established connections of some kind... Unsure.)
 
10 HOURS LATER:

F:\Backup01\GameDesktop070728\Desktop070127\Setup_20070121.zip a variant of Generik.GGVHPRK trojan deleted - quarantined
F:\Deskdown2012\Shockwave_Installer_Slim.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application deleted - quarantined
F:\Downloads\duplicate-file-finder-setup.exe a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application deleted - quarantined
F:\Downloads\FoxitReader602.0413_enu_Setup.exe a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application deleted - quarantined
F:\Downloads\WinZip175.exe a variant of Win32/OpenInstall potentially unwanted application deleted - quarantined
F:\Old Drives\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\5c373f97-656f7410 multiple threats cleaned by deleting - quarantined
F:\Transcend\Deskdown090701\siw.exe a variant of Win32/RemoteAdmin.RemoteExec.AA potentially unsafe application deleted - quarantined
F:\Transcend\Gamedown111119\cpu-z_1.58-setup-en.exe a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application deleted - quarantined
F:\Transcend\Gamedown111119\siw-setup.exe Win32/InstallMonetizer.AF potentially unwanted application deleted - quarantined
 
Also, it would seem that while the system has had a thorough scrubbing, there's still a few attempted or possible connections that occur from time to time:

YGPcib8.png


Wondering if a deeper scan is needed or with the proper firewall filters these can safely be ignored...
 
Uh-yup... looks like we're not done. Here's the protection log from Malwarebytes:

2014/02/25 08:21:24 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:21:48 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:22:29 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:22:45 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:22:53 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:23:25 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:23:57 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:24:13 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:25:33 -0600 IP-BLOCK 178.152.13.34 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:26:45 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:27:17 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:27:33 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:27:57 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:28:37 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:29:09 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:29:33 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:29:41 -0600 IP-BLOCK 93.183.203.244 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:29:57 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:30:21 -0600 IP-BLOCK 89.28.48.250 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:33:49 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:34:05 -0600 IP-BLOCK 41.203.69.5 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:36:21 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:37:09 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:37:33 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:39:01 -0600 IP-BLOCK 89.28.48.231 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:39:01 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:39:33 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:46:05 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:46:37 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:47:09 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:47:41 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:47:57 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:48:29 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 08:49:01 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:01:41 -0600 IP-BLOCK 89.28.24.72 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:03:34 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:03:42 -0600 IP-BLOCK 89.28.122.226 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:04:22 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:04:30 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:04:54 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:05:34 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:05:50 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:05:58 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:06:14 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:06:30 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:06:46 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:08:54 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:09:42 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:10:14 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:10:30 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:10:46 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:11:02 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:11:58 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:11:58 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:12:06 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:12:14 -0600 IP-BLOCK 89.28.66.198 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:14:38 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:14:54 -0600 IP-BLOCK 194.143.137.103 (Type: outgoing, Port: 6881, Process: explorer.exe)
2014/02/25 09:14:54 -0600 IP-BLOCK 41.203.83.74 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:15:02 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:15:18 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:15:34 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:18:30 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:18:30 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:18:30 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:20:30 -0600 IP-BLOCK 79.135.134.101 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:20:46 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:20:54 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:21:18 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:21:26 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:21:58 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:22:38 -0600 IP-BLOCK 89.28.112.131 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:22:46 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:23:02 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:23:10 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:23:18 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:23:26 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:24:54 -0600 IP-BLOCK 89.28.89.107 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:25:02 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:25:10 -0600 IP-BLOCK 89.28.24.72 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:27:18 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:30:06 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:30:31 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:31:11 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:31:35 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:31:51 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:35:35 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:36:31 -0600 IP-BLOCK 109.163.230.138 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:38:47 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:39:43 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:40:07 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:45:19 -0600 IP-BLOCK 89.28.24.72 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:48:07 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:48:15 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:48:31 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:49:03 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:49:27 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:49:43 -0600 IP-BLOCK 91.203.146.230 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:49:51 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:50:31 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:54:31 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:55:19 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:56:07 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:56:47 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:57:03 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:57:11 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:57:27 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:57:43 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:58:23 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:58:47 -0600 IP-BLOCK 89.28.67.51 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 09:58:55 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:04:16 -0600 IP-BLOCK 79.135.143.62 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:06:16 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:06:48 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:07:52 -0600 IP-BLOCK 85.234.169.40 (Type: outgoing, Port: 6881, Process: explorer.exe)
2014/02/25 10:08:08 -0600 IP-BLOCK 89.28.27.240 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:09:04 -0600 IP-BLOCK 89.28.100.252 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:09:12 -0600 IP-BLOCK 222.186.19.21 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:11:20 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:11:44 -0600 IP-BLOCK 89.28.24.72 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:12:00 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:12:08 -0600 IP-BLOCK 89.28.125.117 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:12:56 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:14:17 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:20:25 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:21:05 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:21:37 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:22:01 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:27:21 -0600 IP-BLOCK 121.10.160.226 (Type: outgoing, Port: 6881, Process: explorer.exe)
2014/02/25 10:28:49 -0600 IP-BLOCK 219.146.179.162 (Type: outgoing, Port: 6881, Process: explorer.exe)
2014/02/25 10:32:33 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:32:57 -0600 IP-BLOCK 213.55.112.178 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:33:13 -0600 IP-BLOCK 89.28.24.72 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:33:13 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:38:57 -0600 IP-BLOCK 219.152.144.160 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:39:13 -0600 IP-BLOCK 91.188.36.80 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:39:45 -0600 IP-BLOCK 121.10.236.154 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:40:17 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:41:45 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:43:21 -0600 IP-BLOCK 93.103.86.12 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:46:41 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:47:05 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:47:46 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:48:10 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:51:38 -0600 IP-BLOCK 89.28.99.49 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:53:06 -0600 IP-BLOCK 89.28.68.159 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 10:59:46 -0600 IP-BLOCK 195.216.178.8 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:00:58 -0600 IP-BLOCK 89.28.62.121 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:03:54 -0600 IP-BLOCK 89.28.8.63 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:06:26 -0600 IP-BLOCK 93.183.194.74 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:07:30 -0600 IP-BLOCK 89.28.54.180 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:08:34 -0600 IP-BLOCK 222.186.19.16 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:08:50 -0600 IP-BLOCK 222.186.19.16 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:08:50 -0600 IP-BLOCK 89.28.54.41 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:13:23 -0600 IP-BLOCK 91.188.38.54 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:15:39 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:15:47 -0600 IP-BLOCK 89.28.68.159 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:16:11 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:16:27 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:16:35 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:18:59 -0600 IP-BLOCK 79.135.134.101 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:21:23 -0600 IP-BLOCK 93.115.82.54 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:22:19 -0600 IP-BLOCK 89.28.54.180 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:22:27 -0600 IP-BLOCK 94.102.48.43 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:22:59 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:23:16 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:23:32 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:26:12 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:26:44 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:31:16 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:31:48 -0600 IP-BLOCK 222.186.19.7 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:32:20 -0600 IP-BLOCK 89.28.99.49 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:35:24 -0600 IP-BLOCK 89.28.103.11 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:37:32 -0600 IP-BLOCK 91.188.38.54 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:40:45 -0600 IP-BLOCK 41.203.69.5 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:43:17 -0600 IP-BLOCK 176.120.38.238 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:44:37 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:50:53 -0600 IP-BLOCK 89.28.54.41 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:51:57 -0600 IP-BLOCK 212.113.40.56 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:54:37 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:54:53 -0600 IP-BLOCK 218.10.63.2 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:55:09 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 11:59:26 -0600 IP-BLOCK 89.209.91.187 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:02:30 -0600 IP-BLOCK 79.135.143.62 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:03:50 -0600 IP-BLOCK 89.209.91.187 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:05:02 -0600 IP-BLOCK 89.248.172.103 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:08:14 -0600 IP-BLOCK 89.28.116.223 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:15:02 -0600 IP-BLOCK 89.28.47.216 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:15:10 -0600 IP-BLOCK 93.103.86.215 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:18:47 -0600 IP-BLOCK 89.209.91.187 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:19:03 -0600 IP-BLOCK 89.28.78.254 (Type: outgoing, Port: 6881, Process: explorer.exe)
2014/02/25 12:19:19 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:19:27 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:20:15 -0600 IP-BLOCK 79.135.134.101 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:21:19 -0600 IP-BLOCK 89.28.68.159 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:23:27 -0600 IP-BLOCK 79.135.141.6 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:29:03 -0600 IP-BLOCK 91.188.38.54 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:33:43 -0600 IP-BLOCK 89.209.91.187 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:44:23 -0600 IP-BLOCK 89.28.68.159 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:44:31 -0600 IP-BLOCK 89.28.8.178 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:44:31 -0600 IP-BLOCK 59.34.120.5 (Type: outgoing, Port: 6881, Process: explorer.exe)
2014/02/25 12:46:31 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:46:55 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:47:11 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:47:20 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:48:48 -0600 IP-BLOCK 89.209.91.187 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:49:04 -0600 IP-BLOCK 91.188.38.54 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:50:40 -0600 IP-BLOCK 79.135.134.101 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 12:55:28 -0600 IP-BLOCK 89.28.48.214 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:00:48 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:02:00 -0600 IP-BLOCK 78.26.179.106 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:03:04 -0600 IP-BLOCK 194.143.137.142 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:03:28 -0600 IP-BLOCK 121.10.220.74 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:03:36 -0600 IP-BLOCK 121.10.220.74 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:03:36 -0600 IP-BLOCK 89.209.91.187 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:03:44 -0600 IP-BLOCK 79.135.143.62 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:05:52 -0600 IP-BLOCK 89.28.68.159 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:08:56 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:09:36 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:09:52 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:10:00 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:14:00 -0600 IP-BLOCK 91.188.38.54 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:14:08 -0600 IP-BLOCK 89.28.62.121 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:17:44 -0600 IP-BLOCK 222.186.19.12 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:18:32 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:18:40 -0600 IP-BLOCK 89.209.91.187 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:18:56 -0600 IP-BLOCK 222.186.19.12 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:18:56 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:19:12 -0600 IP-BLOCK 79.135.134.101 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:19:12 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:19:28 -0600 IP-BLOCK 89.28.82.165 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:24:17 -0600 IP-BLOCK 89.28.15.3 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:24:49 -0600 IP-BLOCK 222.186.19.3 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:25:53 -0600 IP-BLOCK 222.186.19.3 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:26:09 -0600 IP-BLOCK 89.28.118.62 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:26:25 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:26:57 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:27:37 -0600 IP-BLOCK 89.28.68.159 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:27:37 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:28:09 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:31:05 -0600 IP-BLOCK 77.78.245.20 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:31:21 -0600 IP-BLOCK 89.28.78.229 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:32:57 -0600 IP-BLOCK 89.28.68.120 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:33:05 -0600 IP-BLOCK 79.135.143.62 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:33:21 -0600 IP-BLOCK 81.163.138.187 (Type: outgoing, Port: 6881, Process: explorer.exe)
2014/02/25 13:33:37 -0600 IP-BLOCK 89.209.91.187 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:33:45 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:34:01 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:34:17 -0600 IP-BLOCK 222.186.19.15 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:35:29 -0600 IP-BLOCK 89.28.62.121 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:36:57 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:37:21 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:40:39 -0600 DETECTION C:\ProgramData\Microsoft\Crypto\RSA64\temp\tmpD246.exe Trojan.Crypt.NKN QUARANTINE
2014/02/25 13:43:05 -0600 IP-BLOCK 91.188.38.54 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:45:37 -0600 IP-BLOCK 219.153.191.32 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:45:53 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:46:33 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:47:13 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:47:37 -0600 IP-BLOCK 222.186.19.18 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:48:34 -0600 IP-BLOCK 89.209.91.187 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:48:58 -0600 IP-BLOCK 89.28.68.159 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:50:02 -0600 IP-BLOCK 79.135.134.101 (Type: incoming, Port: 6881, Process: explorer.exe)
2014/02/25 13:50:18 -0600 IP-BLOCK 89.28.118.62 (Type: incoming, Port: 6881, Process: explorer.exe)

----

Can't imagine a person actively trying to hack into my machine personally, but likely some kind of script? Note the new trojan detected an few minutes ago.
 
I added some stricter firewall rules and enabled a secondary wall on the router. Seems clean thus far... probably need to rescan everything, though. :D
 
Those are incoming attempts.
Every computer will have them listed.
By enabling router's firewall (which is always a good idea) those attempts are being stopped at router level so MBAM has no chance to see them.
In your first screenshot those 3 connections listed at the bottom were never marked as established so basically there was no connection.

Unless you're experiencing some issues....

redtarget.gif
Update Adobe Flash Player: http://get.adobe.com/flashplayer/
Make sure you UN-check Yes, install McAfee Security Scan Plus

NOTE 1: Beginning with Adobe Flash Version 11.3, the universal installer includes the 32-bit and 64-bit versions of the Flash Player.
NOTE 2: While installing make sure you UN-check any extra garbage which wants to install alongside.

redtarget.gif
1. Update your Java version here: https://www.techspot.com/downloads/6463-java-se.html
Alternate download: http://www.java.com/en/download/manual.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

Note 3: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

2. Now, we need to remove old Java version and its remnants...

Download JavaRa to your desktop and unzip it.
  • Run JavaRa.exe (Vista and 7 users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Do NOT post JavaRa log.

=====================================

Your computer is clean

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download
51a5ce45263de-delfix.png
DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.

3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

4. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

11. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

12. Please, let me know, how your computer is doing.
 
So far so good.

Thank you again for all your help, Broni. I'll open a new topic if anything new crops up, but otherwise the machine does appear to be in working order once again.
 
Back