Solved WinLock/Windows Explorer Issue

Frood

Posts: 16   +0
Hello all. First time here but from what I have seen so far, you guys do some great work! Thank you, in advance, for taking the time to check out my problem. Here is the situation so far:

We have a shared computer and Tuesday evening my roomate called me in to check the computer out. Screen was taken up with an "announcement" saying that copyrighted items had been downloaded and to please send us money to get control of the pc back. Nothing was responsive at all. I forced a restart and when it came back on and I logged in, the UAC came up asking if Windows Explorer could make changes. When I clicked cancel or just tried to close the dialog box, that seemed to close explorer as well (No desktop icons, start button, taskbar, ect...).

So I then tried it in safe mode and I was able to start the pc fairly normally. As a precaution, I disconnected from the internet from this point forward. First I ran AVG and it found nothing. Next I tried Malwarebytes and it came up with two results: Trojan.Delf and Trojan.Ransom.Gen. I restarted and nothing had changed. Next I manually updated Malwarebytes and AVG and ran both again. AVG returned nothing again but Malwarebytes gave me Trojan.Winlock. I removed and restarted and again, no change. This time I manually updated Spybot as well and ran all three scans again and none of them returned any results. It's at this point that I turn to you for help. I have followed all of the steps listed in the thread above and have all the needed logs. For the Malwarebytes log, I have included the latest one (that returned nothing). Please let me know if you need the others.

Thanks again for your help!

LOGS:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.09.19.10

Windows Vista Service Pack 2 x86 NTFS (Safe Mode)
Internet Explorer 9.0.8112.16421
Admin :: SHIRLEYDIDOM-PC [administrator]

9/19/2012 9:25:17 PM
mbam-log-2012-09-19 (21-25-17).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 447619
Time elapsed: 1 hour(s), 52 minute(s), 57 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-09-20 10:59:52
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST912082 rev.3.CD
Running: tj4gwf6h.exe; Driver: C:\Users\Admin\AppData\Local\Temp\kwryrfod.sys


---- Devices - GMER 1.0.15 ----

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8520D1F8
Device \Driver\iaStor \Device\Ide\iaStor0 [8804BD30] \SystemRoot\system32\drivers\iastor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 8520D1F8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [8804BD30] \SystemRoot\system32\drivers\iastor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\a24n8zdq \Device\Scsi\a24n8zdq1Port3Path0Target0Lun0 8618D1F8
Device \Driver\a24n8zdq \Device\Scsi\a24n8zdq1Port3Path0Target1Lun0 8618D1F8
Device \Driver\a24n8zdq \Device\Scsi\a24n8zdq1 8618D1F8
Device \FileSystem\Ntfs \Ntfs 8520E1F8
Device \FileSystem\fastfat \Fat 86A901F8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.
DDS (Ver_2011-08-26.01) - NTFSx86 MINIMAL
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by Admin at 11:02:17 on 2012-09-20
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1605 [GMT -4:00]
.
AV: a-squared Anti-Malware *Disabled/Updated* {45D82FD7-7300-6110-96D3-6C8EB10A96DD}
AV: AVG Anti-Virus Free *Enabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82}
SP: AVG Anti-Virus Free *Enabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F}
SP: a-squared Anti-Malware *Disabled/Updated* {FEB9CE33-553A-6E9E-AC63-57FCCA8DDC60}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uWindow Title = Internet Explorer provided by Dell
mStart Page = hxxp://www.yahoo.com/
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: URLHooker2 Class: {93935f7f-9c88-42f8-8445-95251d27fabc} - c:\progra~1\flashv~1\URLHOO~1.DLL
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\11.1.0.12\AVG Secure Search_toolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\11.1.0.12\AVG Secure Search_toolbar.dll
TB: {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [PeerBlock] c:\program files\peerblock\peerblock.exe
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [MarbleStation]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EDesksoft Auto Update] c:\program files\edesksoft\update\EDesksoftUpdate.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [VolPanel] "c:\program files\creative\sbaudigy\volume panel\VolPanlu.exe" /r
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [<NO NAME>]
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [dlbkbmgr.exe] "c:\program files\dell aio printer a920\dlbkbmgr.exe"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [VERIZONDM] "c:\program files\verizondm\bin\sprtcmd.exe" /P VERIZONDM
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
mRun: [mylbx] c:\program files\my lockbox\mylbx.exe /a
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [HF_G_Jul] "c:\program files\avg secure search\HF_G_Jul.exe" /DoAction
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
mRunOnce: [InnoSetupRegFile.0000000001] "c:\windows\is-RJP4O.exe" /REG /REGSVRMODE
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "c:\programdata\malwarebytes\malwarebytes' anti-malware\cleanup.dll",ProcessCleanupScript
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
StartupFolder: c:\users\admin\appdata\roaming\micros~1\windows\startm~1\programs\startup\matrix~1.lnk - c:\program files\matrix screen locker\matrix.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-explorer: HideSCAHealth = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: Interfaces\{08566BEC-A3A2-4754-A14F-85673F5C0482} : NameServer = 192.168.1.1
TCP: Interfaces\{FB699354-B8A5-4099-B170-830788B8166C} : NameServer = 192.168.0.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\11.2.0\ViProtocol.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL, avgrsstx.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\admin\appdata\roaming\mozilla\firefox\profiles\vzop9hjr.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\avg secure search\sitesafetyinstaller\11.2.0\npsitesafety.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npff_gdm.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\wildtangent games\app\browserintegration\registered\0\NP_wtapp.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [2012-5-10 41912]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-7-2 218688]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-17 335240]
S1 AvgMfx86;AVG Minifilter x86 Resident Driver;c:\windows\system32\drivers\avgmfx86.sys [2007-10-22 27784]
S2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared anti-malware\a2service.exe [2008-8-4 980512]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2007-12-6 73728]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-6-17 297752]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 dlbk_device;dlbk_device;c:\windows\system32\dlbkcoms.exe -service --> c:\windows\system32\dlbkcoms.exe -service [?]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-10-6 21504]
S2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\verizondm\bin\sprtsvc.exe [2011-2-1 206120]
S2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\verizondm\bin\tgsrvc.exe [2011-2-1 185640]
S2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\11.2.0\ToolbarUpdater.exe [2012-7-9 935008]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg8\toolbar\ToolbarBroker.exe [2010-10-26 167264]
S3 GamesAppService;GamesAppService;c:\program files\wildtangent games\app\GamesAppService.exe [2010-10-12 206072]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-8-4 113120]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-6-19 20080]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-10-6 16896]
.
=============== Created Last 30 ================
.
2012-09-20 00:10:25 -------- d-sh--w- C:\found.001
2012-09-19 03:20:45 -------- d-sh--w- C:\found.000
2012-09-16 20:02:01 -------- d-----w- c:\programdata\Bilbo
2012-09-16 01:21:07 -------- d-----w- c:\program files\Horror Palace
2012-09-09 17:42:40 -------- d-----w- c:\program files\McPixel
2012-09-05 09:56:50 -------- d-----w- c:\program files\common files\Oberon Media
2012-09-05 09:56:25 -------- d-----w- c:\programdata\Oberon Media
2012-09-05 09:55:44 -------- d-----w- c:\program files\Oberon Media
.
==================== Find3M ====================
.
2012-08-16 14:57:03 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-16 14:57:03 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-11 02:09:09 711240 ----a-w- c:\windows\is-RJP4O.exe
.
============= FINISH: 11:04:32.77 ===============
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 8/29/2007 3:43:47 AM
System Uptime: 9/20/2012 10:28:13 AM (1 hours ago)
.
Motherboard: Dell Inc. | | 0KU927
Processor: Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz | Microprocessor | 1495/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 99 GiB total, 2.478 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 4.924 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is CDROM ()
H: is CDROM ()
I: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e96d-e325-11ce-bfc1-08002be10318}
Description: Conexant HDA D330 MDC V.92 Modem
Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_14F1000F&REV_1000\4&69A777E&0&0102
Manufacturer: Conexant
Name: Conexant HDA D330 MDC V.92 Modem
PNP Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_14F1000F&REV_1000\4&69A777E&0&0102
Service: Modem
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
µTorrent
4 Elements
Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.5.2
Adobe Shockwave Player 11.5
Apple Software Update
Aspell English Dictionary-0.50-2
AVG Free 8.5
Bejeweled 2 Deluxe
Broadcom Management Programs
CDisplay 1.8
Conexant HDA D330 MDC V.92 Modem
Creative MediaSource 5
DAEMON Tools Lite
Dell AIO Printer A920
Dell Support Center (Support Software)
Dell System Customization Wizard
Dell Touchpad
Dell Wireless WLAN Card
DellSupport
Digital Line Detect
Disc2Phone
Exact Audio Copy 0.95b3
FLAC 1.2.0a (remove only)
foobar2000 v0.9.5.5
FoxyTunes for Firefox
FreeRIP v3.45
GNU Aspell 0.50-3
GTK+ Runtime 2.14.7 rev a (remove only)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Inpaint
Java Auto Updater
Java(TM) 6 Update 30
Java(TM) 7 Update 5
JavaFX 2.1.1
Malwarebytes Anti-Malware version 1.61.0.1400
Matrix Screen Locker 1.44
McPixel version 1.0.4
MediaDirect
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Reader
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Works
Modem Diagnostic Tool
Mozilla Firefox 14.0.1 (x86 en-US)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
My Lockbox 2.8.2
NetWaiting
NVIDIA PhysX
OpenOffice.org 3.3
OutlookAddinSetup
PeerBlock 1.1 (r518)
Pidgin
Product Documentation Launcher
Putrid Putters
QuickSet
QuickTime
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler
Roxio MyDVD DE
Roxio Update Manager
screensaver_crop
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition
SigmaTel Audio
Sonic Activation Module
Sony Ericsson Device Data
Sony Ericsson PC Suite
Sound Blaster Audigy ADVANCED MB
Sound Editor Deluxe v3.9
Spybot - Search & Destroy
System Requirements Lab
TagScanner 5.1 build 592
The Lord of the Rings Online™: Mines of Moria™ v02.01.03.4021
The Simpsons Hit & Run(TM)
Total Privacy 5
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687267) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update Installer for WildTangent Games App
User's Guides
VC80CRTRedist - 8.0.50727.6195
Ventrilo Client
Verizon Download Manager
Visual C++ 8.0 Runtime Setup Package
VLC media player 2.0.2
Windows Live ID Sign-in Assistant
WinRAR archiver
WinUtilities 6.4
WinZip 14.0
Yahoo! Messenger
.
==== Event Viewer Messages From Past Week ========
.
9/20/2012 10:44:51 AM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {C2BFE331-6739-4270-86C9-493D9A04CD38}. The error: "2" Happened while starting this command: C:\Windows\system32\igfxsrvc.exe -Embedding
9/20/2012 10:44:51 AM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C}. The error: "2" Happened while starting this command: C:\Windows\system32\igfxsrvc.exe -Embedding
9/20/2012 10:36:06 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
9/20/2012 10:36:04 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
9/20/2012 10:35:30 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
9/20/2012 10:35:30 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
9/20/2012 10:35:30 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
9/20/2012 10:35:26 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/20/2012 10:35:13 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
9/20/2012 10:31:11 AM, Error: Service Control Manager [7001] - The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD ASPI32 AvgLdx86 AvgMfx86 DfsC NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr tdx Wanarpv6 ws2ifsl
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
9/20/2012 10:30:15 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
9/20/2012 10:29:08 AM, Error: EventLog [6008] - The previous system shutdown at 10:27:34 AM on 9/20/2012 was unexpected.
9/20/2012 10:27:33 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
9/20/2012 10:25:48 AM, Error: EventLog [6008] - The previous system shutdown at 10:21:03 AM on 9/20/2012 was unexpected.
9/20/2012 10:02:02 AM, Error: EventLog [6008] - The previous system shutdown at 1:41:57 AM on 9/20/2012 was unexpected.
9/19/2012 8:14:51 PM, Error: EventLog [6008] - The previous system shutdown at 8:00:48 PM on 9/19/2012 was unexpected.
9/19/2012 6:01:00 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume OS.
9/19/2012 5:10:45 AM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {C332C124-340D-4430-AA0D-C75602876FCC}. The error: "2" Happened while starting this command: C:\Windows\system32\igfxsrvc.exe -Embedding
9/19/2012 5:07:28 AM, Error: EventLog [6008] - The previous system shutdown at 1:30:16 AM on 9/19/2012 was unexpected.
9/19/2012 4:08:31 PM, Error: Service Control Manager [7034] - The Windows Search service terminated unexpectedly. It has done this 3 time(s).
9/19/2012 4:08:31 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
9/19/2012 4:06:50 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
9/19/2012 4:06:14 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
9/19/2012 4:06:14 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/19/2012 4:06:13 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
9/19/2012 4:05:52 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
9/19/2012 4:05:00 PM, Error: EventLog [6008] - The previous system shutdown at 4:02:27 PM on 9/19/2012 was unexpected.
9/19/2012 4:03:20 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
9/19/2012 3:44:18 PM, Error: EventLog [6008] - The previous system shutdown at 3:42:02 PM on 9/19/2012 was unexpected.
9/19/2012 10:56:13 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
9/19/2012 10:21:51 AM, Error: EventLog [6008] - The previous system shutdown at 10:19:51 AM on 9/19/2012 was unexpected.
9/19/2012 1:26:29 PM, Error: EventLog [6008] - The previous system shutdown at 1:24:07 PM on 9/19/2012 was unexpected.
9/19/2012 1:22:39 AM, Error: EventLog [6008] - The previous system shutdown at 12:28:13 AM on 9/19/2012 was unexpected.
9/18/2012 11:25:26 PM, Error: EventLog [6008] - The previous system shutdown at 11:11:32 PM on 9/18/2012 was unexpected.
9/18/2012 11:06:43 PM, Error: EventLog [6008] - The previous system shutdown at 10:58:38 PM on 9/18/2012 was unexpected.
.
==== End Of File ===========================

There they are!! Thanks again for taking the time!
 
Welcome aboard
yahooo.gif


Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

=======================================

Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.

=======================================

  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • Wait until the Status box shows Scan Finished
  • Click on Delete.
  • Wait until the Status box shows Deleting Finished.
  • Click on Report and copy/paste the content of the Notepad into your next reply.
  • RKreport.txt could also be found on your desktop.
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

====================================

Download aswMBR to your desktop.
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
 
Heya. Thanks for getting back to me so quickly! Here are the logs you requested:

13:33:43.0346 0604 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
13:33:43.0361 0604 ============================================================
13:33:43.0361 0604 Current date / time: 2012/09/20 13:33:43.0361
13:33:43.0361 0604 SystemInfo:
13:33:43.0361 0604
13:33:43.0361 0604 OS Version: 6.0.6002 ServicePack: 2.0
13:33:43.0361 0604 Product type: Workstation
13:33:43.0361 0604 ComputerName: SHIRLEYDIDOM-PC
13:33:43.0361 0604 UserName: Admin
13:33:43.0361 0604 Windows directory: C:\Windows
13:33:43.0361 0604 System windows directory: C:\Windows
13:33:43.0361 0604 Processor architecture: Intel x86
13:33:43.0361 0604 Number of processors: 2
13:33:43.0361 0604 Page size: 0x1000
13:33:43.0361 0604 Boot type: Safe boot
13:33:43.0361 0604 ============================================================
13:33:43.0783 0604 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:33:43.0783 0604 Drive \Device\Harddisk1\DR3 - Size: 0xF900000 (0.24 Gb), SectorSize: 0x200, Cylinders: 0x1F, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:33:43.0783 0604 ============================================================
13:33:43.0783 0604 \Device\Harddisk0\DR0:
13:33:43.0783 0604 MBR partitions:
13:33:43.0783 0604 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2B800, BlocksNum 0x1400000
13:33:43.0783 0604 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x142B800, BlocksNum 0xC668800
13:33:43.0814 0604 \Device\Harddisk1\DR3:
13:33:43.0814 0604 MBR partitions:
13:33:43.0814 0604 \Device\Harddisk1\DR3\Partition1: MBR, Type 0x6, StartLBA 0x20, BlocksNum 0x7C7C0
13:33:43.0814 0604 ============================================================
13:33:43.0861 0604 C: <-> \Device\Harddisk0\DR0\Partition2
13:33:43.0892 0604 D: <-> \Device\Harddisk0\DR0\Partition1
13:33:43.0892 0604 ============================================================
13:33:43.0892 0604 Initialize success
13:33:43.0892 0604 ============================================================
13:33:51.0271 1356 ============================================================
13:33:51.0271 1356 Scan started
13:33:51.0271 1356 Mode: Manual;
13:33:51.0271 1356 ============================================================
13:33:51.0473 1356 ================ Scan system memory ========================
13:33:51.0473 1356 System memory - ok
13:33:51.0489 1356 ================ Scan services =============================
13:33:51.0661 1356 [ 59F9459B6ACC6811F0DB81D44EA53647 ] a2AntiMalware C:\Program Files\a-squared Anti-Malware\a2service.exe
13:33:51.0707 1356 a2AntiMalware - ok
13:33:51.0910 1356 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
13:33:51.0926 1356 ACPI - ok
13:33:51.0973 1356 [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:33:52.0004 1356 adp94xx - ok
13:33:52.0066 1356 [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:33:52.0066 1356 adpahci - ok
13:33:52.0097 1356 [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
13:33:52.0097 1356 adpu160m - ok
13:33:52.0113 1356 [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:33:52.0129 1356 adpu320 - ok
13:33:52.0175 1356 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:33:52.0175 1356 AeLookupSvc - ok
13:33:52.0222 1356 [ EF1142512BEC12F1C2C87735DA1755BE ] AESTFilters C:\Windows\system32\aestsrv.exe
13:33:52.0222 1356 AESTFilters - ok
13:33:52.0285 1356 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
13:33:52.0300 1356 AFD - ok
13:33:52.0363 1356 [ 8B10CE1C1F9F1D47E4DEB1A547A00CD4 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:33:52.0363 1356 agp440 - ok
13:33:52.0394 1356 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
13:33:52.0409 1356 aic78xx - ok
13:33:52.0441 1356 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
13:33:52.0456 1356 ALG - ok
13:33:52.0472 1356 [ 5C42A992E68724D2CD3DDB4FC3B0409F ] aliide C:\Windows\system32\drivers\aliide.sys
13:33:52.0472 1356 aliide - ok
13:33:52.0487 1356 [ 848F27E5B27C1C253F6CEFDC1A5D8F21 ] amdagp C:\Windows\system32\drivers\amdagp.sys
13:33:52.0503 1356 amdagp - ok
13:33:52.0550 1356 [ 849DFACDDE533DA5D1810F0CAF84EB19 ] amdide C:\Windows\system32\drivers\amdide.sys
13:33:52.0550 1356 amdide - ok
13:33:52.0581 1356 [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
13:33:52.0581 1356 AmdK7 - ok
13:33:52.0628 1356 [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:33:52.0628 1356 AmdK8 - ok
13:33:52.0690 1356 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
13:33:52.0690 1356 Appinfo - ok
13:33:52.0721 1356 [ 5F673180268BB1FDB69C99B6619FE379 ] arc C:\Windows\system32\drivers\arc.sys
13:33:52.0721 1356 arc - ok
13:33:52.0737 1356 [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:33:52.0737 1356 arcsas - ok
13:33:52.0862 1356 [ B979979AB8027F7F53FB16EC4229B7DB ] ASPI32 C:\Windows\system32\drivers\ASPI32.sys
13:33:52.0862 1356 ASPI32 - ok
13:33:52.0955 1356 [ 40C145F12FF461A0220303BDA134F598 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
13:33:52.0955 1356 aspnet_state - ok
13:33:53.0002 1356 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:33:53.0002 1356 AsyncMac - ok
13:33:53.0049 1356 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
13:33:53.0049 1356 atapi - ok
13:33:53.0127 1356 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:33:53.0143 1356 AudioEndpointBuilder - ok
13:33:53.0143 1356 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:33:53.0158 1356 Audiosrv - ok
13:33:53.0314 1356 [ D45B7995761253A92AB071D576114F28 ] AVG Security Toolbar Service C:\Program Files\AVG\AVG8\Toolbar\ToolbarBroker.exe
13:33:53.0314 1356 AVG Security Toolbar Service - ok
13:33:53.0423 1356 [ DB338A6BD3976904EB0F8343F51E64EB ] avg8wd C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
13:33:53.0423 1356 avg8wd - ok
13:33:53.0470 1356 [ BC12F2404BB6F2B6B2FF3C4C246CB752 ] AvgLdx86 C:\Windows\System32\Drivers\avgldx86.sys
13:33:53.0486 1356 AvgLdx86 - ok
13:33:53.0533 1356 [ 5903D729D4F0C5BCA74123C96A1B29E0 ] AvgMfx86 C:\Windows\System32\Drivers\avgmfx86.sys
13:33:53.0533 1356 AvgMfx86 - ok
13:33:53.0611 1356 [ 746F59822A5187510471FC46889B8CC9 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
13:33:53.0642 1356 BCM43XX - ok
13:33:53.0673 1356 [ CD4646067CC7DCBA1907FA0ACF7E3966 ] bcm4sbxp C:\Windows\system32\DRIVERS\bcm4sbxp.sys
13:33:53.0673 1356 bcm4sbxp - ok
13:33:53.0751 1356 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
13:33:53.0751 1356 Beep - ok
13:33:53.0813 1356 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
13:33:53.0813 1356 BFE - ok
13:33:53.0891 1356 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
13:33:53.0938 1356 BITS - ok
13:33:53.0938 1356 blbdrive - ok
13:33:54.0001 1356 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:33:54.0016 1356 bowser - ok
13:33:54.0047 1356 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
13:33:54.0047 1356 BrFiltLo - ok
13:33:54.0063 1356 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
13:33:54.0063 1356 BrFiltUp - ok
13:33:54.0110 1356 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
13:33:54.0110 1356 Browser - ok
13:33:54.0141 1356 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
13:33:54.0157 1356 Brserid - ok
13:33:54.0188 1356 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
13:33:54.0188 1356 BrSerWdm - ok
13:33:54.0219 1356 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
13:33:54.0219 1356 BrUsbMdm - ok
13:33:54.0235 1356 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
13:33:54.0235 1356 BrUsbSer - ok
13:33:54.0266 1356 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
13:33:54.0266 1356 BTHMODEM - ok
13:33:54.0328 1356 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:33:54.0328 1356 cdfs - ok
13:33:54.0359 1356 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:33:54.0359 1356 cdrom - ok
13:33:54.0437 1356 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
13:33:54.0437 1356 CertPropSvc - ok
13:33:54.0453 1356 [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass C:\Windows\system32\drivers\circlass.sys
13:33:54.0453 1356 circlass - ok
13:33:54.0500 1356 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
13:33:54.0515 1356 CLFS - ok
13:33:54.0562 1356 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:33:54.0562 1356 clr_optimization_v2.0.50727_32 - ok
13:33:54.0671 1356 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:33:54.0671 1356 clr_optimization_v4.0.30319_32 - ok
13:33:54.0765 1356 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
13:33:54.0765 1356 CmBatt - ok
13:33:54.0781 1356 [ DE11A06E187756ECB86CFA82DAC40FF7 ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:33:54.0781 1356 cmdide - ok
13:33:54.0812 1356 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
13:33:54.0812 1356 Compbatt - ok
13:33:54.0827 1356 COMSysApp - ok
13:33:54.0859 1356 [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:33:54.0859 1356 crcdisk - ok
13:33:54.0952 1356 [ 0C629820AAD9C90E456B221C94D640CA ] Creative Labs Licensing Service C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
13:33:54.0952 1356 Creative Labs Licensing Service - ok
13:33:54.0999 1356 [ 3C8B6609712F4FF78E521F6DCFC4032B ] Creative Service for CDROM Access C:\Windows\system32\CTsvcCDA.exe
13:33:54.0999 1356 Creative Service for CDROM Access - ok
13:33:55.0030 1356 [ 22A7F883508176489F559EE745B5BF5D ] Crusoe C:\Windows\system32\drivers\crusoe.sys
13:33:55.0030 1356 Crusoe - ok
13:33:55.0077 1356 [ 75C6A297E364014840B48ECCD7525E30 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:33:55.0093 1356 CryptSvc - ok
13:33:55.0171 1356 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:33:55.0217 1356 DcomLaunch - ok
13:33:55.0249 1356 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:33:55.0249 1356 DfsC - ok
13:33:55.0373 1356 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
13:33:55.0451 1356 DFSR - ok
13:33:55.0529 1356 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
13:33:55.0561 1356 Dhcp - ok
13:33:55.0592 1356 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
13:33:55.0592 1356 disk - ok
13:33:55.0639 1356 dlbk_device - ok
13:33:55.0701 1356 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:33:55.0701 1356 Dnscache - ok
13:33:55.0748 1356 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
13:33:55.0763 1356 dot3svc - ok
13:33:55.0810 1356 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
13:33:55.0826 1356 DPS - ok
13:33:55.0888 1356 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:33:55.0888 1356 drmkaud - ok
13:33:55.0951 1356 [ 245F62A2AA67F4A61F10174BF1017327 ] DSBrokerService C:\Program Files\DellSupport\brkrsvc.exe
13:33:55.0951 1356 DSBrokerService - ok
13:33:56.0044 1356 [ 413F2D5F9D802688242C23B38F767ECB ] DSproct C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
13:33:56.0044 1356 DSproct - ok
13:33:56.0091 1356 [ DFEABB7CFFFADEA4A912AB95BDC3177A ] dsunidrv C:\Windows\system32\DRIVERS\dsunidrv.sys
13:33:56.0091 1356 dsunidrv - ok
13:33:56.0138 1356 [ 555E54AC2F601A8821CEF58961653991 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
13:33:56.0138 1356 dtsoftbus01 - ok
13:33:56.0200 1356 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:33:56.0216 1356 DXGKrnl - ok
13:33:56.0263 1356 [ 7505290504C8E2D172FA378CC0497BCC ] e1express C:\Windows\system32\DRIVERS\e1e6032.sys
13:33:56.0263 1356 e1express - ok
13:33:56.0294 1356 [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
13:33:56.0309 1356 E1G60 - ok
13:33:56.0325 1356 EagleNT - ok
13:33:56.0387 1356 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
13:33:56.0403 1356 EapHost - ok
13:33:56.0465 1356 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
13:33:56.0465 1356 Ecache - ok
13:33:56.0559 1356 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:33:56.0559 1356 ehRecvr - ok
13:33:56.0590 1356 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
13:33:56.0590 1356 ehSched - ok
13:33:56.0606 1356 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
13:33:56.0606 1356 ehstart - ok
13:33:56.0653 1356 [ E8F3F21A71720C84BCF423B80028359F ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:33:56.0653 1356 elxstor - ok
13:33:56.0731 1356 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
13:33:56.0777 1356 EMDMgmt - ok
13:33:56.0840 1356 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
13:33:56.0855 1356 EventSystem - ok
13:33:56.0887 1356 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
13:33:56.0902 1356 exfat - ok
13:33:56.0933 1356 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:33:56.0949 1356 fastfat - ok
13:33:56.0980 1356 [ 63BDADA84951B9C03E641800E176898A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:33:56.0980 1356 fdc - ok
13:33:57.0027 1356 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
13:33:57.0027 1356 fdPHost - ok
13:33:57.0058 1356 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
13:33:57.0074 1356 FDResPub - ok
13:33:57.0121 1356 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:33:57.0121 1356 FileInfo - ok
13:33:57.0183 1356 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:33:57.0183 1356 Filetrace - ok
13:33:57.0199 1356 [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:33:57.0214 1356 flpydisk - ok
13:33:57.0245 1356 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:33:57.0261 1356 FltMgr - ok
13:33:57.0339 1356 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
13:33:57.0370 1356 FontCache - ok
13:33:57.0448 1356 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:33:57.0448 1356 FontCache3.0.0.0 - ok
13:33:57.0511 1356 [ 3528C9EC493CA524A877D217C7D51600 ] FSProFilter C:\Windows\system32\Drivers\FSPFltd.sys
13:33:57.0511 1356 FSProFilter - ok
13:33:57.0542 1356 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:33:57.0542 1356 Fs_Rec - ok
13:33:57.0589 1356 [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:33:57.0589 1356 gagp30kx - ok
13:33:57.0713 1356 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files\WildTangent Games\App\GamesAppService.exe
13:33:57.0713 1356 GamesAppService - ok
13:33:57.0760 1356 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
13:33:57.0791 1356 gpsvc - ok
13:33:57.0854 1356 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:33:57.0854 1356 HdAudAddService - ok
13:33:57.0901 1356 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:33:57.0916 1356 HDAudBus - ok
13:33:57.0947 1356 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:33:57.0947 1356 HidBth - ok
13:33:57.0963 1356 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
13:33:57.0963 1356 HidIr - ok
13:33:58.0010 1356 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
13:33:58.0010 1356 hidserv - ok
13:33:58.0088 1356 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:33:58.0088 1356 HidUsb - ok
13:33:58.0135 1356 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:33:58.0150 1356 hkmsvc - ok
13:33:58.0181 1356 [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
13:33:58.0181 1356 HpCISSs - ok
13:33:58.0259 1356 [ E9E589C9AB799F52E18F057635A2B362 ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
13:33:58.0306 1356 HSF_DPV - ok
13:33:58.0353 1356 [ 7845D2385F4DC7DFB3CCAF0C2FA4948E ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
13:33:58.0353 1356 HSXHWAZL - ok
13:33:58.0400 1356 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:33:58.0400 1356 HTTP - ok
13:33:58.0447 1356 [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp C:\Windows\system32\drivers\i2omp.sys
13:33:58.0447 1356 i2omp - ok
13:33:58.0525 1356 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:33:58.0525 1356 i8042prt - ok
13:33:58.0587 1356 [ FD7F9D74C2B35DBDA400804A3F5ED5D8 ] iaStor C:\Windows\system32\drivers\iastor.sys
13:33:58.0587 1356 iaStor - ok
13:33:58.0618 1356 [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
13:33:58.0618 1356 iaStorV - ok
13:33:58.0712 1356 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
13:33:58.0712 1356 IDriverT - ok
13:33:58.0790 1356 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:33:58.0821 1356 idsvc - ok
13:33:58.0915 1356 [ F7ECD4B9E7FAD4A01A0ED889D40E2494 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
13:33:58.0961 1356 igfx - ok
13:33:58.0977 1356 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:33:58.0993 1356 iirsp - ok
13:33:59.0039 1356 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
13:33:59.0055 1356 IKEEXT - ok
13:33:59.0102 1356 [ 1B16626BEAE3A52E611FC681CD796F86 ] intelide C:\Windows\system32\DRIVERS\intelide.sys
13:33:59.0102 1356 intelide - ok
13:33:59.0164 1356 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:33:59.0164 1356 intelppm - ok
13:33:59.0211 1356 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:33:59.0227 1356 IPBusEnum - ok
13:33:59.0273 1356 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:33:59.0273 1356 IpFilterDriver - ok
13:33:59.0305 1356 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:33:59.0320 1356 iphlpsvc - ok
13:33:59.0336 1356 IpInIp - ok
13:33:59.0383 1356 [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
13:33:59.0383 1356 IPMIDRV - ok
13:33:59.0429 1356 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
13:33:59.0429 1356 IPNAT - ok
13:33:59.0476 1356 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:33:59.0476 1356 IRENUM - ok
13:33:59.0492 1356 [ 2F8ECE2699E7E2070545E9B0960A8ED2 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:33:59.0507 1356 isapnp - ok
13:33:59.0570 1356 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:33:59.0570 1356 iScsiPrt - ok
13:33:59.0617 1356 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
13:33:59.0617 1356 iteatapi - ok
13:33:59.0648 1356 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
13:33:59.0648 1356 iteraid - ok
13:33:59.0710 1356 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:33:59.0710 1356 kbdclass - ok
13:33:59.0726 1356 [ D2600CB17B7408B4A83F231DC9A11AC3 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:33:59.0726 1356 kbdhid - ok
13:33:59.0773 1356 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
13:33:59.0773 1356 KeyIso - ok
13:33:59.0835 1356 [ 2B2F1638466E8CB091400C9019CC730E ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:33:59.0866 1356 KSecDD - ok
13:33:59.0929 1356 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:33:59.0960 1356 KtmRm - ok
13:33:59.0991 1356 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll
13:34:00.0022 1356 LanmanServer - ok
13:34:00.0069 1356 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:34:00.0100 1356 LanmanWorkstation - ok
13:34:00.0194 1356 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:34:00.0194 1356 lltdio - ok
13:34:00.0241 1356 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:34:00.0256 1356 lltdsvc - ok
13:34:00.0303 1356 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:34:00.0303 1356 lmhosts - ok
13:34:00.0365 1356 [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:34:00.0365 1356 LSI_FC - ok
13:34:00.0381 1356 [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:34:00.0381 1356 LSI_SAS - ok
13:34:00.0412 1356 [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:34:00.0412 1356 LSI_SCSI - ok
13:34:00.0475 1356 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
13:34:00.0475 1356 luafv - ok
13:34:00.0506 1356 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:34:00.0506 1356 Mcx2Svc - ok
13:34:00.0537 1356 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
13:34:00.0553 1356 mdmxsdk - ok
13:34:00.0584 1356 [ D153B14FC6598EAE8422A2037553ADCE ] megasas C:\Windows\system32\drivers\megasas.sys
13:34:00.0599 1356 megasas - ok
13:34:00.0709 1356 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
13:34:00.0709 1356 Microsoft Office Groove Audit Service - ok
13:34:00.0755 1356 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
13:34:00.0755 1356 MMCSS - ok
13:34:00.0802 1356 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
13:34:00.0818 1356 Modem - ok
13:34:00.0849 1356 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:34:00.0849 1356 monitor - ok
13:34:00.0896 1356 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:34:00.0896 1356 mouclass - ok
13:34:00.0943 1356 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:34:00.0958 1356 mouhid - ok
13:34:01.0005 1356 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
13:34:01.0005 1356 MountMgr - ok
13:34:01.0099 1356 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:34:01.0099 1356 MozillaMaintenance - ok
13:34:01.0145 1356 [ 583A41F26278D9E0EA548163D6139397 ] mpio C:\Windows\system32\drivers\mpio.sys
13:34:01.0145 1356 mpio - ok
13:34:01.0177 1356 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:34:01.0192 1356 mpsdrv - ok
13:34:01.0255 1356 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
13:34:01.0270 1356 MpsSvc - ok
13:34:01.0286 1356 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
13:34:01.0301 1356 Mraid35x - ok
13:34:01.0348 1356 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:34:01.0348 1356 MRxDAV - ok
13:34:01.0395 1356 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:34:01.0411 1356 mrxsmb - ok
13:34:01.0426 1356 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:34:01.0442 1356 mrxsmb10 - ok
13:34:01.0442 1356 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:34:01.0442 1356 mrxsmb20 - ok
13:34:01.0489 1356 [ 0D1C042188FFE61A702A9DF5944DE5BA ] msahci C:\Windows\system32\drivers\msahci.sys
13:34:01.0489 1356 msahci - ok
13:34:01.0504 1356 [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:34:01.0504 1356 msdsm - ok
13:34:01.0551 1356 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
13:34:01.0567 1356 MSDTC - ok
13:34:01.0629 1356 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:34:01.0645 1356 Msfs - ok
13:34:01.0676 1356 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:34:01.0676 1356 msisadrv - ok
13:34:01.0723 1356 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:34:01.0738 1356 MSiSCSI - ok
13:34:01.0738 1356 msiserver - ok
13:34:01.0785 1356 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:34:01.0785 1356 MSKSSRV - ok
13:34:01.0801 1356 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:34:01.0801 1356 MSPCLOCK - ok
13:34:01.0816 1356 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:34:01.0816 1356 MSPQM - ok
13:34:01.0832 1356 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:34:01.0847 1356 MsRPC - ok
13:34:01.0863 1356 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:34:01.0863 1356 mssmbios - ok
13:34:01.0894 1356 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:34:01.0894 1356 MSTEE - ok
13:34:01.0941 1356 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
13:34:01.0957 1356 Mup - ok
13:34:02.0003 1356 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
13:34:02.0035 1356 napagent - ok
13:34:02.0081 1356 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:34:02.0081 1356 NativeWifiP - ok
13:34:02.0159 1356 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:34:02.0175 1356 NDIS - ok
13:34:02.0222 1356 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:34:02.0222 1356 NdisTapi - ok
13:34:02.0269 1356 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:34:02.0284 1356 Ndisuio - ok
13:34:02.0347 1356 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:34:02.0347 1356 NdisWan - ok
13:34:02.0393 1356 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:34:02.0409 1356 NDProxy - ok
13:34:02.0440 1356 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:34:02.0440 1356 NetBIOS - ok
13:34:02.0503 1356 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
13:34:02.0503 1356 netbt - ok
13:34:02.0549 1356 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
13:34:02.0549 1356 Netlogon - ok
13:34:02.0612 1356 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
13:34:02.0627 1356 Netman - ok
13:34:02.0705 1356 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
13:34:02.0721 1356 netprofm - ok
13:34:02.0752 1356 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:34:02.0752 1356 NetTcpPortSharing - ok
13:34:02.0815 1356 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:34:02.0815 1356 nfrd960 - ok
13:34:02.0861 1356 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:34:02.0877 1356 NlaSvc - ok
13:34:02.0924 1356 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:34:02.0924 1356 Npfs - ok
13:34:02.0924 1356 npggsvc - ok
13:34:02.0971 1356 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
13:34:02.0986 1356 nsi - ok
13:34:03.0033 1356 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:34:03.0033 1356 nsiproxy - ok
13:34:03.0111 1356 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:34:03.0189 1356 Ntfs - ok
13:34:03.0220 1356 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
13:34:03.0220 1356 ntrigdigi - ok
13:34:03.0251 1356 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
13:34:03.0251 1356 Null - ok
13:34:03.0267 1356 [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:34:03.0267 1356 nvraid - ok
13:34:03.0314 1356 [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:34:03.0314 1356 nvstor - ok
13:34:03.0329 1356 [ 055081FD5076401C1EE1BCAB08D81911 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:34:03.0345 1356 nv_agp - ok
13:34:03.0345 1356 NwlnkFlt - ok
13:34:03.0361 1356 NwlnkFwd - ok
13:34:03.0470 1356 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
13:34:03.0470 1356 odserv - ok
13:34:03.0548 1356 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
13:34:03.0548 1356 ohci1394 - ok
13:34:03.0595 1356 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:34:03.0595 1356 ose - ok
13:34:03.0657 1356 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
13:34:03.0719 1356 p2pimsvc - ok
13:34:03.0766 1356 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
13:34:03.0782 1356 p2psvc - ok
13:34:03.0829 1356 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
13:34:03.0829 1356 Parport - ok
13:34:03.0875 1356 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:34:03.0875 1356 partmgr - ok
13:34:03.0891 1356 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
13:34:03.0907 1356 Parvdm - ok
13:34:04.0000 1356 [ 2F6E885C432927A186C2E352C8A1CBF4 ] pbfilter C:\Program Files\PeerBlock\pbfilter.sys
13:34:04.0000 1356 pbfilter - ok
13:34:04.0047 1356 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
13:34:04.0063 1356 PcaSvc - ok
13:34:04.0109 1356 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
13:34:04.0109 1356 pci - ok
13:34:04.0141 1356 [ 1636D43F10416AEB483BC6001097B26C ] pciide C:\Windows\system32\drivers\pciide.sys
13:34:04.0141 1356 pciide - ok
13:34:04.0187 1356 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
13:34:04.0187 1356 pcmcia - ok
13:34:04.0265 1356 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:34:04.0312 1356 PEAUTH - ok
13:34:04.0406 1356 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
13:34:04.0499 1356 pla - ok
13:34:04.0562 1356 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:34:04.0577 1356 PlugPlay - ok
13:34:04.0624 1356 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
13:34:04.0640 1356 PNRPAutoReg - ok
13:34:04.0702 1356 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
13:34:04.0718 1356 PNRPsvc - ok
13:34:04.0765 1356 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:34:04.0765 1356 PolicyAgent - ok
13:34:04.0827 1356 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:34:04.0827 1356 PptpMiniport - ok
13:34:04.0858 1356 [ 0E3CEF5D28B40CF273281D620C50700A ] Processor C:\Windows\system32\drivers\processr.sys
13:34:04.0874 1356 Processor - ok
13:34:04.0889 1356 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
13:34:04.0905 1356 ProfSvc - ok
13:34:04.0936 1356 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
13:34:04.0952 1356 ProtectedStorage - ok
13:34:04.0999 1356 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
13:34:04.0999 1356 PSched - ok
13:34:05.0030 1356 [ FEFFCFDC528764A04C8ED63D5FA6E711 ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
13:34:05.0045 1356 PxHelp20 - ok
13:34:05.0108 1356 [ CCDAC889326317792480C0A67156A1EC ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:34:05.0155 1356 ql2300 - ok
13:34:05.0201 1356 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:34:05.0201 1356 ql40xx - ok
13:34:05.0264 1356 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
13:34:05.0279 1356 QWAVE - ok
13:34:05.0326 1356 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:34:05.0342 1356 QWAVEdrv - ok
13:34:05.0451 1356 [ E642B131FB74CAF4BB8A014F31113142 ] R300 C:\Windows\system32\DRIVERS\atikmdag.sys
13:34:05.0545 1356 R300 - ok
13:34:05.0591 1356 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:34:05.0591 1356 RasAcd - ok
13:34:05.0623 1356 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
13:34:05.0654 1356 RasAuto - ok
13:34:05.0685 1356 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:34:05.0685 1356 Rasl2tp - ok
13:34:05.0779 1356 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
13:34:05.0794 1356 RasMan - ok
13:34:05.0841 1356 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:34:05.0841 1356 RasPppoe - ok
13:34:05.0872 1356 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:34:05.0872 1356 RasSstp - ok
13:34:05.0935 1356 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:34:05.0935 1356 rdbss - ok
13:34:05.0966 1356 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:34:05.0981 1356 RDPCDD - ok
13:34:06.0013 1356 [ 0245418224CFA77BF4B41C2FE0622258 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
13:34:06.0013 1356 rdpdr - ok
13:34:06.0028 1356 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:34:06.0028 1356 RDPENCDD - ok
13:34:06.0075 1356 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:34:06.0091 1356 RDPWD - ok
13:34:06.0153 1356 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:34:06.0169 1356 RemoteAccess - ok
13:34:06.0215 1356 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:34:06.0231 1356 RemoteRegistry - ok
13:34:06.0262 1356 [ D85E3FA9F5B1F29BB4ED185C450D1470 ] rimmptsk C:\Windows\system32\DRIVERS\rimmptsk.sys
13:34:06.0262 1356 rimmptsk - ok
13:34:06.0278 1356 [ DB8EB01C58C9FADA00C70B1775278AE0 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys
13:34:06.0278 1356 rimsptsk - ok
13:34:06.0309 1356 [ 6C1F93C0760C9F79A1869D07233DF39D ] rismxdp C:\Windows\system32\DRIVERS\rixdptsk.sys
13:34:06.0309 1356 rismxdp - ok
13:34:06.0418 1356 [ EBCDE8B48FADC6479D96A56D0A432160 ] RoxMediaDB9 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
13:34:06.0465 1356 RoxMediaDB9 - ok
13:34:06.0512 1356 [ AB2B1DE1C8F31EFCE2384B14B3DC4260 ] RoxWatch9 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
13:34:06.0512 1356 RoxWatch9 - ok
13:34:06.0543 1356 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
13:34:06.0543 1356 RpcLocator - ok
13:34:06.0590 1356 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
13:34:06.0605 1356 RpcSs - ok
13:34:06.0652 1356 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:34:06.0652 1356 rspndr - ok
13:34:06.0699 1356 [ 06847AA6F3A9BF7C44134D00A2E578C0 ] s125bus C:\Windows\system32\DRIVERS\s125bus.sys
13:34:06.0699 1356 s125bus - ok
13:34:06.0761 1356 [ F83F88E1B125308FB5015EA0349502B0 ] s125mdfl C:\Windows\system32\DRIVERS\s125mdfl.sys
13:34:06.0761 1356 s125mdfl - ok
13:34:06.0777 1356 [ 402A97756C14940AD6AE5169C2FB105E ] s125mdm C:\Windows\system32\DRIVERS\s125mdm.sys
13:34:06.0793 1356 s125mdm - ok
13:34:06.0824 1356 [ 82B14C51DE76825EC769A6374E4C57D6 ] s125mgmt C:\Windows\system32\DRIVERS\s125mgmt.sys
13:34:06.0824 1356 s125mgmt - ok
13:34:06.0886 1356 [ BEDFC5707C356FD073BF1A4AFE442D91 ] s125obex C:\Windows\system32\DRIVERS\s125obex.sys
13:34:06.0886 1356 s125obex - ok
13:34:06.0933 1356 [ EF4B5A8D53F15CB269469DD4E4BB0109 ] s616bus C:\Windows\system32\DRIVERS\s616bus.sys
13:34:06.0949 1356 s616bus - ok
13:34:07.0027 1356 [ 96187731EEFCF83E844BC1CE6617AAEB ] s616mdfl C:\Windows\system32\DRIVERS\s616mdfl.sys
13:34:07.0027 1356 s616mdfl - ok
13:34:07.0058 1356 [ D2DD87368BFECFA099E50DC120F3F513 ] s616mdm C:\Windows\system32\DRIVERS\s616mdm.sys
13:34:07.0058 1356 s616mdm - ok
13:34:07.0105 1356 [ 5F0BE24E4D4FA134B0B2FEF35D3A9D90 ] s616mgmt C:\Windows\system32\DRIVERS\s616mgmt.sys
13:34:07.0105 1356 s616mgmt - ok
13:34:07.0136 1356 [ B9B507FCC67E204EF38E05FFD4176345 ] s616nd5 C:\Windows\system32\DRIVERS\s616nd5.sys
13:34:07.0151 1356 s616nd5 - ok
13:34:07.0198 1356 [ F123A1F2A04A0E8DBA80B64F0072475A ] s616obex C:\Windows\system32\DRIVERS\s616obex.sys
13:34:07.0198 1356 s616obex - ok
13:34:07.0245 1356 [ E7E55048EBD5C17BFA791B4A6EC3D54B ] s616unic C:\Windows\system32\DRIVERS\s616unic.sys
13:34:07.0261 1356 s616unic - ok
13:34:07.0276 1356 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
13:34:07.0292 1356 SamSs - ok
13:34:07.0323 1356 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:34:07.0323 1356 sbp2port - ok
13:34:07.0385 1356 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:34:07.0401 1356 SCardSvr - ok
13:34:07.0463 1356 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
13:34:07.0510 1356 Schedule - ok
13:34:07.0557 1356 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
13:34:07.0557 1356 SCPolicySvc - ok
13:34:07.0619 1356 [ 8F36B54688C31EED4580129040C6A3D3 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
13:34:07.0619 1356 sdbus - ok
13:34:07.0666 1356 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:34:07.0682 1356 SDRSVC - ok
13:34:07.0713 1356 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:34:07.0713 1356 secdrv - ok
13:34:07.0760 1356 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
13:34:07.0775 1356 seclogon - ok
13:34:07.0822 1356 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
13:34:07.0838 1356 SENS - ok
13:34:07.0885 1356 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
13:34:07.0885 1356 Serenum - ok
13:34:07.0900 1356 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
13:34:07.0900 1356 Serial - ok
13:34:07.0947 1356 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:34:07.0947 1356 sermouse - ok
13:34:08.0009 1356 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
13:34:08.0041 1356 SessionEnv - ok
13:34:08.0056 1356 [ 51CF56AA8BCC241F134B420B8F850406 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:34:08.0072 1356 sffdisk - ok
13:34:08.0072 1356 [ 96DED8B20C734AC41641CE275250E55D ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:34:08.0087 1356 sffp_mmc - ok
13:34:08.0103 1356 [ 8B08CAB1267B2C377883FC9E56981F90 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:34:08.0103 1356 sffp_sd - ok
13:34:08.0119 1356 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
13:34:08.0119 1356 sfloppy - ok
13:34:08.0165 1356 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:34:08.0212 1356 SharedAccess - ok
13:34:08.0259 1356 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:34:08.0290 1356 ShellHWDetection - ok
13:34:08.0306 1356 [ 08072B2FB92477FC813271A84B3A8698 ] sisagp C:\Windows\system32\drivers\sisagp.sys
13:34:08.0306 1356 sisagp - ok
13:34:08.0321 1356 [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
13:34:08.0321 1356 SiSRaid2 - ok
 
Second half of TDSSKiller log:

13:34:08.0337 1356 [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:34:08.0337 1356 SiSRaid4 - ok
13:34:08.0493 1356 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
13:34:08.0633 1356 slsvc - ok
13:34:08.0665 1356 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
13:34:08.0680 1356 SLUINotify - ok
13:34:08.0727 1356 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:34:08.0743 1356 Smb - ok
13:34:08.0774 1356 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:34:08.0789 1356 SNMPTRAP - ok
13:34:08.0821 1356 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
13:34:08.0836 1356 spldr - ok
13:34:08.0899 1356 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
13:34:08.0914 1356 Spooler - ok
13:34:08.0977 1356 sprtsvc_dellsupportcenter - ok
13:34:09.0023 1356 sprtsvc_verizondm - ok
13:34:09.0101 1356 [ 1A606A8D611816ADC47D2B25DBEDCB1F ] sptd C:\Windows\system32\Drivers\sptd.sys
13:34:09.0101 1356 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 1A606A8D611816ADC47D2B25DBEDCB1F
13:34:09.0101 1356 sptd ( LockedFile.Multi.Generic ) - warning
13:34:09.0101 1356 sptd - detected LockedFile.Multi.Generic (1)
13:34:09.0148 1356 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
13:34:09.0164 1356 srv - ok
13:34:09.0211 1356 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:34:09.0211 1356 srv2 - ok
13:34:09.0226 1356 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:34:09.0226 1356 srvnet - ok
13:34:09.0273 1356 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:34:09.0289 1356 SSDPSRV - ok
13:34:09.0351 1356 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:34:09.0367 1356 SstpSvc - ok
13:34:09.0413 1356 [ 799AA3E04879B3FED31ECEA02B1CAA9A ] STacSV C:\Windows\system32\STacSV.exe
13:34:09.0429 1356 STacSV - ok
13:34:09.0460 1356 [ 5AF135B2E2097D4494B9067CE84E2665 ] STHDA C:\Windows\system32\drivers\stwrt.sys
13:34:09.0460 1356 STHDA - ok
13:34:09.0538 1356 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
13:34:09.0554 1356 stisvc - ok
13:34:09.0616 1356 [ 51778FD315C9882F1CBD932743E62A72 ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
13:34:09.0616 1356 stllssvr - ok
13:34:09.0647 1356 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:34:09.0647 1356 swenum - ok
13:34:09.0694 1356 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
13:34:09.0725 1356 swprv - ok
13:34:09.0772 1356 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
13:34:09.0772 1356 Symc8xx - ok
13:34:09.0788 1356 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
13:34:09.0803 1356 Sym_hi - ok
13:34:09.0819 1356 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
13:34:09.0819 1356 Sym_u3 - ok
13:34:09.0866 1356 [ DD17B63F26430E179EF6BDEF5AC735BD ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
13:34:09.0881 1356 SynTP - ok
13:34:09.0959 1356 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
13:34:10.0006 1356 SysMain - ok
13:34:10.0037 1356 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:34:10.0069 1356 TabletInputService - ok
13:34:10.0115 1356 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:34:10.0147 1356 TapiSrv - ok
13:34:10.0193 1356 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
13:34:10.0225 1356 TBS - ok
13:34:10.0287 1356 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:34:10.0334 1356 Tcpip - ok
13:34:10.0396 1356 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
13:34:10.0412 1356 Tcpip6 - ok
13:34:10.0459 1356 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:34:10.0459 1356 tcpipreg - ok
13:34:10.0505 1356 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:34:10.0505 1356 TDPIPE - ok
13:34:10.0552 1356 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:34:10.0552 1356 TDTCP - ok
13:34:10.0599 1356 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:34:10.0599 1356 tdx - ok
13:34:10.0615 1356 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:34:10.0615 1356 TermDD - ok
13:34:10.0646 1356 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
13:34:10.0677 1356 TermService - ok
13:34:10.0677 1356 tgsrvc_verizondm - ok
13:34:10.0708 1356 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
13:34:10.0724 1356 Themes - ok
13:34:10.0739 1356 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
13:34:10.0755 1356 THREADORDER - ok
13:34:10.0802 1356 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
13:34:10.0817 1356 TrkWks - ok
13:34:10.0880 1356 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:34:10.0880 1356 TrustedInstaller - ok
13:34:10.0927 1356 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:34:10.0927 1356 tssecsrv - ok
13:34:10.0989 1356 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
13:34:10.0989 1356 tunmp - ok
13:34:11.0020 1356 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:34:11.0020 1356 tunnel - ok
13:34:11.0051 1356 [ C3ADE15414120033A36C0F293D4A4121 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:34:11.0051 1356 uagp35 - ok
13:34:11.0098 1356 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:34:11.0098 1356 udfs - ok
13:34:11.0145 1356 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:34:11.0176 1356 UI0Detect - ok
13:34:11.0192 1356 [ 6D72EF05921ABDF59FC45C7EBFE7E8DD ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:34:11.0192 1356 uliagpkx - ok
13:34:11.0239 1356 [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci C:\Windows\system32\drivers\uliahci.sys
13:34:11.0239 1356 uliahci - ok
13:34:11.0270 1356 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
13:34:11.0270 1356 UlSata - ok
13:34:11.0285 1356 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
13:34:11.0285 1356 ulsata2 - ok
13:34:11.0332 1356 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:34:11.0348 1356 umbus - ok
13:34:11.0395 1356 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
13:34:11.0410 1356 upnphost - ok
13:34:11.0488 1356 [ 32DB9517628FF0D070682AAB61E688F0 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
13:34:11.0488 1356 usbaudio - ok
13:34:11.0535 1356 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:34:11.0535 1356 usbccgp - ok
13:34:11.0566 1356 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:34:11.0582 1356 usbcir - ok
13:34:11.0629 1356 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:34:11.0629 1356 usbehci - ok
13:34:11.0644 1356 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:34:11.0660 1356 usbhub - ok
13:34:11.0675 1356 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
13:34:11.0675 1356 usbohci - ok
13:34:11.0691 1356 [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint C:\Windows\system32\drivers\usbprint.sys
13:34:11.0707 1356 usbprint - ok
13:34:11.0753 1356 [ B1F95285C08DDFE00C0B955462637EC7 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
13:34:11.0769 1356 usbscan - ok
13:34:11.0785 1356 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:34:11.0800 1356 USBSTOR - ok
13:34:11.0831 1356 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:34:11.0847 1356 usbuhci - ok
13:34:11.0878 1356 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
13:34:11.0894 1356 UxSms - ok
13:34:11.0972 1356 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
13:34:12.0003 1356 vds - ok
13:34:12.0019 1356 [ 7D92BE0028ECDEDEC74617009084B5EF ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:34:12.0019 1356 vga - ok
13:34:12.0081 1356 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
13:34:12.0097 1356 VgaSave - ok
13:34:12.0112 1356 [ D5929A28BDFF4367A12CAF06AF901971 ] viaagp C:\Windows\system32\drivers\viaagp.sys
13:34:12.0112 1356 viaagp - ok
13:34:12.0128 1356 [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
13:34:12.0128 1356 ViaC7 - ok
13:34:12.0159 1356 [ C0ACE9D0F5A5EE0B00F58345947A57FC ] viaide C:\Windows\system32\drivers\viaide.sys
13:34:12.0159 1356 viaide - ok
13:34:12.0190 1356 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:34:12.0190 1356 volmgr - ok
13:34:12.0253 1356 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:34:12.0268 1356 volmgrx - ok
13:34:12.0331 1356 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:34:12.0331 1356 volsnap - ok
13:34:12.0377 1356 [ D984439746D42B30FC65A4C3546C6829 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:34:12.0377 1356 vsmraid - ok
13:34:12.0455 1356 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
13:34:12.0518 1356 VSS - ok
13:34:12.0721 1356 [ 8ED347BAD8D1FB7C40B593BFB01786D2 ] vToolbarUpdater11.2.0 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
13:34:12.0767 1356 vToolbarUpdater11.2.0 - ok
13:34:12.0814 1356 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
13:34:12.0830 1356 W32Time - ok
13:34:12.0877 1356 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:34:12.0877 1356 WacomPen - ok
13:34:12.0908 1356 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
13:34:12.0923 1356 Wanarp - ok
13:34:12.0923 1356 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:34:12.0923 1356 Wanarpv6 - ok
13:34:12.0986 1356 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:34:13.0017 1356 wcncsvc - ok
13:34:13.0048 1356 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:34:13.0079 1356 WcsPlugInService - ok
13:34:13.0111 1356 [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd C:\Windows\system32\drivers\wd.sys
13:34:13.0111 1356 Wd - ok
13:34:13.0157 1356 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:34:13.0173 1356 Wdf01000 - ok
13:34:13.0220 1356 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:34:13.0251 1356 WdiServiceHost - ok
13:34:13.0251 1356 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:34:13.0267 1356 WdiSystemHost - ok
13:34:13.0313 1356 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
13:34:13.0345 1356 WebClient - ok
13:34:13.0376 1356 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:34:13.0391 1356 Wecsvc - ok
13:34:13.0438 1356 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:34:13.0454 1356 wercplsupport - ok
13:34:13.0485 1356 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
13:34:13.0516 1356 WerSvc - ok
13:34:13.0579 1356 [ 4DACA8F07537D4D7E3534BB99294AA26 ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
13:34:13.0594 1356 winachsf - ok
13:34:13.0610 1356 WinHttpAutoProxySvc - ok
13:34:13.0688 1356 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:34:13.0688 1356 Winmgmt - ok
13:34:13.0766 1356 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
13:34:13.0844 1356 WinRM - ok
13:34:13.0906 1356 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:34:13.0937 1356 Wlansvc - ok
13:34:14.0047 1356 [ 5144AE67D60EC653F97DDF3FEED29E77 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
13:34:14.0109 1356 wlidsvc - ok
13:34:14.0109 1356 wltrysvc - ok
13:34:14.0156 1356 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
13:34:14.0156 1356 WmiAcpi - ok
13:34:14.0203 1356 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:34:14.0203 1356 wmiApSrv - ok
13:34:14.0296 1356 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
13:34:14.0359 1356 WMPNetworkSvc - ok
13:34:14.0405 1356 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:34:14.0437 1356 WPCSvc - ok
13:34:14.0468 1356 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:34:14.0499 1356 WPDBusEnum - ok
13:34:14.0561 1356 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
13:34:14.0577 1356 WpdUsb - ok
13:34:14.0702 1356 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:34:14.0764 1356 WPFFontCache_v0400 - ok
13:34:14.0842 1356 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:34:14.0842 1356 ws2ifsl - ok
13:34:14.0889 1356 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll
13:34:14.0920 1356 wscsvc - ok
13:34:14.0967 1356 [ 4422AC5ED8D4C2F0DB63E71D4C069DD7 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
13:34:14.0967 1356 WSDPrintDevice - ok
13:34:14.0983 1356 WSearch - ok
13:34:15.0076 1356 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
13:34:15.0154 1356 wuauserv - ok
13:34:15.0217 1356 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:34:15.0217 1356 WUDFRd - ok
13:34:15.0310 1356 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:34:15.0326 1356 wudfsvc - ok
13:34:15.0373 1356 [ 5A7FF9A18FF6D7E0527FE3ABF9204EF8 ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
13:34:15.0373 1356 XAudio - ok
13:34:15.0404 1356 [ 28DC5D626E036A75A572556F0A6EB1F6 ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
13:34:15.0419 1356 XAudioService - ok
13:34:15.0451 1356 XDva281 - ok
13:34:15.0466 1356 XDva344 - ok
13:34:15.0513 1356 ================ Scan global ===============================
13:34:15.0560 1356 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
13:34:15.0607 1356 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
13:34:15.0669 1356 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
13:34:15.0731 1356 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
13:34:15.0763 1356 [Global] - ok
13:34:15.0778 1356 ================ Scan MBR ==================================
13:34:15.0778 1356 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
13:34:16.0199 1356 \Device\Harddisk0\DR0 - ok
13:34:16.0199 1356 [ E5FA06ACA0D60BA9C870D0EF3D9898C9 ] \Device\Harddisk1\DR3
13:34:19.0444 1356 \Device\Harddisk1\DR3 - ok
13:34:19.0444 1356 ================ Scan VBR ==================================
13:34:19.0460 1356 [ 38B3939DDAAA6276BC1BBB0A99FC7438 ] \Device\Harddisk0\DR0\Partition1
13:34:19.0460 1356 \Device\Harddisk0\DR0\Partition1 - ok
13:34:19.0475 1356 [ 8DDA3BF9B4DDC8C4A2D1F9D508F75785 ] \Device\Harddisk0\DR0\Partition2
13:34:19.0475 1356 \Device\Harddisk0\DR0\Partition2 - ok
13:34:19.0491 1356 [ BBDBB656874D6696CE9ECB5B90486B6B ] \Device\Harddisk1\DR3\Partition1
13:34:19.0491 1356 \Device\Harddisk1\DR3\Partition1 - ok
13:34:19.0491 1356 ============================================================
13:34:19.0491 1356 Scan finished
13:34:19.0491 1356 ============================================================
13:34:19.0507 0232 Detected object count: 1
13:34:19.0507 0232 Actual detected object count: 1
13:34:39.0818 0232 sptd ( LockedFile.Multi.Generic ) - skipped by user
13:34:39.0818 0232 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
 
RogueKiller and MBR logs:


RogueKiller V8.0.4 [09/19/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: https://www.techspot.com/downloads/5562-roguekiller.html
Blog: http://tigzyrk.blogspot.com

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Safe mode
User : Admin [Admin rights]
Mode : Scan -- Date : 09/20/2012 13:37:46

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 8 ¤¤¤
[RUN][SUSP PATH] HKLM\[...]\RunOnce : InnoSetupRegFile.0000000001 ("C:\Windows\is-RJP4O.exe" /REG /REGSVRMODE) -> FOUND
[STARTUP][SUSP PATH] NexDef Plug-in.lnk @shirley DiDomenico : C:\Users\Shirley DiDomenico\AppData\Local\Autobahn\nexdef.exe -> FOUND
[HJ DESK] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
[HJ DESK] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[SHELLSPWN] HKUS\.DEFAULT[...]\command : ("C:\Windows\system32\config\systemprofile\AppData\Local\pdo.exe" -a "%1" %*) -> FOUND
[SHELLSPWN] HKUS\S-1-5-18[...]\command : ("C:\Windows\system32\config\systemprofile\AppData\Local\pdo.exe" -a "%1" %*) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost
::1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1001namen.com
127.0.0.1 1001namen.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
[...]


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST9120822AS +++++
--- User ---
[MBR] 91d8f9683f86e8fef69977e094084d7e
[BSP] bdf99326810b3ea5b3c85f61013cb3ba : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 86 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 178176 | Size: 10240 Mo
2 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 21149696 | Size: 101585 Mo
3 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 229195776 | Size: 2560 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: CBM Flash Disk USB Device +++++
--- User ---
[MBR] e8f762c0c8f58572b8c18a874830a4cb
[BSP] f8e902c9b699ad3dfc38721510653181 : Standard MBR Code
Partition table:
0 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 32 | Size: 248 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[1].txt >>
RKreport[1].txt

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-20 13:40:55
-----------------------------
13:40:55.856 OS Version: Windows 6.0.6002 Service Pack 2
13:40:55.856 Number of processors: 2 586 0xF0D
13:40:55.856 ComputerName: SHIRLEYDIDOM-PC UserName: Admin
13:40:56.761 Initialize success
13:41:05.341 AVAST engine download error: 0
13:41:17.758 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
13:41:17.774 Disk 0 Vendor: ST912082 3.CD Size: 114473MB BusType: 3
13:41:17.836 Disk 0 MBR read successfully
13:41:17.836 Disk 0 MBR scan
13:41:17.836 Disk 0 Windows VISTA default MBR code
13:41:17.836 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 86 MB offset 63
13:41:17.852 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 178176
13:41:17.867 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 101585 MB offset 21149696
13:41:17.867 Disk 0 Partition - 00 0F Extended LBA 2560 MB offset 229195776
13:41:17.914 Disk 0 Partition 4 00 DD MSDOS5.0 2559 MB offset 229197824
13:41:17.930 Disk 0 scanning sectors +234438656
13:41:17.992 Disk 0 scanning C:\Windows\system32\drivers
13:41:28.335 Service scanning
13:41:43.093 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
13:41:48.787 Modules scanning
13:41:53.233 Disk 0 trace - called modules:
13:41:53.279 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys spnb.sys hal.dll >>UNKNOWN [0x851c2938]<<
13:41:53.279 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8611b030]
13:41:53.295 3 CLASSPNP.SYS[887a08b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x852cf030]
13:41:53.295 Scan finished successfully
13:42:04.995 Disk 0 MBR has been saved successfully to "C:\Users\Admin\Desktop\MBR.dat"
13:42:04.995 The log file has been saved successfully to "C:\Users\Admin\Desktop\aswMBR.txt"

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

There you go! A few things I want to ask about. The RogueKiller app created two logs, RKreport[1] and RKreport[2]. I only included the first, please let me know if you need the second. It also created a folder on the affected desktop named RK_Quarantine with the removed entries in it. Is there something I should be doing with that? Thanks again!
 
Yes, I'd like to see the second log.

Create new restore point before proceeding with the next step....
How to:
- Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
- Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
- XP: http://support.microsoft.com/kb/948247

=============================================

Please download ComboFix from Here, Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  • Double click on combofix.exe & follow the prompts.

  • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
Use AppRemover to uninstall it: https://www.techspot.com/downloads/5514-appremover.html
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
**Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try the following...

Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.
Download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

Restart computer in safe mode

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

When the scan is done Notepad will open with rKill.txt log.
NOTE. rKill.txt log will also be present on your desktop.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
 
Here is the second RK log. Also, when I try to create a system restore point, I am not given that tab in Control Panel>System>System Properties. It just shows Computer Name, Hardware, Advanced and Remote. I assume that this is because I am in safe mode. I will await a reply before I attempt to run ComboFix.


RogueKiller V8.0.4 [09/19/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: https://www.techspot.com/downloads/5562-roguekiller.html
Blog: http://tigzyrk.blogspot.com

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Safe mode
User : Admin [Admin rights]
Mode : Remove -- Date : 09/20/2012 13:38:59

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 7 ¤¤¤
[RUN][SUSP PATH] HKLM\[...]\RunOnce : InnoSetupRegFile.0000000001 ("C:\Windows\is-RJP4O.exe" /REG /REGSVRMODE) -> DELETED
[STARTUP][SUSP PATH] NexDef Plug-in.lnk @shirley DiDomenico : C:\Users\Shirley DiDomenico\AppData\Local\Autobahn\nexdef.exe -> DELETED
[HJ DESK] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)
[HJ DESK] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[SHELLSPWN] HKUS\.DEFAULT[...]\command : ("C:\Windows\system32\config\systemprofile\AppData\Local\pdo.exe" -a "%1" %*) -> REPLACED ("%1" %*)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost
::1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1001namen.com
127.0.0.1 1001namen.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
[...]


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST9120822AS +++++
--- User ---
[MBR] 91d8f9683f86e8fef69977e094084d7e
[BSP] bdf99326810b3ea5b3c85f61013cb3ba : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 86 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 178176 | Size: 10240 Mo
2 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 21149696 | Size: 101585 Mo
3 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 229195776 | Size: 2560 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: CBM Flash Disk USB Device +++++
--- User ---
[MBR] e8f762c0c8f58572b8c18a874830a4cb
[BSP] f8e902c9b699ad3dfc38721510653181 : Standard MBR Code
Partition table:
0 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 32 | Size: 248 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[2].txt >>
 
For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:

    • Startup Repair
      System Restore
      Windows Complete PC Restore
      Windows Memory Diagnostic Tool
      Command Prompt
  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
 
Here is the FRST log:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-09-2012
Ran by SYSTEM at 20-09-2012 14:59:47
Running from E:\
Windows Vista (TM) Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1008184 2008-01-18] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-04-27] (Synaptics, Inc.)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [x]
HKLM\...\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r [180224 2006-11-27] (Creative Technology Ltd)
HKLM\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-10] (Creative Technology Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe [1548288 2007-03-21] (Dell Inc.)
HKLM\...\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [81920 2006-10-03] (Macrovision Corporation)
HKLM\...\Run: [] [x]
HKLM\...\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" [184320 2007-04-16] (CyberLink Corp.)
HKLM\...\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [16384 2007-11-15] ( )
HKLM\...\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2009-05-21] (SupportSoft, Inc.)
HKLM\...\Run: [dlbkbmgr.exe] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [275952 2007-03-28] (Dell)
HKLM\...\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe [176128 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-09-07] (IDT, Inc.)
HKLM\...\Run: [VERIZONDM] "C:\Program Files\VERIZONDM\bin\sprtcmd.exe" /P VERIZONDM [206120 2011-02-01] (SupportSoft, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [38872 2012-07-31] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-11] (Adobe Systems Incorporated)
HKLM\...\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 [x]
HKLM\...\Run: [mylbx] C:\Program Files\My Lockbox\mylbx.exe /a [2143552 2012-03-21] (FSPro Labs)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [HF_G_Jul] "C:\Program Files\AVG Secure Search\HF_G_Jul.exe" /DoAction [x]
HKU\Admin\...\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\Admin\...\Run: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe [1866864 2010-11-06] (PeerBlock, LLC)
HKU\Admin\...\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet [5252408 2010-06-01] (Yahoo! Inc.)
HKU\Admin\...\Run: [MarbleStation] [x]
HKU\Admin\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [8704 2006-11-02] (Microsoft Corporation)
HKU\Admin\...\Run: [EDesksoft Auto Update] C:\Program Files\EDesksoft\Update\EDesksoftUpdate.exe [278528 2011-05-22] (EDesksoft Inc)
HKU\Admin\...\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [1305408 2011-01-20] (DT Soft Ltd)
HKU\Admin\...\Policies\system: [LogonHoursAction] 2
HKU\Admin\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Default\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [x]
HKU\Default User\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [x]
HKU\Shirley DiDomenico\...\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background [x]
HKU\Shirley DiDomenico\...\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2009-05-21] (SupportSoft, Inc.)
HKU\Shirley DiDomenico\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [413696 2008-05-27] (Apple Inc.)
HKU\Shirley DiDomenico\...\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" [328568 2010-09-02] (BitTorrent, Inc.)
HKU\Shirley DiDomenico\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-18] (Microsoft Corporation)
HKU\Shirley DiDomenico\...\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\Shirley DiDomenico\...\Run: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe [1866864 2010-11-06] (PeerBlock, LLC)
HKU\Shirley DiDomenico\...\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet [5252408 2010-06-01] (Yahoo! Inc.)
HKU\Shirley DiDomenico\...\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun [687560 2008-12-29] (DT Soft Ltd)
HKU\Shirley DiDomenico\...\Run: [Google Update] "C:\Users\Shirley DiDomenico\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-04-12] (Google Inc.)
HKU\Shirley DiDomenico\...\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.exe -update activex [686792 2012-08-16] (Adobe Systems Incorporated)
HKU\Shirley DiDomenico\...\Policies\system: [LogonHoursAction] 2
HKU\Shirley DiDomenico\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM\...\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [462408 2012-04-04] (Malwarebytes Corporation)
HKLM\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1082440 2012-04-04] (Malwarebytes Corporation)
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
Tcpip\..\Interfaces\{08566BEC-A3A2-4754-A14F-85673F5C0482}: [NameServer]192.168.1.1
Tcpip\..\Interfaces\{FB699354-B8A5-4099-B170-830788B8166C}: [NameServer]192.168.0.1
Startup: C:\Users\Admin\Start Menu\Programs\Startup\Matrix Screen Locker.lnk
ShortcutTarget: Matrix Screen Locker.lnk -> C:\Program Files\Matrix Screen Locker\matrix.exe (BaroufaSoft)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickSet.lnk
ShortcutTarget: QuickSet.lnk -> C:\Windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe (Macrovision Corporation)
Startup: C:\Users\Shirley DiDomenico\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Shirley DiDomenico\Start Menu\Programs\Startup\Xfire.lnk
ShortcutTarget: Xfire.lnk -> C:\Program Files\Xfire\Xfire.exe (No File)

==================== Services (Whitelisted) ===================

2 a2AntiMalware; "C:\Program Files\a-squared Anti-Malware\a2service.exe" [980512 2009-08-26] (Emsi Software GmbH)
2 Creative Labs Licensing Service; "C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe" [72704 2007-08-28] (Creative Labs)
2 Creative Service for CDROM Access; C:\Windows\system32\CTsvcCDA.exe [44032 2007-04-08] (Creative Technology Ltd)
2 dlbk_device; C:\Windows\system32\dlbkcoms.exe -service [538096 2007-03-28] ( )
3 DSBrokerService; "C:\Program Files\DellSupport\brkrsvc.exe" [70656 2007-03-19] ()
3 MozillaMaintenance; "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" [113120 2012-08-04] (Mozilla Foundation)
3 npggsvc; C:\Windows\system32\GameMon.des -service [3818640 2010-12-21] (INCA Internet Co., Ltd.)
2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter [201968 2008-08-13] (SupportSoft, Inc.)
2 sprtsvc_verizondm; C:\Program Files\VERIZONDM\bin\sprtsvc.exe /service /p verizondm [206120 2011-02-01] (SupportSoft, Inc.)
2 tgsrvc_verizondm; C:\Program Files\VERIZONDM\bin\tgsrvc.exe /p verizondm [185640 2011-02-01] (SupportSoft, Inc.)

==================== Drivers (Whitelisted) ====================

1 ASPI32; C:\Windows\System32\Drivers\ASPI32.sys [25244 1999-09-10] (Adaptec)
1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [218688 2011-07-02] (DT Soft Ltd)
0 FSProFilter; C:\Windows\System32\Drivers\FSPFltd.sys [41912 2010-07-22] (FSPro Labs)
3 pbfilter; \??\C:\Program Files\PeerBlock\pbfilter.sys [20080 2010-11-06] ()
0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [36528 2006-07-24] (Sonic Solutions)
3 s125bus; C:\Windows\System32\DRIVERS\s125bus.sys [83336 2007-04-24] (MCCI Corporation)
3 s125mdfl; C:\Windows\System32\DRIVERS\s125mdfl.sys [15112 2007-04-24] (MCCI Corporation)
3 s125mdm; C:\Windows\System32\DRIVERS\s125mdm.sys [108680 2007-04-24] (MCCI Corporation)
3 s125mgmt; C:\Windows\System32\DRIVERS\s125mgmt.sys [100488 2007-04-24] (MCCI Corporation)
3 s125obex; C:\Windows\System32\DRIVERS\s125obex.sys [98696 2007-04-24] (MCCI Corporation)
3 s616bus; C:\Windows\System32\DRIVERS\s616bus.sys [83208 2007-04-03] (MCCI Corporation)
3 s616mdfl; C:\Windows\System32\DRIVERS\s616mdfl.sys [15112 2007-04-03] (MCCI Corporation)
3 s616mdm; C:\Windows\System32\DRIVERS\s616mdm.sys [108680 2007-04-03] (MCCI Corporation)
3 s616mgmt; C:\Windows\System32\DRIVERS\s616mgmt.sys [100360 2007-04-03] (MCCI Corporation)
3 s616nd5; C:\Windows\System32\DRIVERS\s616nd5.sys [23176 2007-04-03] (MCCI Corporation)
3 s616obex; C:\Windows\System32\DRIVERS\s616obex.sys [98568 2007-04-03] (MCCI Corporation)
3 s616unic; C:\Windows\System32\DRIVERS\s616unic.sys [99080 2007-04-03] (MCCI Corporation)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [721904 2009-05-29] (Duplex Secure Ltd.)
4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [x]
3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 XDva281; \??\C:\Windows\system32\XDva281.sys [x]
3 XDva344; \??\C:\Windows\system32\XDva344.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2012-09-20 14:59 - 2012-09-20 14:59 - 00000000 ____D C:\FRST
2012-09-20 10:56 - 2012-09-20 10:14 - 04754465 ____A (Swearware) C:\Users\Admin\Desktop\ComboFix.exe
2012-09-20 09:40 - 2012-09-20 09:09 - 04731392 ____A (AVAST Software) C:\Users\Admin\Desktop\aswMBR.exe
2012-09-20 09:37 - 2012-09-20 09:38 - 00000000 ____D C:\Users\Admin\Desktop\RK_Quarantine
2012-09-20 09:37 - 2012-09-20 09:08 - 01382912 ____A C:\Users\Admin\Desktop\RogueKiller.exe
2012-09-20 09:33 - 2012-09-17 15:25 - 02212440 ____A (Kaspersky Lab ZAO) C:\Users\Admin\Desktop\TDSSKiller.exe
2012-09-20 06:40 - 2012-09-20 06:22 - 00607260 ____R (Swearware) C:\Users\Admin\Desktop\dds.com
2012-09-20 06:39 - 2012-09-20 06:21 - 00302592 ____A C:\Users\Admin\Desktop\tj4gwf6h.exe
2012-09-19 16:10 - 2012-09-19 16:10 - 00000000 __SHD C:\found.001
2012-09-19 15:50 - 2012-09-19 15:51 - 06950656 ____A C:\Users\Admin\Desktop\spybotsd_includes.exe
2012-09-19 06:27 - 2012-09-19 08:59 - 00215115 ____A C:\Windows\System32\avgrep.txt
2012-09-18 19:20 - 2012-09-18 19:20 - 00000000 __SHD C:\found.000
2012-09-18 18:57 - 2012-09-18 18:58 - 83023306 ___AT C:\Users\All Users\a8722872.pad
2012-09-16 12:02 - 2012-09-16 12:02 - 00000000 ____D C:\Users\All Users\Bilbo
2012-09-16 11:23 - 2012-09-16 11:33 - 36269139 ____A C:\Users\Shirley DiDomenico\Downloads\6055.flv
2012-09-16 11:22 - 2012-09-16 11:41 - 40501120 ____A C:\Users\Shirley DiDomenico\Downloads\6059.flv
2012-09-16 11:05 - 2012-09-16 11:09 - 00000000 ____D C:\Users\Shirley DiDomenico\Downloads\Ye Banished Privateers_Songs And Curses_Radio Edit
2012-09-15 17:21 - 2012-09-15 17:21 - 00000000 ____D C:\Program Files\Horror Palace
2012-09-15 17:09 - 2012-09-15 17:26 - 47721731 ____A C:\Users\Shirley DiDomenico\Downloads\5997.flv
2012-09-15 17:07 - 2012-09-15 17:09 - 20765864 ____A C:\Users\Shirley DiDomenico\Downloads\6045.flv
2012-09-15 17:05 - 2012-09-15 17:06 - 21895758 ____A C:\Users\Shirley DiDomenico\Downloads\6051.flv
2012-09-15 09:06 - 2012-09-15 09:18 - 180529664 ____A C:\Users\Shirley DiDomenico\Downloads\prnfle241x.avi
2012-09-09 09:43 - 2012-09-09 09:43 - 00000000 ____D C:\Users\Shirley DiDomenico\AppData\Roaming\gd.sos.McPixel
2012-09-05 01:57 - 2012-09-05 01:57 - 00000000 ____D C:\Users\Shirley DiDomenico\AppData\Roaming\Oberon Media
2012-09-05 01:56 - 2012-09-05 01:57 - 00000000 ____D C:\Users\All Users\Oberon Media
2012-09-05 01:56 - 2012-09-05 01:56 - 00001895 ____A C:\Users\Shirley DiDomenico\Desktop\Bejeweled 2 Deluxe.lnk
2012-09-05 01:56 - 2012-09-05 01:56 - 00001098 ____A C:\Users\Shirley DiDomenico\Desktop\Yahoo! Games - Games And Online Games.lnk
2012-09-05 01:56 - 2012-09-05 01:56 - 00000000 ____D C:\Program Files\Common Files\Oberon Media
2012-09-05 01:55 - 2012-09-05 01:55 - 00000000 ____D C:\Program Files\Oberon Media
0-166-00 59200:168 - 2010-02-01 08:47 - 00006456 ___AH C:\Users\All Users\lefuhove

==================== 3 Months Modified Files ==================

2012-09-20 10:53 - 2009-09-29 05:22 - 00001356 ____A C:\Users\Admin\AppData\Local\d3d9caps.dat
2012-09-20 10:35 - 2006-11-02 02:33 - 00763574 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-20 10:14 - 2012-09-20 10:56 - 04754465 ____A (Swearware) C:\Users\Admin\Desktop\ComboFix.exe
2012-09-20 09:09 - 2012-09-20 09:40 - 04731392 ____A (AVAST Software) C:\Users\Admin\Desktop\aswMBR.exe
2012-09-20 09:08 - 2012-09-20 09:37 - 01382912 ____A C:\Users\Admin\Desktop\RogueKiller.exe
2012-09-20 06:25 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-20 06:25 - 2006-11-02 04:47 - 00003696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-20 06:25 - 2006-11-02 04:47 - 00003696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-20 06:22 - 2012-09-20 06:40 - 00607260 ____R (Swearware) C:\Users\Admin\Desktop\dds.com
2012-09-20 06:21 - 2012-09-20 06:39 - 00302592 ____A C:\Users\Admin\Desktop\tj4gwf6h.exe
2012-09-19 16:15 - 2006-11-02 05:01 - 00032568 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-09-19 15:51 - 2012-09-19 15:50 - 06950656 ____A C:\Users\Admin\Desktop\spybotsd_includes.exe
2012-09-19 15:42 - 2007-08-28 23:42 - 01213212 ____A C:\Windows\WindowsUpdate.log
2012-09-19 15:25 - 2012-04-12 21:09 - 00000960 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3366842975-1503843345-1045313785-1000UA.job
2012-09-19 11:13 - 2010-06-25 19:53 - 00005648 ____A C:\Users\Shirley DiDomenico\AppData\Local\d3d9caps.dat
2012-09-19 11:10 - 2007-09-05 08:33 - 00092464 ____A C:\Windows\PFRO.log
2012-09-19 10:15 - 2006-11-02 02:22 - 63963136 ____A C:\Windows\System32\config\software_previous
2012-09-19 10:15 - 2006-11-02 02:22 - 19136512 ____A C:\Windows\System32\config\system_previous
2012-09-19 10:11 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-09-19 10:11 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-09-19 08:59 - 2012-09-19 06:27 - 00215115 ____A C:\Windows\System32\avgrep.txt
2012-09-19 01:09 - 2006-11-02 02:22 - 43515904 ____A C:\Windows\System32\config\components_previous
2012-09-19 01:09 - 2006-11-02 02:22 - 05242880 ____A C:\Windows\System32\config\default_previous
2012-09-18 18:58 - 2012-09-18 18:57 - 83023306 ___AT C:\Users\All Users\a8722872.pad
2012-09-18 16:25 - 2012-04-12 21:09 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3366842975-1503843345-1045313785-1000Core.job
2012-09-17 15:25 - 2012-09-20 09:33 - 02212440 ____A (Kaspersky Lab ZAO) C:\Users\Admin\Desktop\TDSSKiller.exe
2012-09-16 11:41 - 2012-09-16 11:22 - 40501120 ____A C:\Users\Shirley DiDomenico\Downloads\6059.flv
2012-09-16 11:33 - 2012-09-16 11:23 - 36269139 ____A C:\Users\Shirley DiDomenico\Downloads\6055.flv
2012-09-15 17:26 - 2012-09-15 17:09 - 47721731 ____A C:\Users\Shirley DiDomenico\Downloads\5997.flv
2012-09-15 17:09 - 2012-09-15 17:07 - 20765864 ____A C:\Users\Shirley DiDomenico\Downloads\6045.flv
2012-09-15 17:06 - 2012-09-15 17:05 - 21895758 ____A C:\Users\Shirley DiDomenico\Downloads\6051.flv
2012-09-15 09:18 - 2012-09-15 09:06 - 180529664 ____A C:\Users\Shirley DiDomenico\Downloads\prnfle241x.avi
2012-09-05 01:56 - 2012-09-05 01:56 - 00001895 ____A C:\Users\Shirley DiDomenico\Desktop\Bejeweled 2 Deluxe.lnk
2012-09-05 01:56 - 2012-09-05 01:56 - 00001098 ____A C:\Users\Shirley DiDomenico\Desktop\Yahoo! Games - Games And Online Games.lnk
2012-08-16 06:57 - 2012-07-01 09:53 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-16 06:57 - 2011-06-08 21:49 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-15 12:59 - 2012-07-15 12:59 - 00443567 ___RA C:\Windows\System32\Drivers\etc\hosts.20120715-165926.backup
2012-07-15 12:59 - 2006-11-02 02:23 - 00443567 ___RA C:\Windows\System32\Drivers\etc\hosts.20120919-203503.backup
2012-07-10 18:09 - 2012-07-10 18:09 - 00711240 ____A C:\Windows\is-RJP4O.exe
2012-07-10 18:09 - 2012-07-10 18:09 - 00010498 ____A C:\Windows\is-RJP4O.msg
2012-07-10 18:09 - 2012-07-10 18:09 - 00000868 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-10 18:09 - 2012-07-10 18:09 - 00000441 ____A C:\Windows\is-RJP4O.lst
2012-07-06 20:46 - 2008-07-29 13:50 - 00039936 ____A C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-01 12:23 - 2007-09-05 07:23 - 00125544 ____A C:\Users\Shirley DiDomenico\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-01 11:43 - 2008-07-29 13:37 - 00125544 ____A C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-01 11:40 - 2006-11-02 04:47 - 00453168 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-01 10:41 - 2006-11-02 02:23 - 00000266 ____A C:\Windows\win.ini

==================== Known DLLs (Whitelisted) =================


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================


==================== Memory info ===========================

Percentage of memory in use: 13%
Total physical RAM: 2037.57 MB
Available physical RAM: 1761.82 MB
Total Pagefile: 1969.46 MB
Available Pagefile: 1843.95 MB
Total Virtual: 2047.88 MB
Available Virtual: 1983.71 MB

==================== Partitions =============================

1 Drive c: (OS) (Fixed) (Total:99.2 GB) (Free:6.6 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: () (Removable) (Total:0.24 GB) (Free:0.24 GB) FAT
4 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:4.92 GB) NTFS

Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 112 GB 1024 KB
Disk 1 Online 249 MB 0 B

Partitions of Disk 0:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 86 MB 32 KB
Partition 2 Primary 10 GB 87 MB
Partition 3 Primary 99 GB 10 GB
Partition 0 Extended 2560 MB 109 GB
Partition 4 Logical 2559 MB 109 GB

=========================================================

Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 86 MB Healthy Hidden

=========================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 X RECOVERY NTFS Partition 10 GB Healthy Boot

=========================================================

Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C OS NTFS Partition 99 GB Healthy

=========================================================

Disk: 0
Partition 4
Type : DD
Hidden: Yes
Active: No

There is no volume associated with this partition.

=========================================================

Partitions of Disk 1:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 249 MB 16 KB

=========================================================

Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 E FAT Removable 249 MB Healthy

=========================================================

Last Boot: 2012-09-20 10:48

==================== End Of Log ============================
 
I don't really see anything malicious there.
What does happen when you try to boot to normal mode?
 
Still getting the same thing. When I try and start in normal mode, I get a UAC box that says Windows Explorer wants to make a change. As this started happening right after I saw malware-like activity, I have not let it make the change. When I cancel the dialog box, all of the desktop icons and the taskbar vanish.
 
Now when we know FRST works just fine go ahead and run Combofix.
Don't worry about creating new restore point.
 
**UPDATE** I tried restarting and logging into the Admin account and it seemed to work fine. Then when I tried the regular user one again I still got the UAC box for Windows Explorer.

Should I try Combofix in Safe Mode or Normal?
 
Here is the ComboFix log. Thanks once again for yr time!

ComboFix 12-09-20.02 - Admin 09/20/2012 16:48:18.1.2 - x86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1599 [GMT -4:00]
Running from: c:\users\Admin\Desktop\ComboFix.exe
AV: a-squared Anti-Malware *Disabled/Updated* {45D82FD7-7300-6110-96D3-6C8EB10A96DD}
SP: a-squared Anti-Malware *Disabled/Updated* {FEB9CE33-553A-6E9E-AC63-57FCCA8DDC60}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\a8722872.pad
c:\users\Shirley DiDomenico\AppData\Roaming\Adobe\plugs
c:\users\Shirley DiDomenico\AppData\Roaming\Adobe\shed
c:\windows\system32\131845857.dat
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
D:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-08-20 to 2012-09-20 )))))))))))))))))))))))))))))))
.
.
2012-09-20 22:59 . 2012-09-20 22:59 -------- d-----w- C:\FRST
2012-09-20 20:11 . 2012-09-20 20:11 -------- d-----w- c:\users\Shirley DiDomenico\AppData\Roaming\uTorrent
2012-09-20 00:10 . 2012-09-20 00:10 -------- d-----w- C:\found.001
2012-09-19 03:20 . 2012-09-19 03:20 -------- d-----w- C:\found.000
2012-09-16 20:02 . 2012-09-16 20:02 -------- d-----w- c:\programdata\Bilbo
2012-09-16 01:21 . 2012-09-20 17:01 -------- d-----w- c:\program files\Horror Palace
2012-09-09 17:43 . 2012-09-09 17:43 -------- d-----w- c:\users\Shirley DiDomenico\AppData\Roaming\gd.sos.McPixel
2012-09-05 09:57 . 2012-09-05 09:57 -------- d-----w- c:\users\Shirley DiDomenico\AppData\Roaming\Oberon Media
2012-09-05 09:56 . 2012-09-05 09:56 -------- d-----w- c:\program files\Common Files\Oberon Media
2012-09-05 09:56 . 2012-09-05 09:57 -------- d-----w- c:\programdata\Oberon Media
2012-09-05 09:55 . 2012-09-05 09:55 -------- d-----w- c:\program files\Oberon Media
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-16 14:57 . 2012-07-01 17:53 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-16 14:57 . 2011-06-09 05:49 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-11 02:09 . 2012-07-11 02:09 711240 ----a-w- c:\windows\is-RJP4O.exe
2012-08-04 16:26 . 2012-06-30 04:50 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"PeerBlock"="c:\program files\PeerBlock\peerblock.exe" [2010-11-07 1866864]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"EDesksoft Auto Update"="c:\program files\EDesksoft\Update\EDesksoftUpdate.exe" [2011-05-23 278528]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-28 857648]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 154392]
"VolPanel"="c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-27 180224]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-21 1548288]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"dlbkbmgr.exe"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2007-03-28 275952]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-07 405504]
"VERIZONDM"="c:\program files\VERIZONDM\bin\sprtcmd.exe" [2011-02-01 206120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
"mylbx"="c:\program files\My Lockbox\mylbx.exe" [2012-03-21 2143552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-11-02 8704]
.
c:\users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Matrix Screen Locker.lnk - c:\program files\Matrix Screen Locker\matrix.exe [2005-6-8 488960]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-8-29 45056]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 22:36 30040 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-05-27 14:50 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2007-06-13 12:16 528384 ----a-r- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
.
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [x]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ECACHE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3366842975-1503843345-1045313785-1000Core.job
- c:\users\Shirley DiDomenico\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-13 05:07]
.
2012-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3366842975-1503843345-1045313785-1000UA.job
- c:\users\Shirley DiDomenico\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-13 05:07]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: Interfaces\{08566BEC-A3A2-4754-A14F-85673F5C0482}: NameServer = 192.168.1.1
TCP: Interfaces\{FB699354-B8A5-4099-B170-830788B8166C}: NameServer = 192.168.0.1
FF - ProfilePath - c:\users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vzop9hjr.default\
FF - prefs.js: browser.startup.homepage - about:blank
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-MarbleStation - (no file)
HKLM-Run-Persistence - c:\windows\system32\igfxpers.exe
HKLM-Run-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
HKLM-Run-HF_G_Jul - c:\program files\AVG Secure Search\HF_G_Jul.exe
AddRemove-FLAC - c:\program files\Exact Audio Copy\uninstall.exe
AddRemove-Sound Editor Deluxe_is1 - c:\program files\Sound Editor Deluxe\unins000.exe
AddRemove-{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App - c:\program files\WildTangent Games\App\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-09-20 17:03
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4,
91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,
38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4
"{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,38,12,0c,7a,63,
57,46,21,3d,68,59,52,63,2d,7c,1c,0c,5b
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{93935F7F-9C88-42F8-8445-95251D27FABC}"=hex:51,66,7a,6c,4c,1d,38,12,11,5c,80,
97,ba,d2,96,07,fb,53,d6,65,18,79,be,a8
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:30,ef,ee,bb,4a,26,cd,01
.
[HKEY_USERS\S-1-5-21-3366842975-1503843345-1045313785-1001\Software\SecuROM\License information*]
"datasecu"=hex:2d,99,bf,66,77,42,b6,f7,87,4f,81,fc,35,7a,07,40,47,56,5f,5e,01,
8d,af,28,be,5a,a0,d6,d8,b5,aa,8e,0f,bc,de,40,b9,5a,06,76,a7,93,99,a5,ee,6e,\
"rkeysecu"=hex:6f,c6,d9,04,48,5e,e8,99,8b,d6,fd,1f,ea,27,04,65
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-09-20 17:07:00
ComboFix-quarantined-files.txt 2012-09-20 21:06
.
Pre-Run: 6,882,172,928 bytes free
Post-Run: 7,290,658,816 bytes free
.
- - End Of File - - 0B2465BCAD88CF1D76F4B8E84BF36D60
 
Perfect!

Download OTL to your Desktop.
Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Scan All Users checkbox.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
 
Here are the logs for OTL. OTL:

OTL logfile created on: 9/20/2012 6:06:16 PM - Run 1
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\Admin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.05 Gb Available Physical Memory | 52.57% Memory free
4.21 Gb Paging File | 3.25 Gb Available in Paging File | 77.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.20 Gb Total Space | 7.03 Gb Free Space | 7.09% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 4.92 Gb Free Space | 49.22% Space Free | Partition Type: NTFS
Drive I: | 248.69 Mb Total Space | 248.11 Mb Free Space | 99.76% Space Free | Partition Type: FAT

Computer Name: SHIRLEYDIDOM-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/20 17:54:04 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
PRC - [2012/03/21 14:22:32 | 002,143,552 | ---- | M] (FSPro Labs) -- C:\Program Files\My Lockbox\mylbx.exe
PRC - [2011/02/01 05:54:46 | 000,185,640 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\VERIZONDM\bin\tgsrvc.exe
PRC - [2011/02/01 05:54:42 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\VERIZONDM\bin\sprtsvc.exe
PRC - [2011/02/01 05:54:30 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\VERIZONDM\bin\sprtcmd.exe
PRC - [2009/08/26 09:40:44 | 000,980,512 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Anti-Malware\a2service.exe
PRC - [2009/05/21 10:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/03/05 17:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/08/13 18:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2007/09/07 11:25:12 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stacsv.exe
PRC - [2007/09/07 11:23:36 | 000,405,504 | ---- | M] (IDT, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
PRC - [2007/08/29 14:25:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEstSrv.exe
PRC - [2007/08/29 03:54:24 | 000,072,704 | ---- | M] (Creative Labs) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
PRC - [2007/04/16 17:10:26 | 000,184,320 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Dell\MediaDirect\PCMService.exe
PRC - [2007/03/28 12:09:40 | 000,275,952 | ---- | M] (Dell) -- C:\Program Files\Dell AIO Printer A920\DLBKbmgr.exe
PRC - [2007/03/28 12:09:38 | 000,058,864 | ---- | M] (Dell) -- C:\Program Files\Dell AIO Printer A920\DLBKbmon.exe
PRC - [2007/03/28 12:08:32 | 000,538,096 | ---- | M] ( ) -- C:\Windows\System32\dlbkcoms.exe
PRC - [2007/02/20 14:01:12 | 001,125,088 | ---- | M] (Dell Inc) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2006/11/27 10:14:52 | 000,180,224 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
PRC - [2006/11/02 08:35:35 | 000,176,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpcumi.exe
PRC - [2005/06/08 13:44:22 | 000,488,960 | ---- | M] (BaroufaSoft) -- C:\Program Files\Matrix Screen Locker\matrix.exe


========== Modules (No Company Name) ==========

MOD - [2012/07/01 16:41:28 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012/07/01 16:41:17 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/07/01 15:47:49 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/07/01 15:43:01 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/07/01 15:42:35 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2010/06/30 14:03:14 | 000,051,512 | ---- | M] () -- C:\Program Files\My Lockbox\FSPFlt.dll
MOD - [2007/05/22 10:59:22 | 000,128,512 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/05/16 02:24:12 | 000,249,856 | ---- | M] () -- C:\Windows\System32\igfxTMM.dll
MOD - [2007/03/21 15:33:50 | 000,065,536 | ---- | M] () -- C:\Windows\System32\bcmwlrmt.dll
MOD - [2007/02/20 14:01:18 | 000,105,184 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2006/11/20 14:29:10 | 000,101,376 | ---- | M] () -- C:\Windows\System32\APOMngr.dll
MOD - [2006/11/13 11:07:34 | 000,066,560 | ---- | M] () -- C:\Windows\System32\CmdRtr.dll
MOD - [2003/11/26 23:27:12 | 000,014,848 | ---- | M] () -- C:\Program Files\Matrix Screen Locker\theHook.dll


========== Win32 Services (SafeList) ==========

SRV - [2012/08/04 12:26:32 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2011/02/01 05:54:46 | 000,185,640 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\VERIZONDM\bin\tgsrvc.exe -- (tgsrvc_verizondm)
SRV - [2011/02/01 05:54:42 | 000,206,120 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\VERIZONDM\bin\sprtsvc.exe -- (sprtsvc_verizondm)
SRV - [2010/12/21 17:44:00 | 003,818,640 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2010/10/12 13:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2009/08/26 09:40:44 | 000,980,512 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- C:\Program Files\a-squared Anti-Malware\a2service.exe -- (a2AntiMalware)
SRV - [2008/08/13 18:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2008/01/19 03:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/09/07 11:25:12 | 000,102,400 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\stacsv.exe -- (STacSV)
SRV - [2007/08/29 14:25:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEstSrv.exe -- (AESTFilters)
SRV - [2007/08/29 03:54:24 | 000,072,704 | ---- | M] (Creative Labs) [Auto | Running] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe -- (Creative Labs Licensing Service)
SRV - [2007/03/28 12:08:32 | 000,538,096 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\dlbkcoms.exe -- (dlbk_device)
SRV - [2007/03/19 13:44:44 | 000,070,656 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva344.sys -- (XDva344)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva281.sys -- (XDva281)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Admin\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (awg1xuvp)
DRV - [2011/07/02 22:09:13 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2010/11/06 23:24:32 | 000,020,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\PeerBlock\pbfilter.sys -- (pbfilter)
DRV - [2010/07/22 17:13:28 | 000,041,912 | ---- | M] (FSPro Labs) [File_System | Boot | Running] -- C:\Windows\System32\drivers\FSPFltd.sys -- (FSProFilter)
DRV - [2009/05/29 13:10:13 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2008/01/19 02:14:59 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2007/09/07 11:26:04 | 000,330,240 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2007/04/24 11:33:46 | 000,100,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mgmt.sys -- (s125mgmt)
DRV - [2007/04/24 11:33:46 | 000,098,696 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125obex.sys -- (s125obex)
DRV - [2007/04/24 11:33:44 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdm.sys -- (s125mdm)
DRV - [2007/04/24 11:33:42 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdfl.sys -- (s125mdfl)
DRV - [2007/04/24 11:33:34 | 000,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125bus.sys -- (s125bus)
DRV - [2007/04/03 13:59:42 | 000,099,080 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616unic.sys -- (s616unic)
DRV - [2007/04/03 13:59:42 | 000,098,568 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616obex.sys -- (s616obex)
DRV - [2007/04/03 13:59:42 | 000,023,176 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616nd5.sys -- (s616nd5)
DRV - [2007/04/03 13:59:40 | 000,100,360 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616mgmt.sys -- (s616mgmt)
DRV - [2007/04/03 13:59:38 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616mdm.sys -- (s616mdm)
DRV - [2007/04/03 13:59:36 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616mdfl.sys -- (s616mdfl)
DRV - [2007/04/03 13:59:30 | 000,083,208 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616bus.sys -- (s616bus)
DRV - [2007/02/25 13:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/11/27 03:48:46 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2006/11/27 03:48:44 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/27 03:48:44 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2006/11/21 08:25:44 | 000,045,568 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/11/02 03:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006/11/02 03:30:55 | 000,200,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2006/10/05 18:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/08/04 20:39:10 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [1999/09/10 13:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\Windows\System32\drivers\ASPI32.SYS -- (ASPI32)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...&oe={outputEncoding}&sourceid=ie7&rlz=1I7DMUS


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..\SearchScopes,DefaultScope = {FBB946EF-1996-4192-A27A-E0CC0828C49E}
IE - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...&oe={outputEncoding}&sourceid=ie7&rlz=1I7DMUS
IE - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={...06e26624de1&lang=us&ds=AVG&pr=fr&d=2012-02-14 08:30:29&v=10.0.0.7&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..\SearchScopes\{EAFCF346-F687-4CC3-ACAC-FA02D50C9F8A}: "URL" = http://us.yhs.search.yahoo.com/avg/...ahoo_avg_hs2-tb-web_chrome_us&p={searchTerms}
IE - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..\SearchScopes\{FBB946EF-1996-4192-A27A-E0CC0828C49E}: "URL" = http://search.internet-search-resul...-1996-4192-A27A-E0CC0828C49E}&s={searchTerms}
IE - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..extensions.enabledItems: avg@toolbar:10.0.0.7
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/08/04 12:26:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/08/16 10:58:04 | 000,000,000 | ---D | M]

[2008/12/18 03:20:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\Mozilla\Extensions
[2012/06/30 00:56:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vzop9hjr.default\extensions
[2010/06/19 14:46:33 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vzop9hjr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/23 03:35:40 | 000,000,000 | ---D | M] (PitchDark) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vzop9hjr.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}
[2012/06/30 00:50:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/08/04 12:26:33 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008/02/19 16:27:42 | 000,176,128 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npff_gdm.dll
[2012/07/09 11:42:24 | 000,003,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/06/14 18:19:40 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/06/14 18:19:40 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2011/05/15 23:30:12 | 000,002,223 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\websearch.xml

O1 HOSTS File: ([2012/09/20 17:03:36 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (URLHooker2 Class) - {93935F7F-9C88-42F8-8445-95251D27FABC} - C:\PROGRA~1\FLASHV~1\URLHOO~1.DLL File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..\Toolbar\WebBrowser: (no name) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - No CLSID value found.
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dlbkbmgr.exe] C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe (Dell)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [mylbx] C:\Program Files\My Lockbox\mylbx.exe (FSPro Labs)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VERIZONDM] C:\Program Files\VERIZONDM\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001..\Run: [EDesksoft Auto Update] C:\Program Files\EDesksoft\Update\EDesksoftUpdate.exe (EDesksoft Inc)
O4 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001..\Run: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC)
O4 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Matrix Screen Locker.lnk = C:\Program Files\Matrix Screen Locker\matrix.exe (BaroufaSoft)
O4 - Startup: C:\Users\Shirley DiDomenico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{08566BEC-A3A2-4754-A14F-85673F5C0482}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FB699354-B8A5-4099-B170-830788B8166C}: NameServer = 192.168.0.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\.DEFAULT\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-18\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/20 18:59:37 | 000,000,000 | ---D | C] -- C:\FRST
[2012/09/20 18:05:33 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
[2012/09/20 17:38:01 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/09/20 17:07:03 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\temp
[2012/09/20 17:05:54 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/09/20 16:43:55 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/09/20 16:43:55 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/09/20 16:43:55 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/09/20 16:43:48 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/09/20 16:43:09 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/20 16:42:14 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/09/20 14:56:22 | 004,754,465 | R--- | C] (Swearware) -- C:\Users\Admin\Desktop\ComboFix.exe
[2012/09/20 13:40:43 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Admin\Desktop\aswMBR.exe
[2012/09/20 13:37:26 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\RK_Quarantine
[2012/09/20 13:33:31 | 002,212,440 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Admin\Desktop\TDSSKiller.exe
[2012/09/20 13:32:37 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\logs
[2012/09/20 10:40:21 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Admin\Desktop\dds.com
[2012/09/19 20:10:25 | 000,000,000 | ---D | C] -- C:\found.001
[2012/09/18 23:20:45 | 000,000,000 | ---D | C] -- C:\found.000
[2012/09/16 16:02:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Bilbo
[2012/09/15 21:21:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Horror Palace
[2012/09/15 21:21:07 | 000,000,000 | ---D | C] -- C:\Program Files\Horror Palace
[2012/09/05 05:56:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Oberon Media
[2012/09/05 05:56:49 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo! Games
[2012/09/05 05:56:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Games
[2012/09/05 05:56:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Oberon Media
[2012/09/05 05:55:44 | 000,000,000 | ---D | C] -- C:\Program Files\Oberon Media
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/09/20 18:08:55 | 000,645,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/09/20 18:08:55 | 000,120,908 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/09/20 17:54:04 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
[2012/09/20 17:38:14 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/20 17:38:14 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/20 17:38:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/20 17:03:36 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/09/20 16:25:28 | 000,000,960 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3366842975-1503843345-1045313785-1000UA.job
[2012/09/20 14:53:10 | 000,001,356 | ---- | M] () -- C:\Users\Admin\AppData\Local\d3d9caps.dat
[2012/09/20 14:14:20 | 004,754,465 | R--- | M] (Swearware) -- C:\Users\Admin\Desktop\ComboFix.exe
[2012/09/20 13:09:58 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Admin\Desktop\aswMBR.exe
[2012/09/20 13:08:14 | 001,382,912 | ---- | M] () -- C:\Users\Admin\Desktop\RogueKiller.exe
[2012/09/20 10:22:04 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Admin\Desktop\dds.com
[2012/09/20 10:21:34 | 000,302,592 | ---- | M] () -- C:\Users\Admin\Desktop\tj4gwf6h.exe
[2012/09/19 19:51:00 | 006,950,656 | ---- | M] () -- C:\Users\Admin\Desktop\spybotsd_includes.exe
[2012/09/18 20:25:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3366842975-1503843345-1045313785-1000Core.job
[2012/09/17 19:25:14 | 002,212,440 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Admin\Desktop\TDSSKiller.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,006,456 | -H-- | C] () -- C:\ProgramData\lefuhove
[2012/09/20 16:43:55 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/09/20 16:43:55 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/09/20 16:43:55 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/09/20 16:43:55 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/09/20 16:43:55 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/09/20 13:37:10 | 001,382,912 | ---- | C] () -- C:\Users\Admin\Desktop\RogueKiller.exe
[2012/09/20 10:39:51 | 000,302,592 | ---- | C] () -- C:\Users\Admin\Desktop\tj4gwf6h.exe
[2012/09/19 19:50:32 | 006,950,656 | ---- | C] () -- C:\Users\Admin\Desktop\spybotsd_includes.exe
[2012/07/10 22:09:09 | 000,711,240 | ---- | C] () -- C:\Windows\is-RJP4O.exe
[2011/06/14 21:38:52 | 000,000,394 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Update.cfg
[2011/05/19 21:08:42 | 000,010,036 | -HS- | C] () -- C:\Users\Admin\AppData\Local\l8ht83hg7gd3c7q055qf1q3552
[2011/05/19 20:58:21 | 000,001,710 | -HS- | C] () -- C:\ProgramData\l8ht83hg7gd3c7q055qf1q3552
[2011/05/18 22:27:32 | 000,000,318 | ---- | C] () -- C:\Windows\wininit.ini
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/03/14 13:22:06 | 000,000,020 | ---- | C] () -- C:\Windows\GKLauncherInfo.ini
[2011/03/10 22:51:44 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2011/01/02 10:34:58 | 000,000,552 | ---- | C] () -- C:\Users\Admin\AppData\Local\d3d8caps.dat
[2010/10/13 11:20:09 | 000,001,534 | ---- | C] () -- C:\ProgramData\ss.ini
[2010/01/27 15:03:59 | 000,000,632 | RHS- | C] () -- C:\Users\Admin\ntuser.pol
[2009/09/29 09:22:28 | 000,001,356 | ---- | C] () -- C:\Users\Admin\AppData\Local\d3d9caps.dat
[2009/09/11 23:12:01 | 000,000,093 | ---- | C] () -- C:\Users\Admin\AppData\Local\fusioncache.dat
[2009/08/03 17:39:28 | 000,139,152 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\PnkBstrK.sys
[2008/07/29 17:50:50 | 000,039,936 | ---- | C] () -- C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/07/29 17:36:34 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008/03/22 16:00:52 | 000,004,904 | ---- | C] () -- C:\ProgramData\gdwkhcqj.rue

========== LOP Check ==========

[2009/02/23 17:39:35 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DAEMON Tools
[2011/07/02 22:11:24 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite
[2009/02/23 17:39:35 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DAEMON Tools Pro
[2009/10/03 01:17:08 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Developer
[2009/07/12 10:57:38 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Downloaded Installations
[2009/10/01 05:18:09 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DreamDale
[2011/05/08 23:18:45 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ElementalsTheMagicKey
[2011/07/02 22:01:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\GetRightToGo
[2009/11/01 15:02:05 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\GraveyardShift
[2009/10/01 05:14:33 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MagicBall4
[2010/05/23 17:38:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\OpenOffice.org
[2010/01/06 16:54:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Orbit
[2009/08/23 00:00:22 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Teleca
[2009/09/11 23:12:08 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Turbine
[2012/08/02 16:30:47 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\.purple
[2009/02/23 21:43:17 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\DAEMON Tools
[2011/09/01 12:03:26 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\DAEMON Tools Lite
[2009/10/03 02:50:05 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Developer
[2009/07/12 10:51:53 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Downloaded Installations
[2011/05/18 22:27:34 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\E8B9CDF0A4D6CFE265FB56A07764A72B
[2011/05/14 22:27:22 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\ElementalsTheMagicKey
[2012/09/17 21:54:17 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\foobar2000
[2009/08/01 21:15:39 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\GAMEON
[2012/09/09 13:43:13 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\gd.sos.McPixel
[2011/12/23 09:49:57 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\gtk-2.0
[2011/02/16 01:45:24 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Islands
[2012/09/05 05:57:14 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Oberon Media
[2010/04/24 11:57:32 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\OpenOffice.org
[2010/01/20 11:55:05 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Orbit
[2011/09/19 23:55:45 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Playrix Entertainment
[2009/11/09 22:30:29 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\runic games
[2011/01/01 12:43:49 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\SystemRequirementsLab
[2008/07/26 02:59:17 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Teleca
[2007/09/26 12:38:24 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Template
[2009/09/11 23:19:32 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Turbine
[2010/03/12 01:01:27 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\Unity
[2012/09/20 16:11:39 | 000,000,000 | ---D | M] -- C:\Users\Shirley DiDomenico\AppData\Roaming\uTorrent
[2012/09/19 20:15:19 | 000,032,568 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:CF39FA77
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:C46995DA

< End of report >
 
OTL Extras logfile created on: 9/20/2012 6:06:16 PM - Run 1
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\Admin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.05 Gb Available Physical Memory | 52.57% Memory free
4.21 Gb Paging File | 3.25 Gb Available in Paging File | 77.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.20 Gb Total Space | 7.03 Gb Free Space | 7.09% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 4.92 Gb Free Space | 49.22% Space Free | Partition Type: NTFS
Drive I: | 248.69 Mb Total Space | 248.11 Mb Free Space | 99.76% Space Free | Partition Type: FAT

Computer Name: SHIRLEYDIDOM-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]

[HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]

[HKEY_USERS\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1249FE17-A29D-47A1-A0DA-81699F610BEA}" = lport=49159 | protocol=6 | dir=in | name=akamai netsession interface |
"{33B94FE2-9970-4C33-AB64-89051C392C10}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{4CF2DBD2-7F01-44EE-864E-B869D2643718}" = lport=2869 | protocol=6 | dir=in | app=system |
"{AA212D0E-A0F9-4E6E-96AE-B3717B434F07}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{B8B83E6F-0056-4A89-81A8-32B0A352B4C0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B9CE2001-7ABC-4826-894D-39843969CE16}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{BB895651-CEC2-407B-8B2B-87D3040526C5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{CFAE3899-4EC5-4397-A163-F3892D3B2915}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{E63617A3-CD2A-44BF-8841-39312E0E7AF8}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{F2021F4D-3829-46A9-8C4C-E0020D2F6993}" = lport=59473 | protocol=6 | dir=in | name=akamai netsession interface |
"{F9A3781D-7992-44C2-999D-54B19E497D97}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02583CF5-79A8-4215-B3AC-3670B9E15004}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{08B18C18-6048-4B0A-B432-F1C7CD6CF698}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{0BF013A1-FC9B-4DB4-B0C2-0FF882E690E0}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{10164825-EBC9-4AC4-B0D0-731E6B9A6096}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{1300FB19-268E-4F77-8D7E-64640FC9E5D4}" = protocol=6 | dir=out | app=system |
"{26F71CF7-D6BA-49C8-AB60-238549C59C63}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{34A83659-EEE6-424E-89A1-5D82E9A41CCE}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{359B3BBD-3326-41A8-9272-5A83EF69AA3F}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{35FC34CF-32E0-47C0-BC72-18E320B16E12}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{40D56EF4-6039-43CF-A40F-3279B3F60F79}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{4227AC64-1806-4ECF-921D-E838B230F7DE}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{48E0A38A-97A2-44DC-9450-6BB42E125F79}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{526F4407-4164-4484-9609-AB1B077EFC2F}" = protocol=6 | dir=out | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{604180CB-0DA0-42AE-9D8B-AB6FEB94F96D}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{624E5349-EEB6-4F45-B8F9-15D9BA528162}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\dlbkpswx.exe |
"{6D52F42B-413E-49FE-B8A7-5685B61B2677}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\dlbkpswx.exe |
"{6FBF34FB-C878-400F-842B-A64F4C37E534}" = protocol=17 | dir=in | app=c:\windows\system32\dlbkcoms.exe |
"{705DF03B-E5F4-4258-B6B4-6E16E50C1373}" = protocol=6 | dir=in | app=c:\windows\system32\dlbkcoms.exe |
"{74602DFD-3FC1-4828-8BBF-A844856D2097}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{7F114096-B10C-45FE-8553-ED766F1D6D95}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{7F320983-9D30-4745-9311-934FDD893883}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{7F6702D6-50B6-4882-A431-B4A4C41BB225}" = protocol=6 | dir=in | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{8C21AC6F-7A97-4BE7-8297-77A3FD2F28FD}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{983DFF98-B8CA-4ED3-AB8E-254FB6B67691}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{9AA917A4-BD47-484F-9D95-125A467B1941}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{9C256B58-3226-4421-8F57-E0464AD45444}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{9E5651EF-4872-4399-B01D-57DCE376F001}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{A6B46296-C202-437B-B66A-58D791F1120D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{A735A311-5B29-4342-A7DE-EBD48B322B03}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{B05621CE-F992-4221-9E7B-8BACA9C6952D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B883973B-520A-48D0-92D8-8135BE57EC64}" = protocol=6 | dir=in | app=c:\windows\system32\wbem\unsecapp.exe |
"{BDC57D98-4B07-48B7-A2BE-2A0A1BEEE1AD}" = dir=in | app=c:\program files\dell\mediadirect\powercinema.exe |
"{BFDED1BC-D5DD-4EA8-A09F-751BB5D01D18}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C3F7A8E6-8BED-49C0-AAC4-CB7C9F358971}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{DC3720D3-2410-4CA2-BC1B-6780C3BA7439}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{F37BCD62-D6C6-46E1-8F32-F84186F6FC3F}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{F8121F94-B375-465C-8162-1D2B0D87FC14}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"TCP Query User{046760D8-FFD9-4CAF-9DFE-3E6960F7BC57}C:\program files\groove games\land of the dead\system\lotd.exe" = protocol=6 | dir=in | app=c:\program files\groove games\land of the dead\system\lotd.exe |
"TCP Query User{0C7FC70F-A38A-4862-BFD7-93798A692285}C:\program files\realore\tiny cars 2\tinycars2.exe" = protocol=6 | dir=in | app=c:\program files\realore\tiny cars 2\tinycars2.exe |
"TCP Query User{1B6D6426-29CD-40EB-A990-98B13CACECA8}C:\aeriagames\metalassault\_mas.exe" = protocol=6 | dir=in | app=c:\aeriagames\metalassault\_mas.exe |
"TCP Query User{41D1B42F-6BC9-4489-B084-9C15F77AE46E}C:\program files\turbine\the lord of the rings online\lotroclient.exe" = protocol=6 | dir=in | app=c:\program files\turbine\the lord of the rings online\lotroclient.exe |
"TCP Query User{4C2B5785-3937-4D39-BFC2-2EAD31EA1B0B}C:\program files\realore\tiny cars 2\tinycars2.exe" = protocol=6 | dir=in | app=c:\program files\realore\tiny cars 2\tinycars2.exe |
"TCP Query User{517B0875-538A-4B52-883C-1DAFC1CD08E0}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{5617E441-7770-4400-B19F-E7A03C46E6F3}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{6309C04C-DC86-4C7B-8168-D101AB295282}C:\program files\bittornado\btdownloadgui.exe" = protocol=6 | dir=in | app=c:\program files\bittornado\btdownloadgui.exe |
"TCP Query User{6CAB470A-D0B9-4D16-A946-2AD584CF782A}C:\program files\bittornado\btdownloadgui.exe" = protocol=6 | dir=in | app=c:\program files\bittornado\btdownloadgui.exe |
"TCP Query User{739AF147-4386-40A8-9A7C-16DE2E9B4742}C:\program files\turbine\ddo unlimited\dndclient.exe" = protocol=6 | dir=in | app=c:\program files\turbine\ddo unlimited\dndclient.exe |
"TCP Query User{750C40FA-28DD-4B3A-98BE-AC80647DBBC4}C:\users\shirley didomenico\appdata\local\temp\g2_635\g2viewer.exe" = protocol=6 | dir=in | app=c:\users\shirley didomenico\appdata\local\temp\g2_635\g2viewer.exe |
"TCP Query User{7C48E0FA-6987-4003-A281-201754AFE7A3}C:\program files\pidgin\pidgin.exe" = protocol=6 | dir=in | app=c:\program files\pidgin\pidgin.exe |
"TCP Query User{811A5D0F-0C24-4544-B04C-C286E1772D20}C:\program files\turbine\the lord of the rings online - public test\lotroclient.exe" = protocol=6 | dir=in | app=c:\program files\turbine\the lord of the rings online - public test\lotroclient.exe |
"TCP Query User{8B94F6B5-0356-4EFB-9763-FDC5413C8DB3}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{ABED3D31-2B05-4124-9FD9-1CC43EB1A601}C:\program files\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"TCP Query User{AD27D40A-5F49-49E1-B547-63D872F739E3}C:\users\shirley didomenico\desktop\justin\prog\utorrent.exe" = protocol=6 | dir=in | app=c:\users\shirley didomenico\desktop\justin\prog\utorrent.exe |
"TCP Query User{B2A7DCAD-4EF5-4BE9-8D27-9856C452D04D}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{B5F6507A-3AF3-4133-855A-6F3BB4938BDE}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{BDA66E30-E094-4F62-B7EC-C78B6F7ECB13}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{C6951818-5D5B-43FA-9558-8C6371F074F4}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{DA733E3F-9865-4B57-AE6D-F20C922C0D58}C:\program files\turbine\the lord of the rings online - public test\lotroclient.exe" = protocol=6 | dir=in | app=c:\program files\turbine\the lord of the rings online - public test\lotroclient.exe |
"TCP Query User{DE24185A-7F7D-4F11-B621-876E60978403}C:\users\shirley didomenico\desktop\justin\prog\utorrent.exe" = protocol=6 | dir=in | app=c:\users\shirley didomenico\desktop\justin\prog\utorrent.exe |
"UDP Query User{0565D97F-BDCA-4534-A791-3259CD8DE4B4}C:\program files\realore\tiny cars 2\tinycars2.exe" = protocol=17 | dir=in | app=c:\program files\realore\tiny cars 2\tinycars2.exe |
"UDP Query User{13380535-E366-4DB4-BCA7-FB3127BD0490}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{2EF75435-4656-4A67-B377-CE261FF37D4A}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{42F1BCE7-4A0F-472C-8DDE-C081081FADE6}C:\users\shirley didomenico\desktop\justin\prog\utorrent.exe" = protocol=17 | dir=in | app=c:\users\shirley didomenico\desktop\justin\prog\utorrent.exe |
"UDP Query User{58AE16E9-DF03-4DF8-867F-3A4798AF84C0}C:\program files\turbine\the lord of the rings online - public test\lotroclient.exe" = protocol=17 | dir=in | app=c:\program files\turbine\the lord of the rings online - public test\lotroclient.exe |
"UDP Query User{75FEC07E-710B-4779-AA9A-D3638522523A}C:\program files\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{8C910EF8-CBED-41E6-8AA4-11B5B9E0D67A}C:\program files\turbine\ddo unlimited\dndclient.exe" = protocol=17 | dir=in | app=c:\program files\turbine\ddo unlimited\dndclient.exe |
"UDP Query User{99DD37B3-5202-4DAB-9413-16D5121A8A37}C:\program files\realore\tiny cars 2\tinycars2.exe" = protocol=17 | dir=in | app=c:\program files\realore\tiny cars 2\tinycars2.exe |
"UDP Query User{9FACB636-879D-4B13-ABC8-7379943588A0}C:\users\shirley didomenico\appdata\local\temp\g2_635\g2viewer.exe" = protocol=17 | dir=in | app=c:\users\shirley didomenico\appdata\local\temp\g2_635\g2viewer.exe |
"UDP Query User{B034C1CB-B5C8-4149-83A4-FF2E718206CE}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{B4DDBA19-CF3B-42AE-B4CD-0302E231DC0D}C:\aeriagames\metalassault\_mas.exe" = protocol=17 | dir=in | app=c:\aeriagames\metalassault\_mas.exe |
"UDP Query User{B798890D-4AED-473D-A024-B50015E76ABD}C:\users\shirley didomenico\desktop\justin\prog\utorrent.exe" = protocol=17 | dir=in | app=c:\users\shirley didomenico\desktop\justin\prog\utorrent.exe |
"UDP Query User{B9BCCF40-E43A-4EA8-85FF-38A6DFB1C566}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{BAC4D679-86BA-45ED-A7C2-A4C9E3DCD0D0}C:\program files\turbine\the lord of the rings online\lotroclient.exe" = protocol=17 | dir=in | app=c:\program files\turbine\the lord of the rings online\lotroclient.exe |
"UDP Query User{BFAE0792-F94E-44A5-A521-AA8C3DE4F077}C:\program files\groove games\land of the dead\system\lotd.exe" = protocol=17 | dir=in | app=c:\program files\groove games\land of the dead\system\lotd.exe |
"UDP Query User{C504D492-8F18-422A-8C6D-64C2F045CEB7}C:\program files\bittornado\btdownloadgui.exe" = protocol=17 | dir=in | app=c:\program files\bittornado\btdownloadgui.exe |
"UDP Query User{D0C1A54F-E816-46AA-AD92-A58D4607FF76}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{E24044DE-0E1F-43E7-A885-85C2E90BF773}C:\program files\bittornado\btdownloadgui.exe" = protocol=17 | dir=in | app=c:\program files\bittornado\btdownloadgui.exe |
"UDP Query User{E2C33884-0253-48C9-93E1-6D4A8C5B0772}C:\program files\turbine\the lord of the rings online - public test\lotroclient.exe" = protocol=17 | dir=in | app=c:\program files\turbine\the lord of the rings online - public test\lotroclient.exe |
"UDP Query User{E82E0E63-F055-4BE3-8881-B8DA5A16A496}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{EE5F28EA-87F8-4AEC-913F-B357410EDDCF}C:\program files\pidgin\pidgin.exe" = protocol=17 | dir=in | app=c:\program files\pidgin\pidgin.exe |
"UDP Query User{F5C8BDFD-31C5-4AED-A427-7F88BA19C7F7}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}" = Dell System Customization Wizard
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{25BEC3AB-5CD4-481D-9143-215C1BBB189E}" = Sony Ericsson PC Suite
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 30
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{501451DE-5808-4599-B544-8BD0915B6B24}_is1" = FreeRIP v3.45
"{53C6D09E-EAB6-49E5-BA4C-BA7FF13830FB}" = Sound Blaster Audigy ADVANCED MB
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F0C4457-8E64-491B-8D7B-991504365D1E}" = QuickSet
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110265407}" = Bejeweled 2 Deluxe
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92482FB3-C05B-41C6-89E7-75D985602A6E}" = System Requirements Lab
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6BCCB80-B3FC-4E97-8513-A7BEE73A5C5A}" = Inpaint
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C01408FC-117C-44B7-8B0C-17794E526A01}" = Disc2Phone
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D547A594-AA85-4B92-80EB-47B371B98C68}" = Verizon Download Manager
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EB5F211D-85D5-44C4-BB15-1207C77EF430}" = Visual C++ 8.0 Runtime Setup Package
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F79AAB3A-B8B4-4AC7-94AB-1C4C076C6A89}" = The Simpsons Hit & Run(TM)
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"12bbe590-c890-11d9-9669-0800200c9a66_is1" = The Lord of the Rings Online™: Mines of Moria™ v02.01.03.4021
"4 Elements_is1" = 4 Elements
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Aspell English Dictionary_is1" = Aspell English Dictionary-0.50-2
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CDisplay_is1" = CDisplay 1.8
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dell AIO Printer A920" = Dell AIO Printer A920
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Exact Audio Copy" = Exact Audio Copy 0.95b3
"foobar2000" = foobar2000 v0.9.5.5
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"GNU Aspell_is1" = GNU Aspell 0.50-3
"GTK 2.0" = GTK+ Runtime 2.14.7 rev a (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Matrix Screen Locker" = Matrix Screen Locker 1.44
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"My Lockbox_is1" = My Lockbox 2.8.2
"Pidgin" = Pidgin
"screensaver_crop" = screensaver_crop
"SynTPDeinstKey" = Dell Touchpad
"TagScanner_is1" = TagScanner 5.1 build 592
"Total Privacy 5" = Total Privacy 5
"VLC media player" = VLC media player 2.0.2
"WinRAR archiver" = WinRAR archiver
"WinUtilities" = WinUtilities 6.4
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4/20/2010 1:58:25 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 4/20/2010 1:58:25 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 4/20/2010 1:58:25 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 4/20/2010 1:58:25 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 4/20/2010 1:58:26 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 4/20/2010 1:58:27 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 4/20/2010 1:58:52 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 4/20/2010 1:58:59 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 4/20/2010 1:59:01 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 4/20/2010 1:59:10 PM | Computer Name = ShirleyDiDom-PC | Source = Windows Search Service | ID = 3013
Description =

[ Media Center Events ]
Error - 12/4/2010 7:07:15 PM | Computer Name = ShirleyDiDom-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsTemplate.

[ System Events ]
Error - 9/20/2012 5:05:59 PM | Computer Name = ShirleyDiDom-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 9/20/2012 5:05:59 PM | Computer Name = ShirleyDiDom-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 9/20/2012 5:06:33 PM | Computer Name = ShirleyDiDom-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 9/20/2012 5:06:33 PM | Computer Name = ShirleyDiDom-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 9/20/2012 5:38:46 PM | Computer Name = ShirleyDiDom-PC | Source = DCOM | ID = 10000
Description =

Error - 9/20/2012 5:39:38 PM | Computer Name = ShirleyDiDom-PC | Source = DCOM | ID = 10000
Description =

Error - 9/20/2012 5:39:43 PM | Computer Name = ShirleyDiDom-PC | Source = DCOM | ID = 10016
Description =

Error - 9/20/2012 5:44:23 PM | Computer Name = ShirleyDiDom-PC | Source = DCOM | ID = 10000
Description =

Error - 9/20/2012 5:44:31 PM | Computer Name = ShirleyDiDom-PC | Source = DCOM | ID = 10000
Description =

Error - 9/20/2012 6:05:31 PM | Computer Name = ShirleyDiDom-PC | Source = DCOM | ID = 10000
Description =


< End of report >
 
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva344.sys -- (XDva344)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva281.sys -- (XDva281)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT)
    DRV - File not found [Kernel | On_Demand | Unknown] -- -- (awg1xuvp)
    IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
    IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
    IE - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..\SearchScopes\{FBB946EF-1996-4192-A27A-E0CC0828C49E}: "URL" = http://search.internet-search-resul...-1996-4192-A27A-E0CC0828C49E}&s={searchTerms}
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
    O2 - BHO: (URLHooker2 Class) - {93935F7F-9C88-42F8-8445-95251D27FABC} - C:\PROGRA~1\FLASHV~1\URLHOO~1.DLL File not found
    O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..\Toolbar\WebBrowser: (no name) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - No CLSID value found.
    O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
    O4 - Startup: C:\Users\Shirley DiDomenico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = File not found
    O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
    O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
    O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
    O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
    O15 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-21-3366842975-1503843345-1045313785-1001\..Trusted Domains: sony.com ([]* in Trusted sites)
    O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - File not found
    [2012/09/20 18:59:37 | 000,000,000 | ---D | C] -- C:\FRST
    [2011/05/19 21:08:42 | 000,010,036 | -HS- | C] () -- C:\Users\Admin\AppData\Local\l8ht83hg7gd3c7q055qf1q3552
    [2011/05/19 20:58:21 | 000,001,710 | -HS- | C] () -- C:\ProgramData\l8ht83hg7gd3c7q055qf1q3552
    @Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:CF39FA77
    @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:C46995DA
    
    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

=====================================

Last scans...

1. Download Security Check from HERE, and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

3. Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Next...

  • Double click on adwcleaner.exe to run the tool.
  • Click on Uninstall.
  • Confirm with yes.

4. Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.

5. Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
OTL fix:

All processes killed
========== OTL ==========
Service XDva344 stopped successfully!
Service XDva344 deleted successfully!
File C:\Windows\system32\XDva344.sys not found.
Service XDva281 stopped successfully!
Service XDva281 deleted successfully!
File C:\Windows\system32\XDva281.sys not found.
Service EagleNT stopped successfully!
Service EagleNT deleted successfully!
File C:\Windows\system32\drivers\EagleNT.sys not found.
Error: No service named awg1xuvp was found to stop!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\awg1xuvp deleted successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
Registry key HKEY_USERS\S-1-5-21-3366842975-1503843345-1045313785-1001\Software\Microsoft\Internet Explorer\SearchScopes\{FBB946EF-1996-4192-A27A-E0CC0828C49E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBB946EF-1996-4192-A27A-E0CC0828C49E}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93935F7F-9C88-42F8-8445-95251D27FABC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93935F7F-9C88-42F8-8445-95251D27FABC}\ deleted successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_USERS\S-1-5-21-3366842975-1503843345-1045313785-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{10CECF4F-A96E-4803-8AC2-F565FB29FF47} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10CECF4F-A96E-4803-8AC2-F565FB29FF47}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UpdReg deleted successfully.
C:\Windows\Updreg.EXE moved successfully.
C:\Users\Shirley DiDomenico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk moved successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ not found.
Registry key HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ not found.
Registry key HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ not found.
Registry key HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ not found.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3366842975-1503843345-1045313785-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL deleted successfully.
C:\FRST\Quarantine folder moved successfully.
C:\FRST\Logs folder moved successfully.
C:\FRST\Hives folder moved successfully.
C:\FRST folder moved successfully.
C:\Users\Admin\AppData\Local\l8ht83hg7gd3c7q055qf1q3552 moved successfully.
C:\ProgramData\l8ht83hg7gd3c7q055qf1q3552 moved successfully.
ADS C:\ProgramData\TEMP:CF39FA77 deleted successfully.
ADS C:\ProgramData\TEMP:C46995DA deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 74633 bytes
->Temporary Internet Files folder emptied: 11327258 bytes
->Java cache emptied: 18680048 bytes
->FireFox cache emptied: 75195243 bytes
->Flash cache emptied: 47173 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Shirley DiDomenico
->Temp folder emptied: 243752 bytes
->Temporary Internet Files folder emptied: 353450724 bytes
->Java cache emptied: 49084502 bytes
->FireFox cache emptied: 378124557 bytes
->Google Chrome cache emptied: 169987198 bytes
->Flash cache emptied: 15886051 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 68192521 bytes

Total Files Cleaned = 1,088.00 mb


[EMPTYJAVA]

User: Admin
->Java cache emptied: 0 bytes

User: All Users

User: Default

User: Default User

User: Public

User: Shirley DiDomenico
->Java cache emptied: 0 bytes

Total Java Files Cleaned = 0.00 mb


[EMPTYFLASH]

User: Admin
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: Shirley DiDomenico
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.56.0 log created on 09202012_191118

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Security Check

Results of screen317's Security Check version 0.99.51
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
a-squared Anti-Malware
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.61.0.1400
JavaFX 2.1.1
Java(TM) 6 Update 30
Java(TM) 7 Update 5
Java version out of Date!
Adobe Flash Player 11.3.300.270
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox 14.0.1 Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
a-squared Anti-Malware a2service.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 7 % Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FSS:

Farbar Service Scanner Version: 19-09-2012
Ran by Admin (administrator) on 20-09-2012 at 19:32:13
Running from "C:\Users\Admin\Desktop"
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Google IP is accessible.
Attempt to access Google.com returned error: Other errors
Yahoo IP is accessible.
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****
 
ADWCleaner:

# AdwCleaner v2.002 - Logfile created 09/20/2012 at 19:33:35
# Updated 16/09/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : Admin - SHIRLEYDIDOM-PC
# Boot Mode : Normal
# Running from : C:\Users\Admin\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****

***** [Files / Folders] *****

File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
Folder Deleted : C:\ProgramData\Trymedia

***** [Registry] *****

Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v14.0.1 (en-US)

Profile name : default
File : C:\Users\Shirley DiDomenico\AppData\Roaming\Mozilla\Firefox\Profiles\nkhfur78.default\prefs.js

Deleted : user_pref("FlashVD.cache.video", "hxxp://vids.myspace.com\nhxxp://www.yourfilehost.com\nhxxp://www.m[...]

Profile name : default
File : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vzop9hjr.default\prefs.js

Deleted : user_pref("extensions.snipit.askTbInstalled", true);

*************************

AdwCleaner[S1].txt - [2341 octets] - [20/09/2012 19:33:35]

########## EOF - C:\AdwCleaner[S1].txt - [2401 octets] ##########


ESET Scan looks like it's almost done. Will post log when it's finished.
 
ESET Scan Log:

C:\Users\Shirley DiDomenico\AppData\Roaming\E8B9CDF0A4D6CFE265FB56A07764A72B\enemies-names.txt Win32/Adware.AntimalwareDoctor.AE.Gen application cleaned by deleting - quarantined
C:\Users\Shirley DiDomenico\AppData\Roaming\E8B9CDF0A4D6CFE265FB56A07764A72B\local.ini Win32/Adware.AntimalwareDoctor.AE.Gen application cleaned by deleting - quarantined
 
Update Adobe Reader

You can download it from https://www.techspot.com/downloads/2083-adobe-reader-dc.html
After installing the latest Adobe Reader, uninstall all previous versions (if present).
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.

==============================

Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:

Code:
:OTL
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[emptyjava]
[CLEARALLRESTOREPOINTS]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post resulting log.

2. Now, we'll remove all tools, we used during our cleaning process

Clean up with OTL:

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

3. Make sure, Windows Updates are current.

4. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC) weekly.

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. (Windows XP only) Run defrag at your convenience.

11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

12. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

13. Please, let me know, how your computer is doing.
 
Back