This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Computer

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

For the last few months, my computer has been running increasingly slowly. I'm not sure if this is the right forum, because I'm not sure what's causing the slow down, but I would appreciate any insight. Below is a copy of my HijackThis log. Thank you.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:10:57 PM, on 1/26/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal

Running processes:
C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\Real\realplayer\Update\realsched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\devnz\gbpvr\GBPVRTray.exe
C:\Users\markandmary\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\markandmary\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\markandmary\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\markandmary\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\markandmary\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\markandmary\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\markandmary\AppData\Local\Google\Chrome\Application\chrome.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Users\markandmary\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\markandmary\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mas.cs.umass.edu/~msims
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\IPSBHO.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [TkBellExe] "c:\program files\real\realplayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
O4 - HKCU\..\Run: [Google Update] "C:\Users\markandmary\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: GBPVRTray.exe.lnk = ?
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{68975A08-AF32-45AA-A6B9-EB54B59AB9DB}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GB-PVR Recording Service - WelltonWay - C:\Program Files\devnz\gbpvr\GBPVRRecordingService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 10441 bytes
Hi mhs,


Let's take a deeper insight into your computer and try to determine if this slowness is malware related. But before I suggest you update your profile to show your current operative system: Windows Vista. In the upper right corner click "My Controls" and then in the left panel menu click "Edit Profile Information". Perform the necessary changes, and when finished press the "Amend my Profile" button. When finished, please follow these steps:


Step 1 | Please download OTL from one of the following mirrors:

This is THE Mirror

——————————————————————–

  • Save it to your desktop
  • RIght click on the icon and choose "Run as administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in this topic.
  • You may need two posts to fit them both in.

Step 2 | Please download GMER from one of the following locations and save it to your desktop:

Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

——————————————————————–

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Right click on the randomly named GMER file (i.e. n7gmo46c.exe) and choose "Run as administrator" to run it. Allow the gmer.sys driver to load if asked.

Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

[external image: Posted Image]

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Make sure all options are checked except:
  • IAT/EAT
  • Drives/Partition other than Systemdrive, which is typically C:\
  • Show All (This is important, so do not miss it.)

[external image: Posted Image]
Click the image to enlarge it

  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
– If you encounter any problems, try running GMER in Safe Mode.
Hi, Thank you for the reply. I have updated my profile, but when I click on the link to download the scan.txt file, the link just takes me to a page at Geeks to Go. I don't see a file called scan.txt. Anywhere.
Hi,

The link's not working for me either. Please do the following instead:


  • RIght click on OTL icon and choose "Run as administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted
  • Select All Users
  • Under the Custom Scan box paste this in:

netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

When finished, continue with GMER
Below is the text from both OTL.Txt and Extras.Txt. I'll proceed to GMER now. Thank you.

OTL logfile created on: 1/29/2011 1:47:01 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\markandmary\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.70 Gb Total Space | 130.10 Gb Free Space | 28.55% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 3.97 Gb Free Space | 39.69% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 203.03 Gb Free Space | 43.59% Space Free | Partition Type: NTFS

Computer Name: TEDDY | User Name: markandmary | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\markandmary\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Users\markandmary\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\devnz\gbpvr\PVRX2.exe (WelltonWay)
PRC - C:\Program Files\devnz\gbpvr\GBPVRRecordingService.exe (WelltonWay)
PRC - C:\Program Files\devnz\gbpvr\GBPVRTray.exe (WelltonWay)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe ()
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\markandmary\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll (Symantec Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcp90.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (CLTNetCnService) – File not found
SRV - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe (Carbonite, Inc. (www.carbonite.com))
SRV - (GoogleDesktopManager-051210-111108) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (GB-PVR Recording Service) – C:\Program Files\devnz\gbpvr\GBPVRRecordingService.exe (WelltonWay)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (HauppaugeTVServer) – C:\Program Files\WinTV\HCWTVServer.exe (Hauppauge Computer Works)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110129.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110129.003\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110114.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110128.003\IDSvix86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\N360\0403000.005\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0403000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0403000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0403000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0403000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\Windows\system32\drivers\N360\0403000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0403000.005\SYMDS.SYS (Symantec Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (hcwAVD2) – C:\Windows\System32\drivers\HCWUSB2AV.sys (Conexant Systems, Inc.)
DRV - (61883) – C:\Windows\System32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\Windows\System32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\Windows\System32\drivers\msdv.sys (Microsoft Corporation)
DRV - (MSTAPE) – C:\Windows\System32\drivers\mstape.sys (Microsoft Corporation)
DRV - (AVCSTRM) – C:\Windows\System32\drivers\avcstrm.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ATIAVPCI) – C:\Windows\System32\drivers\atinavrr.sys (ATI Technologies Inc.)
DRV - (nvrd32) – C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DRVNDDM) – C:\Windows\System32\drivers\DRVNDDM.SYS (Roxio)
DRV - (DLARTL_M) – C:\Windows\System32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\Windows\System32\drivers\DLACDBHM.SYS (Roxio)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (BCM43XV) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (DLADResM) – C:\Windows\System32\DLA\DLADResM.SYS (Roxio)
DRV - (DLAUDFAM) – C:\Windows\System32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLABMFSM) – C:\Windows\System32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\Windows\System32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAOPIOM) – C:\Windows\System32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\Windows\System32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\Windows\System32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\Windows\System32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (DRVMCDB) – C:\Windows\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (USBModem) – C:\Windows\System32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\Windows\System32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\Windows\System32\drivers\lgusbbus.sys (LG Electronics Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=3070906


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mas.cs.umass.edu/~msims
IE - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/06/02 09:07:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/04/27 11:55:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/19 08:26:08 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] c:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004..\Run: [updateMgr] File not found
O4 - Startup: C:\Users\markandmary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GBPVRTray.exe.lnk = C:\Users\markandmary\AppData\Roaming\Microsoft\Installer\{4E3C136A-F737-4CF0-9F89-538E733E8C7E}\Icon3C8F050B1.exe ()
O4 - Startup: C:\Users\maryhannah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk = File not found
O4 - Startup: C:\Users\msims\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk = File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\..Trusted Domains: localhost ([]* in Local intranet)
O15 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O15 - HKU\S-1-5-21-1722735798-1293808840-2949554827-1004\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - File not found
O24 - Desktop WallPaper: C:\Users\markandmary\Pictures\Album\2007\January\011107f.jpg
O24 - Desktop BackupWallPaper: C:\Users\markandmary\Pictures\Album\2007\January\011107f.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/29 13:19:00 | 000,000,932 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1722735798-1293808840-2949554827-1004UA.job
[2011/01/29 13:00:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/29 11:59:46 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/29 11:59:46 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/29 08:05:55 | 000,607,916 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/01/29 08:05:55 | 000,106,778 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/01/29 08:04:41 | 000,002,467 | —- | M] () – C:\Users\markandmary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GBPVRTray.exe.lnk
[2011/01/29 08:04:17 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/29 07:59:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/01/27 07:19:06 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1722735798-1293808840-2949554827-1004Core.job
[2011/01/25 20:34:26 | 000,870,128 | —- | M] () – C:\Users\markandmary\AppData\Roaming\mcs.rma
[2011/01/25 20:34:26 | 000,000,004 | —- | M] () – C:\Users\markandmary\AppData\Roaming\B07125
[2011/01/18 16:43:29 | 000,092,160 | —- | M] () – C:\Users\markandmary\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/13 12:53:08 | 000,002,079 | —- | M] () – C:\Users\markandmary\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/01/13 12:53:07 | 000,002,117 | —- | M] () – C:\Users\markandmary\Desktop\Google Chrome.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/12/01 20:39:47 | 000,000,680 | —- | C] () – C:\Users\markandmary\AppData\Local\d3d9caps.dat
[2009/11/28 15:18:03 | 000,000,000 | —- | C] () – C:\Windows\I531_1013.INI
[2009/10/20 13:00:29 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/07/08 21:42:40 | 000,870,128 | —- | C] () – C:\Users\markandmary\AppData\Roaming\mcs.rma
[2009/07/08 21:42:40 | 000,000,004 | —- | C] () – C:\Users\markandmary\AppData\Roaming\B07125
[2008/09/02 13:33:10 | 000,031,729 | —- | C] () – C:\Windows\Irremote.ini
[2008/09/02 13:32:57 | 000,065,536 | —- | C] () – C:\Windows\System32\dmcrypto.dll
[2008/09/02 13:31:31 | 000,000,209 | —- | C] () – C:\Windows\ODBCINST.INI
[2008/09/02 13:31:29 | 000,159,744 | —- | C] () – C:\Windows\System32\hcwChDB.dll
[2008/09/02 13:30:41 | 000,003,116 | —- | C] () – C:\Windows\HCWPNP.INI
[2007/10/03 20:30:30 | 000,011,776 | —- | C] () – C:\Windows\System32\pmsbfn32.dll
[2007/10/03 20:28:05 | 000,000,412 | —- | C] () – C:\Windows\MAXLINK.INI
[2007/09/26 14:30:43 | 000,348,160 | —- | C] () – C:\Windows\SQLite3VB.dll
[2007/09/22 13:34:36 | 000,000,600 | —- | C] () – C:\Users\markandmary\AppData\Local\PUTTY.RND
[2007/09/19 08:08:07 | 000,056,056 | —- | C] () – C:\Windows\System32\DLAAPI_W.DLL
[2007/09/19 08:08:05 | 000,000,120 | —- | C] () – C:\Windows\wininit.ini
[2007/09/18 08:06:51 | 000,000,000 | —- | C] () – C:\Users\markandmary\AppData\Roaming\wklnhst.dat
[2007/09/17 19:22:11 | 000,092,160 | —- | C] () – C:\Users\markandmary\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/09/17 19:01:17 | 000,000,099 | —- | C] () – C:\Users\markandmary\AppData\Local\fusioncache.dat
[2007/09/06 05:36:44 | 000,000,483 | —- | C] () – C:\Windows\ODBC.INI
[2007/03/19 04:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 04:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 04:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 04:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 04:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 04:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 04:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 04:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 04:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 04:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 04:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/07 14:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/16 22:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/07/21 13:50:34 | 000,066,048 | —- | C] () – C:\Windows\System32\hcwxds.dll

========== LOP Check ==========

[2008/03/05 09:46:20 | 000,000,000 | —D | M] – C:\Users\markandmary\AppData\Roaming\Canon
[2009/12/13 10:43:21 | 000,000,000 | —D | M] – C:\Users\markandmary\AppData\Roaming\HandBrake
[2009/06/14 21:47:26 | 000,000,000 | —D | M] – C:\Users\markandmary\AppData\Roaming\NewSoft
[2010/04/26 08:39:59 | 000,000,000 | —D | M] – C:\Users\markandmary\AppData\Roaming\OpenOffice.org
[2007/10/03 20:27:47 | 000,000,000 | —D | M] – C:\Users\markandmary\AppData\Roaming\ScanSoft
[2011/01/28 19:31:35 | 000,032,584 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007/11/14 22:22:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007/11/14 22:22:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 02:33:10 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SVCHOST.EXE >
[2006/11/02 04:45:47 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\System32\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\System32\userinit.exe
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 04:45:50 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 04:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 02:33:37 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< %systemroot%\*. /mp /s >

< End of report >


OTL Extras logfile created on: 1/29/2011 1:47:01 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\markandmary\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.70 Gb Total Space | 130.10 Gb Free Space | 28.55% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 3.97 Gb Free Space | 39.69% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 203.03 Gb Free Space | 43.59% Space Free | Partition Type: NTFS

Computer Name: TEDDY | User Name: markandmary | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{06040048-3E21-46D6-9A91-D927BA08F41D}" = Microsoft Encarta Encyclopedia Standard 2006
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{102CAC7E-912E-4801-4F0A-E6717A691EE0}" = Skins
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX700_series" = Canon MX700 series
"{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}" = Dell System Customization Wizard
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}" = Microsoft Works Suite Add-in for Microsoft Word
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{2227E1FA-01F5-483C-AB0E-2A308E900B3D}" = InterVideo FilterSDK for Hauppauge
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}" = Dell DataSafe Online
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2EAF75B6-274C-D6B7-139B-5D7021D3561E}" = Catalyst Control Center HydraVision Full
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160070}" = Java™ SE Development Kit 6 Update 7
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{3AAB901C-1374-2EB0-5285-643233C649D7}" = ccc-utility
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D7A9A89-958D-F27B-7AD4-2BC57D858FF9}" = ccc-core-static
"{3E25E350-949F-4DB7-8288-2A60E018B4C1}" = Games, Music, & Photos Launcher
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{4E3C136A-F737-4CF0-9F89-538E733E8C7E}" = GB-PVR
"{522FCB93-7B66-D4B0-57C7-6D9A0AC12701}" = Catalyst Control Center Graphics Full New
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5D95AD35-368F-47D5-B63A-A082DDF00116}" = Microsoft Digital Image Standard 2006 Editor
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{64EAE9F8-2BAB-DFEC-91A2-38AFD5F0ADB6}" = Catalyst Control Center InstallProxy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{691F4068-81BF-49E3-B32E-FE3E16400112}" = Microsoft Digital Image Standard 2006 Library
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75CBF75B-98A8-BFDD-F276-20EC77A76462}" = Catalyst Control Center Graphics Full Existing
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77DBD5BE-85F7-CE76-0F26-6F515FC6A7F7}" = CCC Help English
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{83ED1E80-A1B7-4226-BCF1-AC4A88151A6B}" = Microsoft Streets & Trips 2006
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{859F0FA7-B32B-8F6A-A74C-7BD1691E83A5}" = Catalyst Control Center Core Implementation
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{8E1AB809-F821-4F41-8431-44A11ED1EDBA}" = TVT7Diag
"{967FB716-DEFD-8F25-8822-3C7D1E16C63A}" = Catalyst Control Center Graphics Light
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5D6D068-B26F-2205-7BDA-66463B99616F}" = ATI Catalyst Install Manager
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}" = Google SketchUp 6
"{B9738203-0C53-30E5-3DB9-0C3921E6170B}" = Catalyst Control Center Localization All
"{BB82B247-7368-D37C-B659-7557194800DA}" = CCC Help German
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCC4D50D-3490-B045-0E24-910B0D59BEA6}" = CCC Help Chinese Standard
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.16
"{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E38E4893-76E4-5CB0-1349-8795D19F8BD6}" = CCC Help French
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{ED9E03B0-810E-B093-B4FD-282F59FA7EA4}" = CCC Help Spanish
"{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"{F1130B99-2D0D-C194-CF56-476B8666E889}" = ATI AVIVO Codecs
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.6
"{FBE45832-39B8-4CD3-9CF7-925D248EC264}" = Catalyst Control Center Graphics Previews Vista
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Audacity_is1" = Audacity 1.2.6
"Canon MX700 series User Registration" = Canon MX700 series User Registration
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Carbonite Backup" = Carbonite
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.514
"GUIPDFTK" = GUIPDFTK
"HandBrake" = Handbrake 0.9.4
"Hauppauge WinTV" = Hauppauge WinTV
"Hauppauge WinTV Infrared Remote" = Hauppauge WinTV Infrared Remote
"Hauppauge WinTV Radio" = Hauppauge WinTV Radio
"Hauppauge WinTV Scheduler" = Hauppauge WinTV Scheduler
"Hauppauge WinTV TV Services" = Hauppauge WinTV TV Services
"InstallShield_{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Money2006b" = Microsoft Money 2006
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"N360" = Norton Security Suite
"nanoPEG-Editor 2.6.0 for WinTV_is1" = nanoPEG-Editor 2.6.0 for WinTV
"Picasa 3" = Picasa 3
"PictureItPrem_v11" = Microsoft Digital Image Standard 2006
"RealPlayer 12.0" = RealPlayer
"V CAST Music with Rhapsody" = V CAST Music with Rhapsody
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Works2006Setup" = Microsoft Works Suite 2006 Setup Launcher

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1722735798-1293808840-2949554827-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Competition Arena" = Competition Arena
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hi, GMER seems to freeze my computer whether I run it in regular or safe mode. I followed all of your suggestions about disconnecting from the Internet and disabling real-time protection.
Hi,

Let's try something else. Please follow these steps:


Step 1 | Please download Rootkit Unhooker and save it to your Desktop

  • Right click on RKUnhookerLE and select "Run as administrator" to run it
  • Click the Report tab, then click Scan
  • Check Drivers, Stealth and uncheck the rest
  • Click OK
  • Wait until it's finished and then go to File > Save Report
  • Save the report to your Desktop
  • Copy the entire contents of the report and paste it in a reply here.

Note - you may get this warning it is ok, just ignore: "Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"



Step 2 | Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to remove older version Java components and update.

  • Click on the following link to visit java website: Java Runtime Environment (JRE) 6
  • Scroll down to where it says "JDK 6 Update 23 (JDK or JRE)".
  • Click the "Download" button to the right column (JRE).
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue. The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the recently downloaded java installer icon to install the newest version.
  • After the install is complete, go into the Control Panel
    (using Classic View) and double-click the Java Icon. (looks like a
    coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
I apologize for the delayed response. Thanks for your patience. Here is the report from Rootkit Unhooker. I'll take care of the Java Update now. RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows Vista Version 6.0.6002 (Service Pack 2) Number of processors #2 ============================================== >Drivers ============================================== 0x90409000 C:\Windows\system32\DRIVERS\atikmdag.sys 5328896 bytes (ATI Technologies Inc., ATI Radeon Kernel Mode Driver) 0x8284D000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System) 0x8284D000 PnpManager 3903488 bytes 0x8284D000 RAW 3903488 bytes 0x8284D000 WMIxWDM 3903488 bytes 0x81EC0000 Win32k 2109440 bytes 0x81EC0000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0x91856000 C:\Windows\system32\drivers\RTKVHDA.sys 1740800 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0xAD600000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110202.002\NAVEX15.SYS 1355776 bytes (Symantec Corporation, AV Engine) 0x8BE00000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver) 0x8BC05000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver) 0x9000A000 C:\Windows\system32\DRIVERS\nvmfdx32.sys 1052672 bytes (NVIDIA Corporation, NVIDIA MCP Networking Function Driver.) 0x93AF9000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver) 0x80470000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module) 0xA4475000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0xA3C02000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor) 0x9580E000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110114.001\BHDrvx86.sys 704512 bytes (Symantec Corporation, BASH Driver) 0x9091E000 C:\Windows\System32\drivers\dxgkrnl.sys 659456 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0x82F5C000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0x9012B000 C:\Windows\system32\DRIVERS\atinavrr.sys 524288 bytes (ATI Technologies Inc., ATI Unified AVStream Driver) 0x9434A000 C:\Windows\system32\drivers\N360\0403000.005\ccHPx86.sys 520192 bytes (Symantec Corporation, Common Client Hash Provider Driver) 0x80550000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic) 0x82EEB000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xA3D09000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack) 0x942A3000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver) 0xAD77D000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110131.001\IDSvix86.sys 372736 bytes (Symantec Corporation, IDS Core Driver) 0x93E1A000 C:\Windows\System32\Drivers\N360\0403000.005\SYMTDIV.SYS 364544 bytes (Symantec Corporation, Network Dispatch Driver) 0xA4591000 C:\Windows\System32\Drivers\N360\0403000.005\SRTSP.SYS 356352 bytes (Symantec Corporation, Symantec AutoProtect) 0x82E39000 C:\Windows\system32\drivers\N360\0403000.005\SYMDS.SYS 352256 bytes (Symantec Corporation, Symantec Data Store) 0xA440D000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver) 0x806A7000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0x93EAC000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x8060B000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT) 0x8042F000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver) 0x80790000 C:\Windows\system32\drivers\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver) 0x8BD76000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0x94202000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0x8BD3B000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem) 0x959AC000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0x8BF10000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0x91810000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB) 0x8281A000 ACPI_HAL 208896 bytes 0x8281A000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0x82E07000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0x93EF4000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0x901AB000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver) 0x93A01000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x82E9F000 C:\Windows\system32\drivers\N360\0403000.005\SYMEFA.SYS 184320 bytes (Symantec Corporation, Symantec Extended File Attributes) 0x8BD10000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0x909CB000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library) 0xA3CC2000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver) 0xA4553000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver) 0x943C9000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0x8BF60000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache) 0x80662000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0x93A2E000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0x93E73000 C:\Windows\system32\Drivers\SYMEVENT.SYS 151552 bytes (Symantec Corporation, Symantec Event Library) 0x807D1000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x8072F000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll) 0xA3DC1000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0x93AA6000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0x93F5D000 C:\Windows\system32\drivers\N360\0403000.005\Ironx86.SYS 126976 bytes (Symantec Corporation, Iron Driver) 0x9598D000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0x80758000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension) 0x94301000 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 118784 bytes (Symantec Corporation, Symantec Eraser Utility Driver) 0xA3D76000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver) 0x93BE3000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0x95904000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver) 0x93A53000 C:\Windows\system32\drivers\AtiHdmi.sys 106496 bytes (ATI Research Inc., Ati High Definition Audio Function Driver) 0x958D1000 C:\Windows\System32\Drivers\dump_nvstor32.sys 106496 bytes 0x80776000 C:\Windows\system32\drivers\nvstor32.sys 106496 bytes (NVIDIA Corporation, NVIDIA® nForce™ Sata Performance Driver) 0xA3D93000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0x80716000 C:\Windows\system32\drivers\nvraid.sys 102400 bytes (NVIDIA Corporation, NVIDIA® nForce™ RAID Driver) 0x9010D000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0x9592B000 C:\Windows\System32\DLA\DLAIFS_M.SYS 98304 bytes (Roxio, Drive Letter Access Component) 0xA3DE2000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0x94333000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver) 0x9596E000 C:\Windows\System32\DLA\DLAUDF_M.SYS 94208 bytes (Roxio, Drive Letter Access Component) 0x901E5000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xAD763000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver) 0x95958000 C:\Windows\System32\DLA\DLAUDFAM.SYS 90112 bytes (Roxio, Drive Letter Access Component) 0x82ECC000 C:\Windows\System32\Drivers\DRVMCDB.SYS 90112 bytes (Sonic Solutions, Device Driver) 0x93F26000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler) 0x93E04000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver) 0x93F7C000 C:\Windows\system32\DRIVERS\usbcir.sys 90112 bytes (Microsoft Corporation, USB Consumer IR Driver for eHome) 0xA3DAC000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver) 0x805D9000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager) 0x9431E000 C:\Windows\system32\DRIVERS\USBSTOR.SYS 86016 bytes (Microsoft Corporation, USB Mass Storage Class Driver) 0xAD74B000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110202.002\NAVENG.SYS 81920 bytes (Symantec Corporation, AV Engine) 0x82FE9000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0x93E98000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver) 0xA3CF6000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0x93F4A000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0x8BF87000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0x91845000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy) 0x80416000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver) 0x8BFE6000 C:\Windows\system32\DRIVERS\amdk8.sys 65536 bytes (Microsoft Corporation, Processor Device Driver) 0x82E8F000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver) 0x93F9D000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library) 0xA3CB2000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0x80706000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager) 0x8BDC3000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0x805EE000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver) 0x958F5000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver) 0x8BF51000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0x80689000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver) 0x8BDEC000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0x8BDB4000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0x80698000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver) 0x8BDD3000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0x82100000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver) 0x80400000 C:\Windows\system32\DRIVERS\circlass.sys 57344 bytes (Microsoft Corporation, Consumer IR Class Driver for eHome) 0x93F3C000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0x93AE2000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0x806F8000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0x958BA000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0x91803000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0x805CC000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR) 0xA4585000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0x93A9A000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0x909BF000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver) 0x9591F000 C:\Windows\System32\Drivers\DRVNDDM.SYS 45056 bytes (Roxio, Device Driver Manager) 0x93F92000 C:\Windows\system32\DRIVERS\hidir.sys 45056 bytes (Microsoft Corporation, Infrared Miniport Driver for Input Devices) 0x807F4000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver) 0x80600000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver) 0x93AD7000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0x8BDE1000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0x901DA000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0x8BFD2000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x958C7000 C:\Windows\System32\Drivers\dump_diskdump.sys 40960 bytes 0x958EB000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0x90000000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0xA3CEC000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver) 0x9423E000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0xA457B000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0x93FC7000 C:\Windows\system32\drivers\N360\0403000.005\SRTSPX.SYS 40960 bytes (Symantec Corporation, Symantec AutoProtect) 0x8BFF6000 C:\Windows\system32\DRIVERS\usbohci.sys 40960 bytes (Microsoft Corporation, OHCI USB Miniport Driver) 0x8BF98000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver) 0x93A6D000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0x93FBE000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0x93FAD000 C:\Windows\system32\DRIVERS\kbdhid.sys 36864 bytes (Microsoft Corporation, HID Keyboard Filter Driver) 0xAD7D8000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0x82EE2000 C:\Windows\System32\Drivers\PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0x93AF0000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0x820E0000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0x8BFDD000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x80651000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0x80750000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0x80427000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0x93FB6000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0x8065A000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0x93AC7000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x93ACF000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x90400000 C:\Windows\system32\DRIVERS\serscan.sys 32768 bytes (Microsoft Corporation, Serial Imaging Device Driver) 0x8BF49000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor) 0x93A7D000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0x9594A000 C:\Windows\System32\DLA\DLABMFSM.SYS 28672 bytes (Roxio, Drive Letter Access Component) 0x95951000 C:\Windows\System32\DLA\DLABOIOM.SYS 28672 bytes (Roxio, Drive Letter Access Component) 0x93A93000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0x8040F000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0x93A76000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0x806F1000 C:\Windows\system32\drivers\pciide.sys 28672 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0x93A84000 C:\Windows\System32\Drivers\DLARTL_M.SYS 24576 bytes (Roxio, Shared Driver Component) 0x90125000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0x95943000 C:\Windows\System32\DLA\DLAOPIOM.SYS 20480 bytes (Roxio, Drive Letter Access Component) 0x909F5000 C:\Windows\system32\DRIVERS\NCREMOTEPCI.SYS 16384 bytes (PLX Technology, Inc. (visit www.PlxTech.com), Remote PCI (RPCI) driver library (x86)) 0x909FB000 C:\Windows\system32\DRIVERS\BdaSup.SYS 12288 bytes (Microsoft Corporation, Microsoft BDA Driver Support Library) 0x9010B000 C:\Windows\System32\Drivers\DLACDBHM.SYS 8192 bytes (Roxio, Shared Driver Component) 0x95948000 C:\Windows\System32\DLA\DLAPoolM.SYS 8192 bytes (Roxio, Drive Letter Access Component) 0xAD779000 C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys 8192 bytes (Gteko Ltd., Process Trigger Driver) 0xA4473000 C:\Windows\system32\DRIVERS\dsunidrv.sys 8192 bytes (Gteko Ltd., GUniDriver) 0xAD77B000 C:\Windows\system32\drivers\MSPQM.sys 8192 bytes (Microsoft Corporation, MS Proxy Quality Manager) 0x909FE000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0x909F9000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0x9592A000 C:\Windows\System32\DLA\DLADResM.SYS 4096 bytes (Roxio, Drive Letter Access Component) ============================================== >Stealth ============================================== 0x00910000 Hidden Image–>CLI.Foundation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 102400 bytes 0x06B50000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Wizard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 102400 bytes 0x07770000 Hidden Image–>CLI.Aspect.DisplaysOptions.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 102400 bytes 0x05520000 Hidden Image–>CLI.Caste.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 110592 bytes 0x007A0000 Hidden Image–>MOM.Implementation.DLL [ EPROCESS 0x8A14CD90 ] PID: 2104, 118784 bytes 0x00ED0000 Hidden Image–>MOM.Implementation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 118784 bytes 0x07CF0000 Hidden Image–>CLI.Component.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 1224704 bytes 0x003A0000 Hidden Image–>GBPVRPublic.dll [ EPROCESS 0x89A40BF8 ] PID: 380, 151552 bytes 0x00280000 Hidden Image–>GBPVRPublic.dll [ EPROCESS 0x8A071020 ] PID: 2488, 151552 bytes 0x00D70000 Hidden Image–>GBPVRPublic.dll [ EPROCESS 0x89D1ED90 ] PID: 4068, 151552 bytes 0x08210000 Hidden Image–>CLI.Aspect.DisplaysManager.Graphics.Wizard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 1740800 bytes 0x076E0000 Hidden Image–>CLI.Aspect.InfoCentre.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 208896 bytes 0x074A0000 Hidden Image–>CLI.Aspect.InfoCentre.Graphics.Wizard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 217088 bytes 0x07720000 Hidden Image–>CLI.Aspect.CrossDisplay.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 282624 bytes 0x01B30000 Hidden Image–>SupportSoft.Agent.Sprocket.dll [ EPROCESS 0x8986F020 ] PID: 3844, 28672 bytes 0x00B60000 Hidden Image–>MOM.Foundation.DLL [ EPROCESS 0x8A14CD90 ] PID: 2104, 28672 bytes 0x00BA0000 Hidden Image–>LOG.Foundation.Implementation.Private.DLL [ EPROCESS 0x8A14CD90 ] PID: 2104, 28672 bytes 0x008C0000 Hidden Image–>MOM.Foundation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x00A50000 Hidden Image–>LOG.Foundation.Implementation.Private.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x00F50000 Hidden Image–>CLI.Component.Runtime.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x00FD0000 Hidden Image–>AEM.Server.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x041D0000 Hidden Image–>AEM.Plugin.Hotkeys.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x041B0000 Hidden Image–>AEM.Plugin.DPPE.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x041E0000 Hidden Image–>AEM.Plugin.WinMessages.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x04DC0000 Hidden Image–>DEM.Foundation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x04ED0000 Hidden Image–>DEM.Graphics.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x050E0000 Hidden Image–>CLI.Caste.HydraVision.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x05600000 Hidden Image–>AEM.Plugin.GD.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x05410000 Hidden Image–>AEM.Actions.CCAA.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x055C0000 Hidden Image–>DEM.Graphics.I0709.dll [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x055F0000 Hidden Image–>ResourceManagement.Foundation.Private.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x05670000 Hidden Image–>DEM.Graphics.I0804.dll [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x057E0000 Hidden Image–>CLI.Caste.Graphics.Runtime.Shared.Private.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x05820000 Hidden Image–>DEM.Graphics.I0805.dll [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x05850000 Hidden Image–>DEM.Graphics.I0706.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x058A0000 Hidden Image–>CLI.Aspect.HotkeysHandling.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x05890000 Hidden Image–>CLI.Aspect.HotkeysHandling.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x05DD0000 Hidden Image–>DEM.Graphics.I0712.dll [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x05F00000 Hidden Image–>DEM.Graphics.I0812.dll [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x06000000 Hidden Image–>APM.Foundation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x06070000 Hidden Image–>CLI.Component.Runtime.Extension.EEU.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x06060000 Hidden Image–>AEM.Plugin.REG.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x060D0000 Hidden Image–>CLI.Component.Client.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x060C0000 Hidden Image–>AEM.Plugin.EEU.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x066E0000 Hidden Image–>CLI.Component.Wizard.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x06A20000 Hidden Image–>CLI.Caste.Graphics.Wizard.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x06B70000 Hidden Image–>atixclib.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x07490000 Hidden Image–>Branding.dll [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x074F0000 Hidden Image–>CLI.Caste.HydraVision.Wizard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x07610000 Hidden Image–>CLI.Component.Dashboard.Shared.Private.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x076C0000 Hidden Image–>CLI.Caste.Graphics.Dashboard.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x079E0000 Hidden Image–>CLI.Caste.HydraVision.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 28672 bytes 0x00960000 Hidden Image–>GBPVRBackendCommon.dll [ EPROCESS 0x89A40BF8 ] PID: 380, 339968 bytes 0x00A40000 Hidden Image–>GBPVRBackendCommon.dll [ EPROCESS 0x8A071020 ] PID: 2488, 339968 bytes 0x08780000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 339968 bytes 0x00DE0000 Hidden Image–>GBPVRBackendCommon.dll [ EPROCESS 0x89D1ED90 ] PID: 4068, 339968 bytes 0x05550000 Hidden Image–>CLI.Caste.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 348160 bytes 0x01A40000 Hidden Image–>NEWAEM.Foundation.DLL [ EPROCESS 0x8A14CD90 ] PID: 2104, 36864 bytes 0x00DB0000 Hidden Image–>CLI.Foundation.XManifest.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x00FC0000 Hidden Image–>NEWAEM.Foundation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x050D0000 Hidden Image–>CLI.Caste.HydraVision.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x05800000 Hidden Image–>CLI.Aspect.CustomFormats.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x059C0000 Hidden Image–>CLI.Aspect.DisplaysColour2.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x05A10000 Hidden Image–>CLI.Aspect.DisplaysOptions.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x05D80000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x05FC0000 Hidden Image–>CLI.Aspect.PowerPlayDPPE.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x06900000 Hidden Image–>CLI.Component.Wizard.Shared.Private.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x075C0000 Hidden Image–>CLI.Component.Dashboard.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 36864 bytes 0x08720000 Hidden Image–>CLI.Aspect.DeviceDFP.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 372736 bytes 0x05B70000 Hidden Image–>NativeUtilities.dll [ EPROCESS 0x89A40BF8 ] PID: 380, 3899392 bytes 0x04A40000 Hidden Image–>NativeUtilities.dll [ EPROCESS 0x8A071020 ] PID: 2488, 3899392 bytes 0x086B0000 Hidden Image–>CLI.Aspect.DeviceCRT.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 405504 bytes 0x06F30000 Hidden Image–>CLI.Component.Wizard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 413696 bytes 0x07220000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Wizard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 421888 bytes 0x015B0000 Hidden Image–>SupportSoft.Agent.Sprocket.SupportMessage.dll [ EPROCESS 0x8986F020 ] PID: 3844, 45056 bytes 0x007D0000 Hidden Image–>LOG.Foundation.DLL [ EPROCESS 0x8A14CD90 ] PID: 2104, 45056 bytes 0x007F0000 Hidden Image–>LOG.Foundation.Private.DLL [ EPROCESS 0x8A14CD90 ] PID: 2104, 45056 bytes 0x00E10000 Hidden Image–>CCC.Implementation.DLL [ EPROCESS 0x8A14CD90 ] PID: 2104, 45056 bytes 0x002F0000 Hidden Image–>CCC.Implementation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 45056 bytes 0x008B0000 Hidden Image–>LOG.Foundation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 45056 bytes 0x00BF0000 Hidden Image–>LOG.Foundation.Private.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 45056 bytes 0x00F70000 Hidden Image–>ATICCCom.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 45056 bytes 0x05880000 Hidden Image–>CLI.Aspect.DeviceProperty.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 45056 bytes 0x05A00000 Hidden Image–>CLI.Aspect.DisplaysOptions.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 45056 bytes 0x05D60000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 45056 bytes 0x05D70000 Hidden Image–>CLI.Aspect.DeviceProperty.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 45056 bytes 0x06FA0000 Hidden Image–>CLI.Aspect.TransCode.Graphics.Wizard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 503808 bytes 0x00B70000 Hidden Image–>System.Data.SQLite.dll [ EPROCESS 0x89A40BF8 ] PID: 380, 507904 bytes 0x053F0000 Hidden Image–>System.Data.SQLite.dll [ EPROCESS 0x8A071020 ] PID: 2488, 507904 bytes 0x01F70000 Hidden Image–>System.Data.SQLite.dll [ EPROCESS 0x89D1ED90 ] PID: 4068, 507904 bytes 0x00F30000 Hidden Image–>CLI.Component.Runtime.Shared.Private.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x00F40000 Hidden Image–>CLI.Foundation.Private.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x00FB0000 Hidden Image–>AEM.Server.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x00FF0000 Hidden Image–>AEM.Plugin.Source.Kit.Server.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x04C30000 Hidden Image–>DEM.Graphics.I0601.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x059B0000 Hidden Image–>CLI.Aspect.DisplaysColour2.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x057F0000 Hidden Image–>CLI.Aspect.DeviceCV.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x05A20000 Hidden Image–>CLI.Aspect.DeviceCRT.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x05FB0000 Hidden Image–>CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x06080000 Hidden Image–>CLI.Component.Client.Shared.Private.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x06A10000 Hidden Image–>CLI.Caste.Graphics.Wizard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x06A40000 Hidden Image–>CLI.Aspect.TransCode.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x076D0000 Hidden Image–>CLI.Aspect.Welcome.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 53248 bytes 0x06EA0000 Hidden Image–>CLI.Component.Systemtray.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 561152 bytes 0x087E0000 Hidden Image–>CLI.Aspect.DisplaysColour2.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 585728 bytes 0x05A30000 Hidden Image–>CLI.Aspect.DeviceCRT.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 61440 bytes 0x05DB0000 Hidden Image–>CLI.Aspect.DeviceDFP.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 61440 bytes 0x05F30000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 61440 bytes 0x05F90000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 61440 bytes 0x073C0000 Hidden Image–>ResourceManagement.Foundation.Implementation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 659456 bytes 0x00EF0000 Hidden Image–>CLI.Component.SkinFactory.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 69632 bytes 0x00F10000 Hidden Image–>CLI.Component.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 69632 bytes 0x00F80000 Hidden Image–>ADL.Foundation.dll [ EPROCESS 0x8A3365C0 ] PID: 3996, 69632 bytes 0x05D90000 Hidden Image–>CLI.Aspect.DeviceDFP.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 69632 bytes 0x05EE0000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 69632 bytes 0x05FE0000 Hidden Image–>APM.Server.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 69632 bytes 0x00810000 Hidden Image–>sprtmessage.dll [ EPROCESS 0x8986F020 ] PID: 3844, 77824 bytes 0x00860000 Hidden Image–>LOG.Foundation.Implementation.DLL [ EPROCESS 0x8A14CD90 ] PID: 2104, 77824 bytes 0x00BC0000 Hidden Image–>LOG.Foundation.Implementation.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 77824 bytes 0x056C0000 Hidden Image–>CLI.Aspect.DeviceCV.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 77824 bytes 0x05860000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Shared.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 77824 bytes 0x08B00000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 790528 bytes 0x05830000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 86016 bytes 0x076A0000 Hidden Image–>CLI.Caste.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 86016 bytes 0x002D0000 Hidden Image–>PVRUiPublic.dll [ EPROCESS 0x8A071020 ] PID: 2488, 94208 bytes 0x05F50000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Runtime.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 94208 bytes 0x085C0000 Hidden Image–>CLI.Aspect.DisplaysManager2.Graphics.Dashboard.DLL [ EPROCESS 0x8A3365C0 ] PID: 3996, 962560 bytes
Hi there,


Please follow the steps below in order:


Step 1 | Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    
    :Commands
    [purity]
    [EmptyFlash]
    [emptytemp]
    [createrestorepoint]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • It will produce a log for you on reboot, please post that log in your next reply.

Step 2 | Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

Step 3 | Let's perform an ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go here then click on: [external image: Posted Image]
    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed make sure you first copy the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic.
  • Now click on: [external image: Posted Image] (Selecting Uninstall application on close if you so wish)


Please post back including:

OTL log
Malwarebyte's Antimalware log
ESET Online Scan log
Below are the OTL log and the Malwarebytes log. I will do the ESET scan tomorrow. Thank you. All processes killed ========== OTL ========== ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User: Default User User: markandmary ->Flash cache emptied: 207294 bytes User: maryhannah User: msims ->Flash cache emptied: 1035 bytes User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: markandmary ->Temp folder emptied: 667154 bytes ->Temporary Internet Files folder emptied: 2908452 bytes ->Java cache emptied: 316 bytes ->Google Chrome cache emptied: 110373490 bytes ->Flash cache emptied: 0 bytes User: maryhannah ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 402 bytes User: msims ->Temp folder emptied: 9429084 bytes ->Temporary Internet Files folder emptied: 804 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2358832 bytes RecycleBin emptied: 5252475 bytes Total Files Cleaned = 125.00 mb OTL by OldTimer - Version 3.2.20.6 log created on 02032011_154254 Files\Folders moved on Reboot… Registry entries deleted on Reboot… Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5680 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18999 2/4/2011 7:44:31 PM mbam-log-2011-02-04 (19-44-31).txt Scan type: Quick scan Objects scanned: 172150 Time elapsed: 5 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Sorry. I still haven't completed it. Just as it was finishing yesterday, we had a power outage. I'm about to restart it. Thanks again for your patience.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI