This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Fake Windows Defender

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Windows Defender suddenly began popping up and warning me of multiple threats (trojans, worms, keyloggers, etc.). After running Symantec and Malware and finding nothing, I decided to google the program and found that it's a cheap imitation of the program and can't be turn off. I cannot access or delete it through the Control Panel and it won't be turned off through its own "Tools" option.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:35:05 AM, on 4/12/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\USB Camera\VM331_STI.EXE
C:\Program Files (x86)\ID Vault\IDVault.exe
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe
C:\Program Files (x86)\SFT\GuardedID\GIDD.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\windows\SysWOW64\rundll32.exe
C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Hotspot Shield\bin\openvpntray.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTE.EXE
C:\Users\The\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\The\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\SysWOW64\rundll32.exe
C:\Users\The\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\The\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: GuardId.MSIEBrowser.BHO - {5b0a01d2-b8a0-4e56-9e6b-cba0ef4b4eb5} - mscoree.dll (file missing)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Hotspot Shield - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHot0.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHot0.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331_STI.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0"
O4 - HKLM\..\Run: [YouCam Mirror Tray icon] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [GIDDesktop] C:\Program Files (x86)\SFT\GuardedID\gidd.exe /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [RegWork] C:\Program Files (x86)\RegWork\RegWork.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\The\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [8a20288c-45f6-4e38-9aba-510671b53074] rundll32.exe "C:\ProgramData\8a20288c-45f6-4e38-9aba-510671b53074.dat", ypbxwmwqw
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: ID Vault.lnk = C:\Program Files (x86)\ID Vault\IDVault.exe
O4 - Global Startup: Lenovo Smile Dock.lnk = C:\Program Files (x86)\DDNi\Lenovo Smile Dock\Delay.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{007C9D54-1894-4DC7-8D9F-C4D8201BF272}: NameServer = 10.24.40.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{007C9D54-1894-4DC7-8D9F-C4D8201BF272}: NameServer = 10.24.40.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{007C9D54-1894-4DC7-8D9F-C4D8201BF272}: NameServer = 10.24.40.1
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IDVault Service (IDVaultSvc) - White Sky, Inc. - C:\Program Files (x86)\ID Vault\IDVaultSvc.exe
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo ReadyComm AppSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\AppSvc.exe
O23 - Service: Lenovo ReadyComm ConnSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~2\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: Oasis2Service - Unknown owner - C:\Program Files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 14634 bytes
Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

1) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

2) GMER
Please download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and put it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


3) What You Will Need To Post:
  • DDS logs
  • GMER log
1) MCPR
Please download the McAfee Consumer Product Removal Tool to your desktop.
  • Right-click on MCPR.exe and click Run as Administrator
  • Restart your computer after running the tool.

2) Combofix
Download Combofix to your desktop from any of the links below.

Link 1
Link 2


==================================

Disable Symantec Endpoint Protection, then double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

3) What You Will Need To Post:
  • Combofix log
ComboFix 11-04-13.02 - The 04/13/2011 18:34:15.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3959.2712 [GMT -7:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\8a20288c-45f6-4e38-9aba-510671b53074.dat c:\programdata\FullRemove.exe c:\windows\s.bat . . ((((((((((((((((((((((((( Files Created from 2011-03-14 to 2011-04-14 ))))))))))))))))))))))))))))))) . . 2011-04-14 01:37 . 2011-04-14 01:37 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-04-12 08:31 . 2011-04-12 08:31 ——– d—–w- c:\program files (x86)\Trend Micro 2011-04-10 04:28 . 2010-12-21 01:09 38224 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-04-10 04:28 . 2011-04-10 04:28 ——– d—–w- c:\programdata\Malwarebytes 2011-04-10 04:28 . 2011-04-13 02:35 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-04-10 04:28 . 2010-12-21 01:08 24152 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-04-10 04:11 . 2011-03-23 17:11 8424784 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{691DA5B2-4B83-42DA-BACD-377205D3A74E}\mpengine.dll 2011-03-25 19:33 . 2011-03-25 19:33 ——– dc—-w- c:\windows\system32\DRVSTORE 2011-03-25 19:33 . 2009-05-18 20:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-03-25 19:33 . 2008-04-17 19:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-03-25 19:33 . 2008-04-17 19:12 107368 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-03-25 19:33 . 2011-03-25 19:33 ——– d—–w- c:\program files\iPod 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001} 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\program files\iTunes 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\program files (x86)\iTunes 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-03-25 19:30 . 2011-03-25 19:31 ——– d—–w- c:\program files (x86)\QuickTime 2011-03-25 19:30 . 2011-03-25 19:32 ——– d—–w- c:\programdata\Apple Computer 2011-03-25 19:29 . 2011-03-25 19:29 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-03-25 19:29 . 2011-03-25 19:29 ——– d—–w- c:\program files\Common Files\Apple 2011-03-25 19:28 . 2011-03-25 19:29 ——– d—–w- c:\program files\Bonjour 2011-03-25 19:28 . 2011-03-25 19:29 ——– d—–w- c:\program files (x86)\Bonjour 2011-03-25 19:28 . 2011-03-25 21:02 ——– d—–w- c:\programdata\Apple 2011-03-25 19:28 . 2011-03-25 19:33 ——– d—–w- c:\program files (x86)\Common Files\Apple 2011-03-25 02:35 . 2011-03-25 02:35 ——– d—–w- c:\programdata\RegWork 2011-03-25 02:31 . 2011-03-25 02:31 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-03-25 02:29 . 2011-03-25 02:29 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-03-25 02:29 . 2011-03-25 02:29 ——– d—–w- c:\program files (x86)\Java 2011-03-24 21:02 . 2011-03-24 21:02 ——– d—–w- c:\windows\SysWow64\Wat 2011-03-24 21:02 . 2011-03-24 21:02 ——– d—–w- c:\windows\system32\Wat 2011-03-24 18:53 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll 2011-03-24 18:53 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll 2011-03-24 18:48 . 2009-11-25 19:47 99176 —-a-w- c:\windows\SysWow64\PresentationHostProxy.dll 2011-03-24 18:48 . 2009-11-25 19:47 49472 —-a-w- c:\windows\SysWow64\netfxperf.dll 2011-03-24 18:48 . 2009-11-25 19:47 297808 —-a-w- c:\windows\SysWow64\mscoree.dll 2011-03-24 18:48 . 2009-11-25 19:47 295264 —-a-w- c:\windows\SysWow64\PresentationHost.exe 2011-03-24 18:48 . 2009-11-25 19:47 1130824 —-a-w- c:\windows\SysWow64\dfshim.dll 2011-03-24 18:48 . 2009-11-25 19:47 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll 2011-03-24 18:48 . 2009-11-25 19:47 444752 —-a-w- c:\windows\system32\mscoree.dll 2011-03-24 18:48 . 2009-11-25 19:47 320352 —-a-w- c:\windows\system32\PresentationHost.exe 2011-03-24 18:48 . 2009-11-25 19:47 48960 —-a-w- c:\windows\system32\netfxperf.dll 2011-03-24 18:48 . 2009-11-25 19:47 1942856 —-a-w- c:\windows\system32\dfshim.dll 2011-03-24 18:42 . 2010-03-04 04:40 184832 —-a-w- c:\windows\system32\drivers\usbvideo.sys 2011-03-24 18:42 . 2010-03-04 04:32 243712 —-a-w- c:\windows\system32\drivers\ks.sys 2011-03-23 02:14 . 2011-04-01 23:07 ——– d—–w- c:\program files (x86)\VitalSource Bookshelf 2011-03-23 00:25 . 2011-01-07 08:07 662528 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-23 00:25 . 2011-01-07 07:31 442880 —-a-w- c:\windows\SysWow64\XpsPrint.dll 2011-03-23 00:25 . 2011-01-07 08:07 475648 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-03-23 00:25 . 2011-01-07 07:31 288256 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2011-03-23 00:25 . 2010-08-21 06:29 558592 —-a-w- c:\windows\system32\spoolsv.exe 2011-03-23 00:23 . 2010-12-23 06:07 723968 —-a-w- c:\windows\system32\EncDec.dll 2011-03-23 00:22 . 2011-01-05 04:00 3127808 —-a-w- c:\windows\system32\win32k.sys 2011-03-23 00:22 . 2010-03-04 07:57 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-23 00:22 . 2010-03-04 07:57 2080256 —-a-w- c:\program files\Windows Mail\msoe.dll 2011-03-23 00:22 . 2010-03-04 07:33 1619968 —-a-w- c:\program files (x86)\Windows Mail\msoe.dll 2011-03-23 00:22 . 2010-03-04 07:33 740864 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-03-23 00:22 . 2010-08-04 07:07 552960 —-a-w- c:\windows\system32\msdri.dll 2011-03-23 00:22 . 2010-08-04 07:05 288256 —-a-w- c:\windows\system32\MSNP.ax 2011-03-23 00:22 . 2010-08-04 06:15 204288 —-a-w- c:\windows\SysWow64\MSNP.ax 2011-03-23 00:22 . 2010-08-21 06:36 340992 —-a-w- c:\windows\system32\schannel.dll 2011-03-23 00:22 . 2010-08-21 05:36 224256 —-a-w- c:\windows\SysWow64\schannel.dll 2011-03-23 00:22 . 2010-08-21 06:31 633856 —-a-w- c:\windows\system32\comctl32.dll 2011-03-23 00:22 . 2010-08-21 05:33 530432 —-a-w- c:\windows\SysWow64\comctl32.dll 2011-03-23 00:20 . 2010-11-02 05:12 1837568 —-a-w- c:\windows\system32\d3d10warp.dll 2011-03-23 00:19 . 2010-10-27 05:18 5510528 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-03-23 00:18 . 2010-10-16 04:33 987136 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll 2011-03-23 00:18 . 2010-10-16 04:33 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll 2011-03-23 00:18 . 2010-10-16 04:33 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll 2011-03-23 00:18 . 2010-10-16 04:33 208896 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll 2011-03-23 00:18 . 2010-08-27 03:38 463360 —-a-w- c:\windows\system32\drivers\srv.sys 2011-03-23 00:18 . 2010-08-27 03:37 402944 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-03-23 00:18 . 2010-08-27 06:14 236032 —-a-w- c:\windows\system32\srvsvc.dll 2011-03-23 00:18 . 2010-08-27 05:46 9728 —-a-w- c:\windows\SysWow64\sscore.dll 2011-03-23 00:18 . 2010-08-27 03:37 161792 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-03-23 00:11 . 2011-03-23 00:12 ——– dc-h–w- c:\programdata\{DC88B4E9-0A30-46AE-A4D5-38E7C0D304E4} 2011-03-22 06:46 . 2011-03-22 06:46 ——– d—–w- c:\programdata\Oberon Media 2011-03-22 06:06 . 2011-03-22 06:06 ——– d—–w- c:\program files (x86)\Common Files\Oberon Media 2011-03-22 06:06 . 2011-03-22 06:44 ——– d—–w- c:\program files (x86)\Oberon Media 2011-03-22 06:06 . 2011-04-10 03:42 ——– d—–w- c:\program files (x86)\Lenovo Games 2011-03-22 05:59 . 2011-03-22 05:59 ——– d—–w- c:\programdata\hssff 2011-03-22 05:55 . 2010-09-20 17:14 65816 ——w- c:\windows\system32\GIDLogonCP64.dll 2011-03-22 05:55 . 2010-09-20 17:13 442656 ——w- c:\windows\system32\GIDHookLogon64.dll 2011-03-22 05:48 . 2011-03-22 05:48 ——– d—–w- c:\programdata\IsolatedStorage 2011-03-22 05:47 . 2010-09-20 17:09 29288 ——w- c:\windows\system32\drivers\gidv2.sys 2011-03-22 05:47 . 2009-06-12 23:32 109064 ——w- c:\windows\system32\EasyHook64.dll 2011-03-22 05:47 . 2010-09-20 17:13 458520 ——w- c:\windows\system32\GIDHOOK64.DLL 2011-03-22 05:47 . 2010-09-20 17:12 100624 ——w- c:\windows\system32\GIDBIN3.DLL 2011-03-22 05:47 . 2010-09-20 17:12 204560 ——w- c:\windows\system32\GIDBIN1.DLL 2011-03-22 05:47 . 2011-03-22 05:47 ——– d—–w- c:\programdata\GID 2011-03-22 05:46 . 2011-03-22 05:46 ——– d—–w- c:\program files (x86)\SFT 2011-03-22 05:46 . 2011-03-22 05:54 ——– d—–w- c:\program files (x86)\ID Vault 2011-03-22 05:46 . 2011-03-22 05:54 ——– d—–w- c:\windows\ID Vault 2011-03-22 05:46 . 2011-03-22 05:46 ——– d—–w- c:\programdata\White Sky, Inc 2011-03-22 05:22 . 2011-03-22 05:23 ——– d—–w- c:\programdata\Symantec 2011-03-22 05:22 . 2011-03-22 05:22 ——– d—–w- c:\program files\Common Files\Symantec Shared 2011-03-22 05:22 . 2011-03-22 05:22 ——– d—–w- c:\program files (x86)\Symantec 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–r- c:\program files (x86)\Skype 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–w- c:\program files (x86)\Common Files\Skype 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–w- c:\programdata\Skype 2011-03-22 04:50 . 2011-03-22 04:50 0 —-a-w- c:\windows\SysWow64\ConduitEngine.tmp 2011-03-22 04:50 . 2011-04-14 01:33 ——– d—–w- c:\users\AppData 2011-03-22 01:22 . 2011-04-10 03:53 ——– d—–w- c:\programdata\CyberLink 2011-03-22 00:44 . 2011-03-22 00:44 ——– d—–w- c:\users\The 2011-03-22 00:43 . 2011-03-22 05:58 ——– d—–w- c:\program files (x86)\Hotspot_Shield 2011-03-22 00:43 . 2011-03-22 00:43 ——– d—–w- c:\program files (x86)\Conduit 2011-03-22 00:43 . 2011-03-22 00:43 ——– d—–w- C:\Hotspot Shield 2011-03-22 00:43 . 2011-03-22 05:59 ——– d—–w- c:\program files (x86)\Hotspot Shield 2011-03-22 00:30 . 2011-03-22 00:30 ——– d—–w- C:\Recovery . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-22 04:54 . 2010-06-24 11:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-02-18 23:36 . 2011-02-18 23:36 51712 —-a-w- c:\windows\system32\drivers\usbaapl64.sys 2011-02-18 23:36 . 2011-02-18 23:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-02-06 14:22 . 2011-02-06 14:22 2219520 —-a-w- c:\windows\system32\Apblend64.dll 2011-02-06 14:22 . 2011-02-06 14:22 1767936 —-a-w- c:\windows\system32\imagereog.dll 2011-02-06 14:22 . 2011-02-06 14:22 2110816 —-a-w- c:\windows\SysWow64\Apblend.dll 2011-02-06 14:22 . 2011-02-06 14:22 1398112 —-a-w- c:\windows\SysWow64\Imagereog.dll 2011-02-06 14:22 . 2011-02-06 14:22 1171456 —-a-w- c:\windows\SysWow64\PicNotify.dll 2011-02-06 14:22 . 2011-02-06 14:22 11104 —-a-w- c:\windows\SysWow64\biologon.dll 2011-02-06 14:22 . 2011-02-06 14:22 1025376 —-a-w- c:\windows\SysWow64\CamOpEx.dll 2011-02-06 14:22 . 2011-02-06 14:22 778240 —-a-w- c:\windows\system32\EncIcons.dll 2011-02-06 14:22 . 2011-02-06 14:22 622592 —-a-w- c:\windows\system32\SimpleExt.dll 2011-02-06 14:22 . 2011-02-06 14:22 1502720 —-a-w- c:\windows\system32\IcnOvrly.dll 2011-02-06 14:21 . 2011-02-06 14:21 876032 —-a-w- c:\windows\SysWow64\DevIL.dll 2011-02-06 14:21 . 2011-02-06 14:21 77824 —-a-w- c:\windows\SysWow64\ILU.dll 2011-02-06 14:21 . 2011-02-06 14:21 3727720 —-a-w- c:\windows\SysWow64\d3dx9_35.dll 2011-02-06 14:21 . 2011-02-06 14:21 32768 —-a-w- c:\windows\SysWow64\ILUT.dll 2011-02-06 14:21 . 2011-02-06 14:21 1044480 —-a-w- c:\windows\SysWow64\3DImageRenderer.dll 2011-02-06 05:28 . 2011-02-06 05:28 51712 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-02-06 05:28 . 2011-02-06 05:28 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-02-06 05:27 . 2011-02-06 05:27 52224 —-a-w- c:\windows\system32\rtutils.dll 2011-02-06 05:27 . 2011-02-06 05:27 37376 —-a-w- c:\windows\SysWow64\rtutils.dll 2011-02-06 05:27 . 2011-02-06 05:27 82944 —-a-w- c:\windows\SysWow64\iccvid.dll 2011-02-06 05:26 . 2011-02-06 05:26 410504 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2011-02-06 05:26 . 2011-02-06 05:26 27016 —-a-w- c:\windows\system32\drivers\amdxata.sys 2011-02-06 05:26 . 2011-02-06 05:26 2566144 —-a-w- c:\windows\system32\esent.dll 2011-02-06 05:26 . 2011-02-06 05:26 187264 —-a-w- c:\windows\system32\drivers\storport.sys 2011-02-06 05:26 . 2011-02-06 05:26 1686016 —-a-w- c:\windows\SysWow64\esent.dll 2011-02-06 05:26 . 2011-02-06 05:26 166280 —-a-w- c:\windows\system32\drivers\nvstor.sys 2011-02-06 05:26 . 2011-02-06 05:26 1657216 —-a-w- c:\windows\system32\drivers\ntfs.sys 2011-02-06 05:26 . 2011-02-06 05:26 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys 2011-02-06 05:26 . 2011-02-06 05:26 107912 —-a-w- c:\windows\system32\drivers\amdsata.sys 2011-02-06 05:25 . 2011-02-06 05:25 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2011-02-06 05:25 . 2011-02-06 05:25 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2011-02-06 05:25 . 2011-02-06 05:25 153160 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2011-02-06 05:25 . 2011-02-06 05:25 1446912 —-a-w- c:\windows\system32\lsasrv.dll 2011-02-06 05:25 . 2011-02-06 05:25 286720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-02-06 05:25 . 2011-02-06 05:25 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-06 05:25 . 2011-02-06 05:25 125952 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-02-06 05:24 . 2011-02-06 05:24 84992 —-a-w- c:\windows\system32\asycfilt.dll 2011-02-06 05:24 . 2011-02-06 05:24 67584 —-a-w- c:\windows\SysWow64\asycfilt.dll 2011-02-06 05:24 . 2011-02-06 05:24 139264 —-a-w- c:\windows\system32\cabview.dll 2011-02-06 05:24 . 2011-02-06 05:24 132608 —-a-w- c:\windows\SysWow64\cabview.dll 2011-02-06 05:23 . 2011-02-06 05:23 85504 —-a-w- c:\windows\SysWow64\secproc_ssp_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 85504 —-a-w- c:\windows\SysWow64\secproc_ssp.dll 2011-02-06 05:23 . 2011-02-06 05:23 424960 —-a-w- c:\windows\system32\secproc.dll 2011-02-06 05:23 . 2011-02-06 05:23 422912 —-a-w- c:\windows\system32\secproc_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 369152 —-a-w- c:\windows\SysWow64\secproc.dll 2011-02-06 05:23 . 2011-02-06 05:23 365568 —-a-w- c:\windows\SysWow64\secproc_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 357888 —-a-w- c:\windows\system32\RMActivate_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 356352 —-a-w- c:\windows\system32\RMActivate.exe 2011-02-06 05:23 . 2011-02-06 05:23 324608 —-a-w- c:\windows\SysWow64\RMActivate_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 320512 —-a-w- c:\windows\SysWow64\RMActivate.exe 2011-02-06 05:23 . 2011-02-06 05:23 306688 —-a-w- c:\windows\system32\RMActivate_ssp.exe 2011-02-06 05:23 . 2011-02-06 05:23 305152 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 280064 —-a-w- c:\windows\SysWow64\RMActivate_ssp.exe 2011-02-06 05:23 . 2011-02-06 05:23 277504 —-a-w- c:\windows\SysWow64\RMActivate_ssp_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 121856 —-a-w- c:\windows\system32\secproc_ssp_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 121856 —-a-w- c:\windows\system32\secproc_ssp.dll 2011-02-06 05:23 . 2011-02-06 05:23 1896832 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-02-06 05:23 . 2011-02-06 05:23 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2011-02-06 05:23 . 2011-02-06 05:23 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2011-02-06 05:23 . 2011-02-06 05:23 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-02-06 05:23 . 2011-02-06 05:23 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2011-02-06 05:23 . 2011-02-06 05:23 243200 —-a-w- c:\windows\system32\wow64.dll 2011-02-06 05:23 . 2011-02-06 05:23 2048 —-a-w- c:\windows\SysWow64\user.exe 2011-02-06 05:23 . 2011-02-06 05:23 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2011-02-06 05:23 . 2011-02-06 05:23 220672 —-a-w- c:\windows\system32\wintrust.dll 2011-02-06 05:23 . 2011-02-06 05:23 172032 —-a-w- c:\windows\SysWow64\wintrust.dll 2011-02-06 05:22 . 2011-02-06 05:22 613888 —-a-w- c:\windows\system32\psisdecd.dll 2011-02-06 05:22 . 2011-02-06 05:22 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll 2011-02-06 05:22 . 2011-02-06 05:22 389632 —-a-w- c:\windows\system32\winlogon.exe 2011-02-06 05:22 . 2011-02-06 05:22 2870272 —-a-w- c:\windows\explorer.exe 2011-02-06 05:22 . 2011-02-06 05:22 2614272 —-a-w- c:\windows\SysWow64\explorer.exe 2011-02-06 05:22 . 2011-02-06 05:22 14336 —-a-w- c:\windows\system32\drivers\sffp_sd.sys 2011-02-06 05:21 . 2011-02-06 05:21 91648 —-a-w- c:\windows\SysWow64\avifil32.dll 2011-02-06 05:21 . 2011-02-06 05:21 84480 —-a-w- c:\windows\SysWow64\mciavi32.dll 2011-02-06 05:21 . 2011-02-06 05:21 54272 —-a-w- c:\windows\system32\iyuv_32.dll 2011-02-06 05:21 . 2011-02-06 05:21 50176 —-a-w- c:\windows\SysWow64\iyuv_32.dll 2011-02-06 05:21 . 2011-02-06 05:21 38912 —-a-w- c:\windows\system32\msvidc32.dll 2011-02-06 05:21 . 2011-02-06 05:21 31744 —-a-w- c:\windows\SysWow64\msvidc32.dll 2011-02-06 05:21 . 2011-02-06 05:21 25088 —-a-w- c:\windows\system32\msyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 22016 —-a-w- c:\windows\SysWow64\msyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 16384 —-a-w- c:\windows\system32\msrle32.dll 2011-02-06 05:21 . 2011-02-06 05:21 1572352 —-a-w- c:\windows\system32\quartz.dll 2011-02-06 05:21 . 2011-02-06 05:21 14848 —-a-w- c:\windows\system32\tsbyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 13312 —-a-w- c:\windows\SysWow64\msrle32.dll 2011-02-06 05:21 . 2011-02-06 05:21 1328640 —-a-w- c:\windows\SysWow64\quartz.dll 2011-02-06 05:21 . 2011-02-06 05:21 12288 —-a-w- c:\windows\SysWow64\tsbyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 70656 —-a-w- c:\windows\SysWow64\fontsub.dll 2011-02-06 05:21 . 2011-02-06 05:21 100864 —-a-w- c:\windows\system32\fontsub.dll 2011-02-06 05:20 . 2011-02-06 05:20 311808 —-a-w- c:\windows\system32\msv1_0.dll 2011-02-06 05:20 . 2011-02-06 05:20 257024 —-a-w- c:\windows\SysWow64\msv1_0.dll 2011-02-06 05:20 . 2011-02-06 05:20 46592 —-a-w- c:\windows\system32\msasn1.dll 2011-02-06 05:20 . 2011-02-06 05:20 34816 —-a-w- c:\windows\SysWow64\msasn1.dll 2011-02-06 05:19 . 2011-02-06 05:19 1975296 —-a-w- c:\windows\system32\CertEnroll.dll 2011-02-06 05:19 . 2011-02-06 05:19 1320960 —-a-w- c:\windows\SysWow64\CertEnroll.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2011-01-17 14:54 175912 —-a-w- c:\program files (x86)\ConduitEngine\prxConduitEngine.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}] 2011-01-17 14:54 175912 —-a-w- c:\program files (x86)\Hotspot_Shield\prxtbHot0.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "c:\program files (x86)\Hotspot_Shield\prxtbHot0.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-03-23 136176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696] "331BigDog"="c:\program files (x86)\USB Camera\VM331_STI.EXE" [2010-01-15 536576] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-12-03 35184] "VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2011-02-06 3122528] "UCam_Menu"="c:\program files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "YouCam Mirror Tray icon"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2010-03-02 171104] "UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408] "GIDDesktop"="c:\program files (x86)\SFT\GuardedID\gidd.exe" [2010-09-20 391944] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-03-07 421160] . c:\users\The\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 227712] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2009-8-11 1080608] ID Vault.lnk - c:\program files (x86)\ID Vault\IDVault.exe [2010-12-4 2879816] Lenovo Smile Dock.lnk - c:\program files (x86)\DDNi\Lenovo Smile Dock\Delay.exe [2010-6-30 9728] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer5"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [x] R3 IGRS;IGRS;c:\program files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152] R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192] R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [x] S1 GIDv2;GIDv2; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2010-10-15 326704] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336] S2 IDVaultSvc;IDVault Service;c:\program files (x86)\ID Vault\IDVaultSvc.exe [2010-12-04 42312] S2 Oasis2Service;Oasis2Service;c:\program files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe [2010-06-23 46080] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-12-09 2320920] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [x] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-06-17 132656] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys [x] S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg] 2010-09-20 17:15 432904 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe . Contents of the 'Scheduled Tasks' folder . 2011-04-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3339888093-537584527-826026314-1000Core.job - c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-23 02:03] . 2011-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3339888093-537584527-826026314-1000UA.job - c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-23 02:03] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}] 2010-09-22 19:19 284208 —-a-w- c:\program files (x86)\Hotspot Shield\hssie\HssIE_64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc] @="{771C7324-DA80-49D3-8017-753B0AF60951}" [HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}] 2011-02-06 14:22 1502720 —-a-w- c:\windows\System32\IcnOvrly.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-05-07 16416360] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272] "OnekeyStudio"="c:\program files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe" [2009-12-19 776608] "EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\utility.exe" [2010-04-12 4462496] "Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2010-03-18 7056800] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uStart Page = hxxp://lenovo.msn.com uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://lenovo.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Send image to &Bluetooth Device… - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm TCP: {007C9D54-1894-4DC7-8D9F-C4D8201BF272} = 10.1.24.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL FF - ProfilePath - c:\users\The\AppData\Roaming\Mozilla\Firefox\Profiles\atuefuve.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Hotspot Shield Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1561552&SearchSource=13 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF - Ext: afurladvisor: [removed] - c:\program files (x86)\Mozilla Firefox\extensions\[removed] FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Hotspot Shield Community Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - %profile%\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d} FF - Ext: springshine: [removed] - %profile%\extensions\[removed] FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed] FF - user.js: general.useragent.extra.brc - . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-RegWork - c:\program files (x86)\RegWork\RegWork.exe SafeBoot-Symantec Antvirus Toolbar-Locked - (no file) WebBrowser-{C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - (no file) HKLM-Run-ETDWare - %ProgramFiles%\Elantech\ETDCtrl.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-04-13 18:39:01 ComboFix-quarantined-files.txt 2011-04-14 01:39 . Pre-Run: 412,777,009,152 bytes free Post-Run: 412,699,385,856 bytes free . - - End Of File - - 6DE2C94C648A43A579100CC2EBBF2184
ComboFix 11-04-13.02 - The 04/13/2011 18:34:15.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3959.2712 [GMT -7:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\8a20288c-45f6-4e38-9aba-510671b53074.dat c:\programdata\FullRemove.exe c:\windows\s.bat . . ((((((((((((((((((((((((( Files Created from 2011-03-14 to 2011-04-14 ))))))))))))))))))))))))))))))) . . 2011-04-14 01:37 . 2011-04-14 01:37 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-04-12 08:31 . 2011-04-12 08:31 ——– d—–w- c:\program files (x86)\Trend Micro 2011-04-10 04:28 . 2010-12-21 01:09 38224 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-04-10 04:28 . 2011-04-10 04:28 ——– d—–w- c:\programdata\Malwarebytes 2011-04-10 04:28 . 2011-04-13 02:35 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-04-10 04:28 . 2010-12-21 01:08 24152 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-04-10 04:11 . 2011-03-23 17:11 8424784 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{691DA5B2-4B83-42DA-BACD-377205D3A74E}\mpengine.dll 2011-03-25 19:33 . 2011-03-25 19:33 ——– dc—-w- c:\windows\system32\DRVSTORE 2011-03-25 19:33 . 2009-05-18 20:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-03-25 19:33 . 2008-04-17 19:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-03-25 19:33 . 2008-04-17 19:12 107368 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-03-25 19:33 . 2011-03-25 19:33 ——– d—–w- c:\program files\iPod 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001} 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\program files\iTunes 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\program files (x86)\iTunes 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-03-25 19:30 . 2011-03-25 19:31 ——– d—–w- c:\program files (x86)\QuickTime 2011-03-25 19:30 . 2011-03-25 19:32 ——– d—–w- c:\programdata\Apple Computer 2011-03-25 19:29 . 2011-03-25 19:29 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-03-25 19:29 . 2011-03-25 19:29 ——– d—–w- c:\program files\Common Files\Apple 2011-03-25 19:28 . 2011-03-25 19:29 ——– d—–w- c:\program files\Bonjour 2011-03-25 19:28 . 2011-03-25 19:29 ——– d—–w- c:\program files (x86)\Bonjour 2011-03-25 19:28 . 2011-03-25 21:02 ——– d—–w- c:\programdata\Apple 2011-03-25 19:28 . 2011-03-25 19:33 ——– d—–w- c:\program files (x86)\Common Files\Apple 2011-03-25 02:35 . 2011-03-25 02:35 ——– d—–w- c:\programdata\RegWork 2011-03-25 02:31 . 2011-03-25 02:31 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-03-25 02:29 . 2011-03-25 02:29 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-03-25 02:29 . 2011-03-25 02:29 ——– d—–w- c:\program files (x86)\Java 2011-03-24 21:02 . 2011-03-24 21:02 ——– d—–w- c:\windows\SysWow64\Wat 2011-03-24 21:02 . 2011-03-24 21:02 ——– d—–w- c:\windows\system32\Wat 2011-03-24 18:53 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll 2011-03-24 18:53 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll 2011-03-24 18:48 . 2009-11-25 19:47 99176 —-a-w- c:\windows\SysWow64\PresentationHostProxy.dll 2011-03-24 18:48 . 2009-11-25 19:47 49472 —-a-w- c:\windows\SysWow64\netfxperf.dll 2011-03-24 18:48 . 2009-11-25 19:47 297808 —-a-w- c:\windows\SysWow64\mscoree.dll 2011-03-24 18:48 . 2009-11-25 19:47 295264 —-a-w- c:\windows\SysWow64\PresentationHost.exe 2011-03-24 18:48 . 2009-11-25 19:47 1130824 —-a-w- c:\windows\SysWow64\dfshim.dll 2011-03-24 18:48 . 2009-11-25 19:47 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll 2011-03-24 18:48 . 2009-11-25 19:47 444752 —-a-w- c:\windows\system32\mscoree.dll 2011-03-24 18:48 . 2009-11-25 19:47 320352 —-a-w- c:\windows\system32\PresentationHost.exe 2011-03-24 18:48 . 2009-11-25 19:47 48960 —-a-w- c:\windows\system32\netfxperf.dll 2011-03-24 18:48 . 2009-11-25 19:47 1942856 —-a-w- c:\windows\system32\dfshim.dll 2011-03-24 18:42 . 2010-03-04 04:40 184832 —-a-w- c:\windows\system32\drivers\usbvideo.sys 2011-03-24 18:42 . 2010-03-04 04:32 243712 —-a-w- c:\windows\system32\drivers\ks.sys 2011-03-23 02:14 . 2011-04-01 23:07 ——– d—–w- c:\program files (x86)\VitalSource Bookshelf 2011-03-23 00:25 . 2011-01-07 08:07 662528 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-23 00:25 . 2011-01-07 07:31 442880 —-a-w- c:\windows\SysWow64\XpsPrint.dll 2011-03-23 00:25 . 2011-01-07 08:07 475648 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-03-23 00:25 . 2011-01-07 07:31 288256 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2011-03-23 00:25 . 2010-08-21 06:29 558592 —-a-w- c:\windows\system32\spoolsv.exe 2011-03-23 00:23 . 2010-12-23 06:07 723968 —-a-w- c:\windows\system32\EncDec.dll 2011-03-23 00:22 . 2011-01-05 04:00 3127808 —-a-w- c:\windows\system32\win32k.sys 2011-03-23 00:22 . 2010-03-04 07:57 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-23 00:22 . 2010-03-04 07:57 2080256 —-a-w- c:\program files\Windows Mail\msoe.dll 2011-03-23 00:22 . 2010-03-04 07:33 1619968 —-a-w- c:\program files (x86)\Windows Mail\msoe.dll 2011-03-23 00:22 . 2010-03-04 07:33 740864 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-03-23 00:22 . 2010-08-04 07:07 552960 —-a-w- c:\windows\system32\msdri.dll 2011-03-23 00:22 . 2010-08-04 07:05 288256 —-a-w- c:\windows\system32\MSNP.ax 2011-03-23 00:22 . 2010-08-04 06:15 204288 —-a-w- c:\windows\SysWow64\MSNP.ax 2011-03-23 00:22 . 2010-08-21 06:36 340992 —-a-w- c:\windows\system32\schannel.dll 2011-03-23 00:22 . 2010-08-21 05:36 224256 —-a-w- c:\windows\SysWow64\schannel.dll 2011-03-23 00:22 . 2010-08-21 06:31 633856 —-a-w- c:\windows\system32\comctl32.dll 2011-03-23 00:22 . 2010-08-21 05:33 530432 —-a-w- c:\windows\SysWow64\comctl32.dll 2011-03-23 00:20 . 2010-11-02 05:12 1837568 —-a-w- c:\windows\system32\d3d10warp.dll 2011-03-23 00:19 . 2010-10-27 05:18 5510528 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-03-23 00:18 . 2010-10-16 04:33 987136 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll 2011-03-23 00:18 . 2010-10-16 04:33 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll 2011-03-23 00:18 . 2010-10-16 04:33 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll 2011-03-23 00:18 . 2010-10-16 04:33 208896 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll 2011-03-23 00:18 . 2010-08-27 03:38 463360 —-a-w- c:\windows\system32\drivers\srv.sys 2011-03-23 00:18 . 2010-08-27 03:37 402944 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-03-23 00:18 . 2010-08-27 06:14 236032 —-a-w- c:\windows\system32\srvsvc.dll 2011-03-23 00:18 . 2010-08-27 05:46 9728 —-a-w- c:\windows\SysWow64\sscore.dll 2011-03-23 00:18 . 2010-08-27 03:37 161792 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-03-23 00:11 . 2011-03-23 00:12 ——– dc-h–w- c:\programdata\{DC88B4E9-0A30-46AE-A4D5-38E7C0D304E4} 2011-03-22 06:46 . 2011-03-22 06:46 ——– d—–w- c:\programdata\Oberon Media 2011-03-22 06:06 . 2011-03-22 06:06 ——– d—–w- c:\program files (x86)\Common Files\Oberon Media 2011-03-22 06:06 . 2011-03-22 06:44 ——– d—–w- c:\program files (x86)\Oberon Media 2011-03-22 06:06 . 2011-04-10 03:42 ——– d—–w- c:\program files (x86)\Lenovo Games 2011-03-22 05:59 . 2011-03-22 05:59 ——– d—–w- c:\programdata\hssff 2011-03-22 05:55 . 2010-09-20 17:14 65816 ——w- c:\windows\system32\GIDLogonCP64.dll 2011-03-22 05:55 . 2010-09-20 17:13 442656 ——w- c:\windows\system32\GIDHookLogon64.dll 2011-03-22 05:48 . 2011-03-22 05:48 ——– d—–w- c:\programdata\IsolatedStorage 2011-03-22 05:47 . 2010-09-20 17:09 29288 ——w- c:\windows\system32\drivers\gidv2.sys 2011-03-22 05:47 . 2009-06-12 23:32 109064 ——w- c:\windows\system32\EasyHook64.dll 2011-03-22 05:47 . 2010-09-20 17:13 458520 ——w- c:\windows\system32\GIDHOOK64.DLL 2011-03-22 05:47 . 2010-09-20 17:12 100624 ——w- c:\windows\system32\GIDBIN3.DLL 2011-03-22 05:47 . 2010-09-20 17:12 204560 ——w- c:\windows\system32\GIDBIN1.DLL 2011-03-22 05:47 . 2011-03-22 05:47 ——– d—–w- c:\programdata\GID 2011-03-22 05:46 . 2011-03-22 05:46 ——– d—–w- c:\program files (x86)\SFT 2011-03-22 05:46 . 2011-03-22 05:54 ——– d—–w- c:\program files (x86)\ID Vault 2011-03-22 05:46 . 2011-03-22 05:54 ——– d—–w- c:\windows\ID Vault 2011-03-22 05:46 . 2011-03-22 05:46 ——– d—–w- c:\programdata\White Sky, Inc 2011-03-22 05:22 . 2011-03-22 05:23 ——– d—–w- c:\programdata\Symantec 2011-03-22 05:22 . 2011-03-22 05:22 ——– d—–w- c:\program files\Common Files\Symantec Shared 2011-03-22 05:22 . 2011-03-22 05:22 ——– d—–w- c:\program files (x86)\Symantec 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–r- c:\program files (x86)\Skype 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–w- c:\program files (x86)\Common Files\Skype 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–w- c:\programdata\Skype 2011-03-22 04:50 . 2011-03-22 04:50 0 —-a-w- c:\windows\SysWow64\ConduitEngine.tmp 2011-03-22 04:50 . 2011-04-14 01:33 ——– d—–w- c:\users\AppData 2011-03-22 01:22 . 2011-04-10 03:53 ——– d—–w- c:\programdata\CyberLink 2011-03-22 00:44 . 2011-03-22 00:44 ——– d—–w- c:\users\The 2011-03-22 00:43 . 2011-03-22 05:58 ——– d—–w- c:\program files (x86)\Hotspot_Shield 2011-03-22 00:43 . 2011-03-22 00:43 ——– d—–w- c:\program files (x86)\Conduit 2011-03-22 00:43 . 2011-03-22 00:43 ——– d—–w- C:\Hotspot Shield 2011-03-22 00:43 . 2011-03-22 05:59 ——– d—–w- c:\program files (x86)\Hotspot Shield 2011-03-22 00:30 . 2011-03-22 00:30 ——– d—–w- C:\Recovery . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-22 04:54 . 2010-06-24 11:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-02-18 23:36 . 2011-02-18 23:36 51712 —-a-w- c:\windows\system32\drivers\usbaapl64.sys 2011-02-18 23:36 . 2011-02-18 23:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-02-06 14:22 . 2011-02-06 14:22 2219520 —-a-w- c:\windows\system32\Apblend64.dll 2011-02-06 14:22 . 2011-02-06 14:22 1767936 —-a-w- c:\windows\system32\imagereog.dll 2011-02-06 14:22 . 2011-02-06 14:22 2110816 —-a-w- c:\windows\SysWow64\Apblend.dll 2011-02-06 14:22 . 2011-02-06 14:22 1398112 —-a-w- c:\windows\SysWow64\Imagereog.dll 2011-02-06 14:22 . 2011-02-06 14:22 1171456 —-a-w- c:\windows\SysWow64\PicNotify.dll 2011-02-06 14:22 . 2011-02-06 14:22 11104 —-a-w- c:\windows\SysWow64\biologon.dll 2011-02-06 14:22 . 2011-02-06 14:22 1025376 —-a-w- c:\windows\SysWow64\CamOpEx.dll 2011-02-06 14:22 . 2011-02-06 14:22 778240 —-a-w- c:\windows\system32\EncIcons.dll 2011-02-06 14:22 . 2011-02-06 14:22 622592 —-a-w- c:\windows\system32\SimpleExt.dll 2011-02-06 14:22 . 2011-02-06 14:22 1502720 —-a-w- c:\windows\system32\IcnOvrly.dll 2011-02-06 14:21 . 2011-02-06 14:21 876032 —-a-w- c:\windows\SysWow64\DevIL.dll 2011-02-06 14:21 . 2011-02-06 14:21 77824 —-a-w- c:\windows\SysWow64\ILU.dll 2011-02-06 14:21 . 2011-02-06 14:21 3727720 —-a-w- c:\windows\SysWow64\d3dx9_35.dll 2011-02-06 14:21 . 2011-02-06 14:21 32768 —-a-w- c:\windows\SysWow64\ILUT.dll 2011-02-06 14:21 . 2011-02-06 14:21 1044480 —-a-w- c:\windows\SysWow64\3DImageRenderer.dll 2011-02-06 05:28 . 2011-02-06 05:28 51712 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-02-06 05:28 . 2011-02-06 05:28 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-02-06 05:27 . 2011-02-06 05:27 52224 —-a-w- c:\windows\system32\rtutils.dll 2011-02-06 05:27 . 2011-02-06 05:27 37376 —-a-w- c:\windows\SysWow64\rtutils.dll 2011-02-06 05:27 . 2011-02-06 05:27 82944 —-a-w- c:\windows\SysWow64\iccvid.dll 2011-02-06 05:26 . 2011-02-06 05:26 410504 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2011-02-06 05:26 . 2011-02-06 05:26 27016 —-a-w- c:\windows\system32\drivers\amdxata.sys 2011-02-06 05:26 . 2011-02-06 05:26 2566144 —-a-w- c:\windows\system32\esent.dll 2011-02-06 05:26 . 2011-02-06 05:26 187264 —-a-w- c:\windows\system32\drivers\storport.sys 2011-02-06 05:26 . 2011-02-06 05:26 1686016 —-a-w- c:\windows\SysWow64\esent.dll 2011-02-06 05:26 . 2011-02-06 05:26 166280 —-a-w- c:\windows\system32\drivers\nvstor.sys 2011-02-06 05:26 . 2011-02-06 05:26 1657216 —-a-w- c:\windows\system32\drivers\ntfs.sys 2011-02-06 05:26 . 2011-02-06 05:26 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys 2011-02-06 05:26 . 2011-02-06 05:26 107912 —-a-w- c:\windows\system32\drivers\amdsata.sys 2011-02-06 05:25 . 2011-02-06 05:25 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2011-02-06 05:25 . 2011-02-06 05:25 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2011-02-06 05:25 . 2011-02-06 05:25 153160 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2011-02-06 05:25 . 2011-02-06 05:25 1446912 —-a-w- c:\windows\system32\lsasrv.dll 2011-02-06 05:25 . 2011-02-06 05:25 286720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-02-06 05:25 . 2011-02-06 05:25 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-06 05:25 . 2011-02-06 05:25 125952 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-02-06 05:24 . 2011-02-06 05:24 84992 —-a-w- c:\windows\system32\asycfilt.dll 2011-02-06 05:24 . 2011-02-06 05:24 67584 —-a-w- c:\windows\SysWow64\asycfilt.dll 2011-02-06 05:24 . 2011-02-06 05:24 139264 —-a-w- c:\windows\system32\cabview.dll 2011-02-06 05:24 . 2011-02-06 05:24 132608 —-a-w- c:\windows\SysWow64\cabview.dll 2011-02-06 05:23 . 2011-02-06 05:23 85504 —-a-w- c:\windows\SysWow64\secproc_ssp_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 85504 —-a-w- c:\windows\SysWow64\secproc_ssp.dll 2011-02-06 05:23 . 2011-02-06 05:23 424960 —-a-w- c:\windows\system32\secproc.dll 2011-02-06 05:23 . 2011-02-06 05:23 422912 —-a-w- c:\windows\system32\secproc_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 369152 —-a-w- c:\windows\SysWow64\secproc.dll 2011-02-06 05:23 . 2011-02-06 05:23 365568 —-a-w- c:\windows\SysWow64\secproc_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 357888 —-a-w- c:\windows\system32\RMActivate_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 356352 —-a-w- c:\windows\system32\RMActivate.exe 2011-02-06 05:23 . 2011-02-06 05:23 324608 —-a-w- c:\windows\SysWow64\RMActivate_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 320512 —-a-w- c:\windows\SysWow64\RMActivate.exe 2011-02-06 05:23 . 2011-02-06 05:23 306688 —-a-w- c:\windows\system32\RMActivate_ssp.exe 2011-02-06 05:23 . 2011-02-06 05:23 305152 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 280064 —-a-w- c:\windows\SysWow64\RMActivate_ssp.exe 2011-02-06 05:23 . 2011-02-06 05:23 277504 —-a-w- c:\windows\SysWow64\RMActivate_ssp_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 121856 —-a-w- c:\windows\system32\secproc_ssp_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 121856 —-a-w- c:\windows\system32\secproc_ssp.dll 2011-02-06 05:23 . 2011-02-06 05:23 1896832 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-02-06 05:23 . 2011-02-06 05:23 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2011-02-06 05:23 . 2011-02-06 05:23 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2011-02-06 05:23 . 2011-02-06 05:23 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-02-06 05:23 . 2011-02-06 05:23 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2011-02-06 05:23 . 2011-02-06 05:23 243200 —-a-w- c:\windows\system32\wow64.dll 2011-02-06 05:23 . 2011-02-06 05:23 2048 —-a-w- c:\windows\SysWow64\user.exe 2011-02-06 05:23 . 2011-02-06 05:23 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2011-02-06 05:23 . 2011-02-06 05:23 220672 —-a-w- c:\windows\system32\wintrust.dll 2011-02-06 05:23 . 2011-02-06 05:23 172032 —-a-w- c:\windows\SysWow64\wintrust.dll 2011-02-06 05:22 . 2011-02-06 05:22 613888 —-a-w- c:\windows\system32\psisdecd.dll 2011-02-06 05:22 . 2011-02-06 05:22 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll 2011-02-06 05:22 . 2011-02-06 05:22 389632 —-a-w- c:\windows\system32\winlogon.exe 2011-02-06 05:22 . 2011-02-06 05:22 2870272 —-a-w- c:\windows\explorer.exe 2011-02-06 05:22 . 2011-02-06 05:22 2614272 —-a-w- c:\windows\SysWow64\explorer.exe 2011-02-06 05:22 . 2011-02-06 05:22 14336 —-a-w- c:\windows\system32\drivers\sffp_sd.sys 2011-02-06 05:21 . 2011-02-06 05:21 91648 —-a-w- c:\windows\SysWow64\avifil32.dll 2011-02-06 05:21 . 2011-02-06 05:21 84480 —-a-w- c:\windows\SysWow64\mciavi32.dll 2011-02-06 05:21 . 2011-02-06 05:21 54272 —-a-w- c:\windows\system32\iyuv_32.dll 2011-02-06 05:21 . 2011-02-06 05:21 50176 —-a-w- c:\windows\SysWow64\iyuv_32.dll 2011-02-06 05:21 . 2011-02-06 05:21 38912 —-a-w- c:\windows\system32\msvidc32.dll 2011-02-06 05:21 . 2011-02-06 05:21 31744 —-a-w- c:\windows\SysWow64\msvidc32.dll 2011-02-06 05:21 . 2011-02-06 05:21 25088 —-a-w- c:\windows\system32\msyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 22016 —-a-w- c:\windows\SysWow64\msyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 16384 —-a-w- c:\windows\system32\msrle32.dll 2011-02-06 05:21 . 2011-02-06 05:21 1572352 —-a-w- c:\windows\system32\quartz.dll 2011-02-06 05:21 . 2011-02-06 05:21 14848 —-a-w- c:\windows\system32\tsbyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 13312 —-a-w- c:\windows\SysWow64\msrle32.dll 2011-02-06 05:21 . 2011-02-06 05:21 1328640 —-a-w- c:\windows\SysWow64\quartz.dll 2011-02-06 05:21 . 2011-02-06 05:21 12288 —-a-w- c:\windows\SysWow64\tsbyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 70656 —-a-w- c:\windows\SysWow64\fontsub.dll 2011-02-06 05:21 . 2011-02-06 05:21 100864 —-a-w- c:\windows\system32\fontsub.dll 2011-02-06 05:20 . 2011-02-06 05:20 311808 —-a-w- c:\windows\system32\msv1_0.dll 2011-02-06 05:20 . 2011-02-06 05:20 257024 —-a-w- c:\windows\SysWow64\msv1_0.dll 2011-02-06 05:20 . 2011-02-06 05:20 46592 —-a-w- c:\windows\system32\msasn1.dll 2011-02-06 05:20 . 2011-02-06 05:20 34816 —-a-w- c:\windows\SysWow64\msasn1.dll 2011-02-06 05:19 . 2011-02-06 05:19 1975296 —-a-w- c:\windows\system32\CertEnroll.dll 2011-02-06 05:19 . 2011-02-06 05:19 1320960 —-a-w- c:\windows\SysWow64\CertEnroll.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2011-01-17 14:54 175912 —-a-w- c:\program files (x86)\ConduitEngine\prxConduitEngine.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}] 2011-01-17 14:54 175912 —-a-w- c:\program files (x86)\Hotspot_Shield\prxtbHot0.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "c:\program files (x86)\Hotspot_Shield\prxtbHot0.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-03-23 136176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696] "331BigDog"="c:\program files (x86)\USB Camera\VM331_STI.EXE" [2010-01-15 536576] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-12-03 35184] "VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2011-02-06 3122528] "UCam_Menu"="c:\program files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "YouCam Mirror Tray icon"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2010-03-02 171104] "UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408] "GIDDesktop"="c:\program files (x86)\SFT\GuardedID\gidd.exe" [2010-09-20 391944] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-03-07 421160] . c:\users\The\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 227712] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2009-8-11 1080608] ID Vault.lnk - c:\program files (x86)\ID Vault\IDVault.exe [2010-12-4 2879816] Lenovo Smile Dock.lnk - c:\program files (x86)\DDNi\Lenovo Smile Dock\Delay.exe [2010-6-30 9728] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer5"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [x] R3 IGRS;IGRS;c:\program files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152] R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192] R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [x] S1 GIDv2;GIDv2; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2010-10-15 326704] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336] S2 IDVaultSvc;IDVault Service;c:\program files (x86)\ID Vault\IDVaultSvc.exe [2010-12-04 42312] S2 Oasis2Service;Oasis2Service;c:\program files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe [2010-06-23 46080] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-12-09 2320920] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [x] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-06-17 132656] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys [x] S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg] 2010-09-20 17:15 432904 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe . Contents of the 'Scheduled Tasks' folder . 2011-04-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3339888093-537584527-826026314-1000Core.job - c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-23 02:03] . 2011-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3339888093-537584527-826026314-1000UA.job - c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-23 02:03] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}] 2010-09-22 19:19 284208 —-a-w- c:\program files (x86)\Hotspot Shield\hssie\HssIE_64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc] @="{771C7324-DA80-49D3-8017-753B0AF60951}" [HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}] 2011-02-06 14:22 1502720 —-a-w- c:\windows\System32\IcnOvrly.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-05-07 16416360] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272] "OnekeyStudio"="c:\program files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe" [2009-12-19 776608] "EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\utility.exe" [2010-04-12 4462496] "Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2010-03-18 7056800] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uStart Page = hxxp://lenovo.msn.com uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://lenovo.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Send image to &Bluetooth Device… - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm TCP: {007C9D54-1894-4DC7-8D9F-C4D8201BF272} = 10.1.24.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL FF - ProfilePath - c:\users\The\AppData\Roaming\Mozilla\Firefox\Profiles\atuefuve.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Hotspot Shield Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1561552&SearchSource=13 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF - Ext: afurladvisor: [removed] - c:\program files (x86)\Mozilla Firefox\extensions\[removed] FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Hotspot Shield Community Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - %profile%\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d} FF - Ext: springshine: [removed] - %profile%\extensions\[removed] FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed] FF - user.js: general.useragent.extra.brc - . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-RegWork - c:\program files (x86)\RegWork\RegWork.exe SafeBoot-Symantec Antvirus Toolbar-Locked - (no file) WebBrowser-{C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - (no file) HKLM-Run-ETDWare - %ProgramFiles%\Elantech\ETDCtrl.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-04-13 18:39:01 ComboFix-quarantined-files.txt 2011-04-14 01:39 . Pre-Run: 412,777,009,152 bytes free Post-Run: 412,699,385,856 bytes free . - - End Of File - - 6DE2C94C648A43A579100CC2EBBF2184
Do you use Hotspot Shield? It can be considered foistware, as it bundles a toolbar and the Conduit engine - but if you have an active need for it we won't remove it. Let me know if you want to keep it or remove it, and we'll proceed.
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

SecCenter::
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

Folder::
c:\program files (x86)\Hotspot_Shield
c:\program files (x86)\Conduit

Registry::
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"=-
[-HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]

Driver::
HssWd

DDS::
FF - ProfilePath - c:\users\The\AppData\Roaming\Mozilla\Firefox\Profiles\atuefuve.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Hotspot Shield Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1561552&SearchSource=13
FF - Ext: Hotspot Shield Community Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - %profile%\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed]


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
ComboFix 11-04-13.02 - The 04/14/2011 18:27:54.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3959.2156 [GMT -7:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe Command switches used :: c:\users\The\Downloads\CFscript.txt AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: Symantec Endpoint Protection *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: Symantec Endpoint Protection *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Conduit c:\program files (x86)\Conduit\Community Alerts\Alert.dll c:\program files (x86)\Conduit\Community Alerts\Alert0.dll c:\program files (x86)\Hotspot_Shield c:\program files (x86)\Hotspot_Shield\Hotspot_ShieldToolbarHelper.exe c:\program files (x86)\Hotspot_Shield\Hotspot_ShieldToolbarHelper1.exe c:\program files (x86)\Hotspot_Shield\INSTALL.LOG c:\program files (x86)\Hotspot_Shield\prxtbHot0.dll c:\program files (x86)\Hotspot_Shield\tbHot0.dll c:\program files (x86)\Hotspot_Shield\tbHot1.dll c:\program files (x86)\Hotspot_Shield\toolbar.cfg c:\program files (x86)\Hotspot_Shield\uninstall.exe c:\program files (x86)\Hotspot_Shield\UNWISE.EXE . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_HssWd . . ((((((((((((((((((((((((( Files Created from 2011-03-15 to 2011-04-15 ))))))))))))))))))))))))))))))) . . 2011-04-12 08:31 . 2011-04-12 08:31 ——– d—–w- c:\program files (x86)\Trend Micro 2011-04-10 04:28 . 2010-12-21 01:09 38224 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-04-10 04:28 . 2011-04-10 04:28 ——– d—–w- c:\programdata\Malwarebytes 2011-04-10 04:28 . 2011-04-13 02:35 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-04-10 04:28 . 2010-12-21 01:08 24152 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-04-10 04:11 . 2011-03-23 17:11 8424784 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{691DA5B2-4B83-42DA-BACD-377205D3A74E}\mpengine.dll 2011-03-25 19:33 . 2011-03-25 19:33 ——– dc—-w- c:\windows\system32\DRVSTORE 2011-03-25 19:33 . 2009-05-18 20:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-03-25 19:33 . 2008-04-17 19:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-03-25 19:33 . 2008-04-17 19:12 107368 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-03-25 19:33 . 2011-03-25 19:33 ——– d—–w- c:\program files\iPod 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001} 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\program files\iTunes 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\program files (x86)\iTunes 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-03-25 19:30 . 2011-03-25 19:31 ——– d—–w- c:\program files (x86)\QuickTime 2011-03-25 19:30 . 2011-03-25 19:32 ——– d—–w- c:\programdata\Apple Computer 2011-03-25 19:29 . 2011-03-25 19:29 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-03-25 19:29 . 2011-03-25 19:29 ——– d—–w- c:\program files\Common Files\Apple 2011-03-25 19:28 . 2011-03-25 19:29 ——– d—–w- c:\program files\Bonjour 2011-03-25 19:28 . 2011-03-25 19:29 ——– d—–w- c:\program files (x86)\Bonjour 2011-03-25 19:28 . 2011-03-25 21:02 ——– d—–w- c:\programdata\Apple 2011-03-25 19:28 . 2011-03-25 19:33 ——– d—–w- c:\program files (x86)\Common Files\Apple 2011-03-25 02:35 . 2011-03-25 02:35 ——– d—–w- c:\programdata\RegWork 2011-03-25 02:31 . 2011-03-25 02:31 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-03-25 02:29 . 2011-03-25 02:29 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-03-25 02:29 . 2011-03-25 02:29 ——– d—–w- c:\program files (x86)\Java 2011-03-24 21:02 . 2011-03-24 21:02 ——– d—–w- c:\windows\SysWow64\Wat 2011-03-24 21:02 . 2011-03-24 21:02 ——– d—–w- c:\windows\system32\Wat 2011-03-24 18:53 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll 2011-03-24 18:53 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll 2011-03-24 18:48 . 2009-11-25 19:47 99176 —-a-w- c:\windows\SysWow64\PresentationHostProxy.dll 2011-03-24 18:48 . 2009-11-25 19:47 49472 —-a-w- c:\windows\SysWow64\netfxperf.dll 2011-03-24 18:48 . 2009-11-25 19:47 297808 —-a-w- c:\windows\SysWow64\mscoree.dll 2011-03-24 18:48 . 2009-11-25 19:47 295264 —-a-w- c:\windows\SysWow64\PresentationHost.exe 2011-03-24 18:48 . 2009-11-25 19:47 1130824 —-a-w- c:\windows\SysWow64\dfshim.dll 2011-03-24 18:48 . 2009-11-25 19:47 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll 2011-03-24 18:48 . 2009-11-25 19:47 444752 —-a-w- c:\windows\system32\mscoree.dll 2011-03-24 18:48 . 2009-11-25 19:47 320352 —-a-w- c:\windows\system32\PresentationHost.exe 2011-03-24 18:48 . 2009-11-25 19:47 48960 —-a-w- c:\windows\system32\netfxperf.dll 2011-03-24 18:48 . 2009-11-25 19:47 1942856 —-a-w- c:\windows\system32\dfshim.dll 2011-03-24 18:42 . 2010-03-04 04:40 184832 —-a-w- c:\windows\system32\drivers\usbvideo.sys 2011-03-24 18:42 . 2010-03-04 04:32 243712 —-a-w- c:\windows\system32\drivers\ks.sys 2011-03-23 02:14 . 2011-04-01 23:07 ——– d—–w- c:\program files (x86)\VitalSource Bookshelf 2011-03-23 00:25 . 2011-01-07 08:07 662528 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-23 00:25 . 2011-01-07 07:31 442880 —-a-w- c:\windows\SysWow64\XpsPrint.dll 2011-03-23 00:25 . 2011-01-07 08:07 475648 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-03-23 00:25 . 2011-01-07 07:31 288256 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2011-03-23 00:25 . 2010-08-21 06:29 558592 —-a-w- c:\windows\system32\spoolsv.exe 2011-03-23 00:23 . 2010-12-23 06:07 723968 —-a-w- c:\windows\system32\EncDec.dll 2011-03-23 00:22 . 2011-01-05 04:00 3127808 —-a-w- c:\windows\system32\win32k.sys 2011-03-23 00:22 . 2010-03-04 07:57 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-23 00:22 . 2010-03-04 07:57 2080256 —-a-w- c:\program files\Windows Mail\msoe.dll 2011-03-23 00:22 . 2010-03-04 07:33 1619968 —-a-w- c:\program files (x86)\Windows Mail\msoe.dll 2011-03-23 00:22 . 2010-03-04 07:33 740864 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-03-23 00:22 . 2010-08-04 07:07 552960 —-a-w- c:\windows\system32\msdri.dll 2011-03-23 00:22 . 2010-08-04 07:05 288256 —-a-w- c:\windows\system32\MSNP.ax 2011-03-23 00:22 . 2010-08-04 06:15 204288 —-a-w- c:\windows\SysWow64\MSNP.ax 2011-03-23 00:22 . 2010-08-21 06:36 340992 —-a-w- c:\windows\system32\schannel.dll 2011-03-23 00:22 . 2010-08-21 05:36 224256 —-a-w- c:\windows\SysWow64\schannel.dll 2011-03-23 00:22 . 2010-08-21 06:31 633856 —-a-w- c:\windows\system32\comctl32.dll 2011-03-23 00:22 . 2010-08-21 05:33 530432 —-a-w- c:\windows\SysWow64\comctl32.dll 2011-03-23 00:20 . 2010-11-02 05:12 1837568 —-a-w- c:\windows\system32\d3d10warp.dll 2011-03-23 00:19 . 2010-10-27 05:18 5510528 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-03-23 00:18 . 2010-10-16 04:33 987136 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll 2011-03-23 00:18 . 2010-10-16 04:33 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll 2011-03-23 00:18 . 2010-10-16 04:33 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll 2011-03-23 00:18 . 2010-10-16 04:33 208896 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll 2011-03-23 00:18 . 2010-08-27 03:38 463360 —-a-w- c:\windows\system32\drivers\srv.sys 2011-03-23 00:18 . 2010-08-27 03:37 402944 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-03-23 00:18 . 2010-08-27 06:14 236032 —-a-w- c:\windows\system32\srvsvc.dll 2011-03-23 00:18 . 2010-08-27 05:46 9728 —-a-w- c:\windows\SysWow64\sscore.dll 2011-03-23 00:18 . 2010-08-27 03:37 161792 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-03-23 00:11 . 2011-03-23 00:12 ——– dc-h–w- c:\programdata\{DC88B4E9-0A30-46AE-A4D5-38E7C0D304E4} 2011-03-22 06:46 . 2011-03-22 06:46 ——– d—–w- c:\programdata\Oberon Media 2011-03-22 06:06 . 2011-03-22 06:06 ——– d—–w- c:\program files (x86)\Common Files\Oberon Media 2011-03-22 06:06 . 2011-03-22 06:44 ——– d—–w- c:\program files (x86)\Oberon Media 2011-03-22 06:06 . 2011-04-10 03:42 ——– d—–w- c:\program files (x86)\Lenovo Games 2011-03-22 05:59 . 2011-03-22 05:59 ——– d—–w- c:\programdata\hssff 2011-03-22 05:55 . 2010-09-20 17:14 65816 ——w- c:\windows\system32\GIDLogonCP64.dll 2011-03-22 05:55 . 2010-09-20 17:13 442656 ——w- c:\windows\system32\GIDHookLogon64.dll 2011-03-22 05:48 . 2011-03-22 05:48 ——– d—–w- c:\programdata\IsolatedStorage 2011-03-22 05:47 . 2010-09-20 17:09 29288 ——w- c:\windows\system32\drivers\gidv2.sys 2011-03-22 05:47 . 2009-06-12 23:32 109064 ——w- c:\windows\system32\EasyHook64.dll 2011-03-22 05:47 . 2010-09-20 17:13 458520 ——w- c:\windows\system32\GIDHOOK64.DLL 2011-03-22 05:47 . 2010-09-20 17:12 100624 ——w- c:\windows\system32\GIDBIN3.DLL 2011-03-22 05:47 . 2010-09-20 17:12 204560 ——w- c:\windows\system32\GIDBIN1.DLL 2011-03-22 05:47 . 2011-03-22 05:47 ——– d—–w- c:\programdata\GID 2011-03-22 05:46 . 2011-03-22 05:46 ——– d—–w- c:\program files (x86)\SFT 2011-03-22 05:46 . 2011-03-22 05:54 ——– d—–w- c:\program files (x86)\ID Vault 2011-03-22 05:46 . 2011-03-22 05:54 ——– d—–w- c:\windows\ID Vault 2011-03-22 05:46 . 2011-03-22 05:46 ——– d—–w- c:\programdata\White Sky, Inc 2011-03-22 05:22 . 2011-03-22 05:23 ——– d—–w- c:\programdata\Symantec 2011-03-22 05:22 . 2011-03-22 05:22 ——– d—–w- c:\program files\Common Files\Symantec Shared 2011-03-22 05:22 . 2011-03-22 05:22 ——– d—–w- c:\program files (x86)\Symantec 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–r- c:\program files (x86)\Skype 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–w- c:\program files (x86)\Common Files\Skype 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–w- c:\programdata\Skype 2011-03-22 04:50 . 2011-03-22 04:50 0 —-a-w- c:\windows\SysWow64\ConduitEngine.tmp 2011-03-22 04:50 . 2011-03-22 04:50 ——– d—–w- c:\program files (x86)\ConduitEngine 2011-03-22 04:50 . 2011-04-14 01:39 ——– d—–w- c:\users\AppData 2011-03-22 01:22 . 2011-04-10 03:53 ——– d—–w- c:\programdata\CyberLink 2011-03-22 00:44 . 2011-03-22 00:44 ——– d—–w- c:\users\The 2011-03-22 00:43 . 2011-03-22 00:43 ——– d—–w- C:\Hotspot Shield 2011-03-22 00:43 . 2011-03-22 05:59 ——– d—–w- c:\program files (x86)\Hotspot Shield 2011-03-22 00:30 . 2011-03-22 00:30 ——– d—–w- C:\Recovery . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-22 04:54 . 2010-06-24 11:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-02-18 23:36 . 2011-02-18 23:36 51712 —-a-w- c:\windows\system32\drivers\usbaapl64.sys 2011-02-18 23:36 . 2011-02-18 23:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-02-06 14:22 . 2011-02-06 14:22 2219520 —-a-w- c:\windows\system32\Apblend64.dll 2011-02-06 14:22 . 2011-02-06 14:22 1767936 —-a-w- c:\windows\system32\imagereog.dll 2011-02-06 14:22 . 2011-02-06 14:22 2110816 —-a-w- c:\windows\SysWow64\Apblend.dll 2011-02-06 14:22 . 2011-02-06 14:22 1398112 —-a-w- c:\windows\SysWow64\Imagereog.dll 2011-02-06 14:22 . 2011-02-06 14:22 1171456 —-a-w- c:\windows\SysWow64\PicNotify.dll 2011-02-06 14:22 . 2011-02-06 14:22 11104 —-a-w- c:\windows\SysWow64\biologon.dll 2011-02-06 14:22 . 2011-02-06 14:22 1025376 —-a-w- c:\windows\SysWow64\CamOpEx.dll 2011-02-06 14:22 . 2011-02-06 14:22 778240 —-a-w- c:\windows\system32\EncIcons.dll 2011-02-06 14:22 . 2011-02-06 14:22 622592 —-a-w- c:\windows\system32\SimpleExt.dll 2011-02-06 14:22 . 2011-02-06 14:22 1502720 —-a-w- c:\windows\system32\IcnOvrly.dll 2011-02-06 14:21 . 2011-02-06 14:21 876032 —-a-w- c:\windows\SysWow64\DevIL.dll 2011-02-06 14:21 . 2011-02-06 14:21 77824 —-a-w- c:\windows\SysWow64\ILU.dll 2011-02-06 14:21 . 2011-02-06 14:21 3727720 —-a-w- c:\windows\SysWow64\d3dx9_35.dll 2011-02-06 14:21 . 2011-02-06 14:21 32768 —-a-w- c:\windows\SysWow64\ILUT.dll 2011-02-06 14:21 . 2011-02-06 14:21 1044480 —-a-w- c:\windows\SysWow64\3DImageRenderer.dll 2011-02-06 05:28 . 2011-02-06 05:28 51712 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-02-06 05:28 . 2011-02-06 05:28 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-02-06 05:27 . 2011-02-06 05:27 52224 —-a-w- c:\windows\system32\rtutils.dll 2011-02-06 05:27 . 2011-02-06 05:27 37376 —-a-w- c:\windows\SysWow64\rtutils.dll 2011-02-06 05:27 . 2011-02-06 05:27 82944 —-a-w- c:\windows\SysWow64\iccvid.dll 2011-02-06 05:26 . 2011-02-06 05:26 410504 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2011-02-06 05:26 . 2011-02-06 05:26 27016 —-a-w- c:\windows\system32\drivers\amdxata.sys 2011-02-06 05:26 . 2011-02-06 05:26 2566144 —-a-w- c:\windows\system32\esent.dll 2011-02-06 05:26 . 2011-02-06 05:26 187264 —-a-w- c:\windows\system32\drivers\storport.sys 2011-02-06 05:26 . 2011-02-06 05:26 1686016 —-a-w- c:\windows\SysWow64\esent.dll 2011-02-06 05:26 . 2011-02-06 05:26 166280 —-a-w- c:\windows\system32\drivers\nvstor.sys 2011-02-06 05:26 . 2011-02-06 05:26 1657216 —-a-w- c:\windows\system32\drivers\ntfs.sys 2011-02-06 05:26 . 2011-02-06 05:26 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys 2011-02-06 05:26 . 2011-02-06 05:26 107912 —-a-w- c:\windows\system32\drivers\amdsata.sys 2011-02-06 05:25 . 2011-02-06 05:25 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2011-02-06 05:25 . 2011-02-06 05:25 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2011-02-06 05:25 . 2011-02-06 05:25 153160 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2011-02-06 05:25 . 2011-02-06 05:25 1446912 —-a-w- c:\windows\system32\lsasrv.dll 2011-02-06 05:25 . 2011-02-06 05:25 286720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-02-06 05:25 . 2011-02-06 05:25 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-06 05:25 . 2011-02-06 05:25 125952 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-02-06 05:24 . 2011-02-06 05:24 84992 —-a-w- c:\windows\system32\asycfilt.dll 2011-02-06 05:24 . 2011-02-06 05:24 67584 —-a-w- c:\windows\SysWow64\asycfilt.dll 2011-02-06 05:24 . 2011-02-06 05:24 139264 —-a-w- c:\windows\system32\cabview.dll 2011-02-06 05:24 . 2011-02-06 05:24 132608 —-a-w- c:\windows\SysWow64\cabview.dll 2011-02-06 05:23 . 2011-02-06 05:23 85504 —-a-w- c:\windows\SysWow64\secproc_ssp_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 85504 —-a-w- c:\windows\SysWow64\secproc_ssp.dll 2011-02-06 05:23 . 2011-02-06 05:23 424960 —-a-w- c:\windows\system32\secproc.dll 2011-02-06 05:23 . 2011-02-06 05:23 422912 —-a-w- c:\windows\system32\secproc_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 369152 —-a-w- c:\windows\SysWow64\secproc.dll 2011-02-06 05:23 . 2011-02-06 05:23 365568 —-a-w- c:\windows\SysWow64\secproc_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 357888 —-a-w- c:\windows\system32\RMActivate_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 356352 —-a-w- c:\windows\system32\RMActivate.exe 2011-02-06 05:23 . 2011-02-06 05:23 324608 —-a-w- c:\windows\SysWow64\RMActivate_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 320512 —-a-w- c:\windows\SysWow64\RMActivate.exe 2011-02-06 05:23 . 2011-02-06 05:23 306688 —-a-w- c:\windows\system32\RMActivate_ssp.exe 2011-02-06 05:23 . 2011-02-06 05:23 305152 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 280064 —-a-w- c:\windows\SysWow64\RMActivate_ssp.exe 2011-02-06 05:23 . 2011-02-06 05:23 277504 —-a-w- c:\windows\SysWow64\RMActivate_ssp_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 121856 —-a-w- c:\windows\system32\secproc_ssp_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 121856 —-a-w- c:\windows\system32\secproc_ssp.dll 2011-02-06 05:23 . 2011-02-06 05:23 1896832 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-02-06 05:23 . 2011-02-06 05:23 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2011-02-06 05:23 . 2011-02-06 05:23 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2011-02-06 05:23 . 2011-02-06 05:23 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-02-06 05:23 . 2011-02-06 05:23 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2011-02-06 05:23 . 2011-02-06 05:23 243200 —-a-w- c:\windows\system32\wow64.dll 2011-02-06 05:23 . 2011-02-06 05:23 2048 —-a-w- c:\windows\SysWow64\user.exe 2011-02-06 05:23 . 2011-02-06 05:23 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2011-02-06 05:23 . 2011-02-06 05:23 220672 —-a-w- c:\windows\system32\wintrust.dll 2011-02-06 05:23 . 2011-02-06 05:23 172032 —-a-w- c:\windows\SysWow64\wintrust.dll 2011-02-06 05:22 . 2011-02-06 05:22 613888 —-a-w- c:\windows\system32\psisdecd.dll 2011-02-06 05:22 . 2011-02-06 05:22 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll 2011-02-06 05:22 . 2011-02-06 05:22 389632 —-a-w- c:\windows\system32\winlogon.exe 2011-02-06 05:22 . 2011-02-06 05:22 2870272 —-a-w- c:\windows\explorer.exe 2011-02-06 05:22 . 2011-02-06 05:22 2614272 —-a-w- c:\windows\SysWow64\explorer.exe 2011-02-06 05:22 . 2011-02-06 05:22 14336 —-a-w- c:\windows\system32\drivers\sffp_sd.sys 2011-02-06 05:21 . 2011-02-06 05:21 91648 —-a-w- c:\windows\SysWow64\avifil32.dll 2011-02-06 05:21 . 2011-02-06 05:21 84480 —-a-w- c:\windows\SysWow64\mciavi32.dll 2011-02-06 05:21 . 2011-02-06 05:21 54272 —-a-w- c:\windows\system32\iyuv_32.dll 2011-02-06 05:21 . 2011-02-06 05:21 50176 —-a-w- c:\windows\SysWow64\iyuv_32.dll 2011-02-06 05:21 . 2011-02-06 05:21 38912 —-a-w- c:\windows\system32\msvidc32.dll 2011-02-06 05:21 . 2011-02-06 05:21 31744 —-a-w- c:\windows\SysWow64\msvidc32.dll 2011-02-06 05:21 . 2011-02-06 05:21 25088 —-a-w- c:\windows\system32\msyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 22016 —-a-w- c:\windows\SysWow64\msyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 16384 —-a-w- c:\windows\system32\msrle32.dll 2011-02-06 05:21 . 2011-02-06 05:21 1572352 —-a-w- c:\windows\system32\quartz.dll 2011-02-06 05:21 . 2011-02-06 05:21 14848 —-a-w- c:\windows\system32\tsbyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 13312 —-a-w- c:\windows\SysWow64\msrle32.dll 2011-02-06 05:21 . 2011-02-06 05:21 1328640 —-a-w- c:\windows\SysWow64\quartz.dll 2011-02-06 05:21 . 2011-02-06 05:21 12288 —-a-w- c:\windows\SysWow64\tsbyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 70656 —-a-w- c:\windows\SysWow64\fontsub.dll 2011-02-06 05:21 . 2011-02-06 05:21 100864 —-a-w- c:\windows\system32\fontsub.dll 2011-02-06 05:20 . 2011-02-06 05:20 311808 —-a-w- c:\windows\system32\msv1_0.dll 2011-02-06 05:20 . 2011-02-06 05:20 257024 —-a-w- c:\windows\SysWow64\msv1_0.dll 2011-02-06 05:20 . 2011-02-06 05:20 46592 —-a-w- c:\windows\system32\msasn1.dll 2011-02-06 05:20 . 2011-02-06 05:20 34816 —-a-w- c:\windows\SysWow64\msasn1.dll 2011-02-06 05:19 . 2011-02-06 05:19 1975296 —-a-w- c:\windows\system32\CertEnroll.dll 2011-02-06 05:19 . 2011-02-06 05:19 1320960 —-a-w- c:\windows\SysWow64\CertEnroll.dll . . ((((((((((((((((((((((((((((( SnapShot@2011-04-14_01.37.37 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:54 . 2011-04-15 01:55 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-04-14 01:22 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-04-14 01:22 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-04-15 01:55 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-04-14 01:22 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-04-15 01:55 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-02-06 13:44 . 2011-04-14 01:43 39074 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-04-14 01:43 33916 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin - 2011-03-22 01:51 . 2011-04-14 01:22 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-03-22 01:51 . 2011-04-15 01:57 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-03-22 01:51 . 2011-04-14 01:22 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-03-22 01:51 . 2011-04-15 01:57 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-03-22 01:51 . 2011-04-14 01:22 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-22 01:51 . 2011-04-15 01:57 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-22 01:51 . 2011-04-15 01:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-03-22 01:51 . 2011-04-14 01:22 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-03-22 01:51 . 2011-04-15 01:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-03-22 01:51 . 2011-04-14 01:22 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-03-22 05:45 . 2011-04-14 01:24 5602 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3339888093-537584527-826026314-1000_UserData.bin + 2011-03-22 05:45 . 2011-04-14 01:43 5602 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3339888093-537584527-826026314-1000_UserData.bin + 2011-04-15 01:55 . 2011-04-15 01:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-04-14 01:22 . 2011-04-14 01:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2011-04-15 01:55 . 2011-04-15 01:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-04-14 01:22 . 2011-04-14 01:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-03-22 01:48 . 2011-04-14 21:35 271554 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin + 2011-03-23 01:57 . 2011-04-15 01:17 266590 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2009-07-14 02:36 . 2011-04-14 00:36 624178 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-04-15 00:54 624178 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-04-15 00:54 106522 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2011-04-14 00:36 106522 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2011-04-14 01:17 403804 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2011-04-15 01:53 403804 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2011-03-22 05:39 . 2011-04-14 01:17 1373544 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat + 2011-03-22 05:39 . 2011-04-15 01:53 1373544 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat - 2009-07-14 02:34 . 2011-04-14 00:44 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT + 2009-07-14 02:34 . 2011-04-14 21:55 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-03-23 136176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696] "331BigDog"="c:\program files (x86)\USB Camera\VM331_STI.EXE" [2010-01-15 536576] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-12-03 35184] "VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2011-02-06 3122528] "UCam_Menu"="c:\program files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "YouCam Mirror Tray icon"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2010-03-02 171104] "UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408] "GIDDesktop"="c:\program files (x86)\SFT\GuardedID\gidd.exe" [2010-09-20 391944] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-03-07 421160] "ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2009-02-03 115560] . c:\users\The\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 227712] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2009-8-11 1080608] ID Vault.lnk - c:\program files (x86)\ID Vault\IDVault.exe [2010-12-4 2879816] Lenovo Smile Dock.lnk - c:\program files (x86)\DDNi\Lenovo Smile Dock\Delay.exe [2010-6-30 9728] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer5"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [x] R3 IGRS;IGRS;c:\program files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152] R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192] R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [x] S1 GIDv2;GIDv2; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336] S2 IDVaultSvc;IDVault Service;c:\program files (x86)\ID Vault\IDVaultSvc.exe [2010-12-04 42312] S2 Oasis2Service;Oasis2Service;c:\program files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe [2010-06-23 46080] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-12-09 2320920] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [x] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-06-17 132656] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys [x] S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg] 2010-09-20 17:15 432904 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe . Contents of the 'Scheduled Tasks' folder . 2011-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3339888093-537584527-826026314-1000Core.job - c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-23 02:03] . 2011-04-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3339888093-537584527-826026314-1000UA.job - c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-23 02:03] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc] @="{771C7324-DA80-49D3-8017-753B0AF60951}" [HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}] 2011-02-06 14:22 1502720 —-a-w- c:\windows\System32\IcnOvrly.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "combofix"="c:\combofix\CF31042.cfxxe" [X] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-05-07 16416360] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272] "ETDWare"="%ProgramFiles%\Elantech\ETDCtrl.exe" [BU] "OnekeyStudio"="c:\program files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe" [2009-12-19 776608] "EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\utility.exe" [2010-04-12 4462496] "Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2010-03-18 7056800] . ——- Supplementary Scan ——- . uStart Page = hxxp://lenovo.msn.com uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://lenovo.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Send image to &Bluetooth Device… - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm TCP: {007C9D54-1894-4DC7-8D9F-C4D8201BF272} = 10.1.24.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL FF - ProfilePath - c:\users\The\AppData\Roaming\Mozilla\Firefox\Profiles\atuefuve.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Hotspot Shield Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1561552&SearchSource=13 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF - Ext: afurladvisor: [removed] - c:\program files (x86)\Mozilla Firefox\extensions\[removed] FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Hotspot Shield Community Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - %profile%\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d} FF - Ext: springshine: [removed] - %profile%\extensions\[removed] FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed] FF - user.js: general.useragent.extra.brc - . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) AddRemove-Hotspot_Shield Toolbar - c:\program files (x86)\Hotspot_Shield\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Symantec Shared\ccSvcHst.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe c:\program files (x86)\Hotspot Shield\HssWPR\hsssrv.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\program files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe c:\program files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe c:\program files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe . ************************************************************************** . Completion time: 2011-04-14 19:00:21 - machine was rebooted ComboFix-quarantined-files.txt 2011-04-15 02:00 ComboFix2.txt 2011-04-14 01:39 . Pre-Run: 416,291,827,712 bytes free Post-Run: 415,741,038,592 bytes free . - - End Of File - - 74675C206FB2E41CC12CDCDD8396F41F
Sorry for the delay bannana.

Please go to this link, and follow the settings to reset your Firefox preferences. Also select the Reset toolbars and controls checkbox and the Restore default search engines checkbox.

Then…
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Folder::
c:\program files (x86)\Hotspot Shield


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
ComboFix 11-04-13.02 - The 04/20/2011 14:16:59.3.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3959.2548 [GMT -7:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe Command switches used :: c:\users\The\Desktop\CFScript.txt AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: Symantec Endpoint Protection *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: Symantec Endpoint Protection *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . - REDUCED FUNCTIONALITY MODE - . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Hotspot Shield c:\program files (x86)\Hotspot Shield\bin\curl-ca-bundle.crt c:\program files (x86)\Hotspot Shield\bin\curllib.dll c:\program files (x86)\Hotspot Shield\bin\ffinst.exe c:\program files (x86)\Hotspot Shield\bin\hssinst.dll c:\program files (x86)\Hotspot Shield\bin\HssInstaller.exe c:\program files (x86)\Hotspot Shield\bin\HssInstaller64.exe c:\program files (x86)\Hotspot Shield\bin\HssTrayService.exe c:\program files (x86)\Hotspot Shield\bin\hsswd.exe c:\program files (x86)\Hotspot Shield\bin\lang\gui-ara.dll c:\program files (x86)\Hotspot Shield\bin\lang\gui-bur.dll c:\program files (x86)\Hotspot Shield\bin\lang\gui-chi.dll c:\program files (x86)\Hotspot Shield\bin\lang\gui-eng.dll c:\program files (x86)\Hotspot Shield\bin\lang\gui-fre.dll c:\program files (x86)\Hotspot Shield\bin\lang\gui-ger.dll c:\program files (x86)\Hotspot Shield\bin\lang\gui-per.dll c:\program files (x86)\Hotspot Shield\bin\lang\gui-rus.dll c:\program files (x86)\Hotspot Shield\bin\lang\gui-spa.dll c:\program files (x86)\Hotspot Shield\bin\lang\gui-vie.dll c:\program files (x86)\Hotspot Shield\bin\libcurl.dll c:\program files (x86)\Hotspot Shield\bin\libeay32.dll c:\program files (x86)\Hotspot Shield\bin\libidn-11.dll c:\program files (x86)\Hotspot Shield\bin\libpkcs11-helper-1.dll c:\program files (x86)\Hotspot Shield\bin\libsasl.dll c:\program files (x86)\Hotspot Shield\bin\libssl32.dll c:\program files (x86)\Hotspot Shield\bin\msvcr90.dll c:\program files (x86)\Hotspot Shield\bin\openldap.dll c:\program files (x86)\Hotspot Shield\bin\openvpn.exe c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe c:\program files (x86)\Hotspot Shield\bin\openvpntray.exe c:\program files (x86)\Hotspot Shield\bin\ssleay32.dll c:\program files (x86)\Hotspot Shield\bin\tapinstall.exe c:\program files (x86)\Hotspot Shield\config\config.hvpn c:\program files (x86)\Hotspot Shield\config\hsscon.cfg c:\program files (x86)\Hotspot Shield\config\hssst.cfg c:\program files (x86)\Hotspot Shield\config\sd-info-direct.cfg c:\program files (x86)\Hotspot Shield\config\sd-info-failed.cfg c:\program files (x86)\Hotspot Shield\config\sd-info-main.cfg c:\program files (x86)\Hotspot Shield\config\sd-info-saved.cfg c:\program files (x86)\Hotspot Shield\config\sdcon.cfg c:\program files (x86)\Hotspot Shield\config\upd_dat.cfg c:\program files (x86)\Hotspot Shield\driver\OemWin2k.inf c:\program files (x86)\Hotspot Shield\driver\taphss.cat c:\program files (x86)\Hotspot Shield\driver\taphss.sys c:\program files (x86)\Hotspot Shield\hss.ico c:\program files (x86)\Hotspot Shield\HssFF\config_ff.txt c:\program files (x86)\Hotspot Shield\HssFF\config_ff_srch.txt c:\program files (x86)\Hotspot Shield\hssie\config.txt c:\program files (x86)\Hotspot Shield\hssie\config_srch.txt c:\program files (x86)\Hotspot Shield\hssie\HssIE.dll c:\program files (x86)\Hotspot Shield\hssie\HssIE_64.dll c:\program files (x86)\Hotspot Shield\hsswd\default\default.cfg c:\program files (x86)\Hotspot Shield\HssWPR\hssdrv.cat c:\program files (x86)\Hotspot Shield\HssWPR\hssdrv.sys c:\program files (x86)\Hotspot Shield\HssWPR\hssdrv_m.cat c:\program files (x86)\Hotspot Shield\HssWPR\hssinst.dll c:\program files (x86)\Hotspot Shield\HssWPR\HssInstaller64.exe c:\program files (x86)\Hotspot Shield\HssWPR\hsssrv.exe c:\program files (x86)\Hotspot Shield\HssWPR\nethss.inf c:\program files (x86)\Hotspot Shield\HssWPR\nethss_m.inf c:\program files (x86)\Hotspot Shield\HssWPR\wpr.conf c:\program files (x86)\Hotspot Shield\htdocs\check.js c:\program files (x86)\Hotspot Shield\htdocs\conect.png c:\program files (x86)\Hotspot Shield\htdocs\connect_original.png c:\program files (x86)\Hotspot Shield\htdocs\connect_stay.png c:\program files (x86)\Hotspot Shield\htdocs\disconnect.html c:\program files (x86)\Hotspot Shield\htdocs\disconnect_original.png c:\program files (x86)\Hotspot Shield\htdocs\greenico.png c:\program files (x86)\Hotspot Shield\htdocs\HSS_logo.png c:\program files (x86)\Hotspot Shield\htdocs\lang.js c:\program files (x86)\Hotspot Shield\htdocs\logo.png c:\program files (x86)\Hotspot Shield\htdocs\message.html c:\program files (x86)\Hotspot Shield\htdocs\nsidefs.js c:\program files (x86)\Hotspot Shield\htdocs\oac.html c:\program files (x86)\Hotspot Shield\htdocs\oac.js c:\program files (x86)\Hotspot Shield\htdocs\redico.png c:\program files (x86)\Hotspot Shield\htdocs\restart.html c:\program files (x86)\Hotspot Shield\htdocs\turnoff.png c:\program files (x86)\Hotspot Shield\htdocs\turnon.png c:\program files (x86)\Hotspot Shield\license.txt c:\program files (x86)\Hotspot Shield\log\config.log c:\program files (x86)\Hotspot Shield\log\oas.log c:\program files (x86)\Hotspot Shield\Uninstall.exe . . ((((((((((((((((((((((((( Files Created from 2011-03-20 to 2011-04-20 ))))))))))))))))))))))))))))))) . . 2011-04-20 21:18 . 2011-04-20 21:18 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-04-15 02:15 . 2011-04-15 02:15 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-04-12 08:31 . 2011-04-12 08:31 ——– d—–w- c:\program files (x86)\Trend Micro 2011-04-10 04:28 . 2010-12-21 01:09 38224 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-04-10 04:28 . 2011-04-10 04:28 ——– d—–w- c:\programdata\Malwarebytes 2011-04-10 04:28 . 2011-04-13 02:35 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-04-10 04:28 . 2010-12-21 01:08 24152 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-04-10 04:11 . 2011-03-23 17:11 8424784 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{691DA5B2-4B83-42DA-BACD-377205D3A74E}\mpengine.dll 2011-03-25 19:33 . 2011-03-25 19:33 ——– dc—-w- c:\windows\system32\DRVSTORE 2011-03-25 19:33 . 2009-05-18 20:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-03-25 19:33 . 2008-04-17 19:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-03-25 19:33 . 2008-04-17 19:12 107368 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-03-25 19:33 . 2011-03-25 19:33 ——– d—–w- c:\program files\iPod 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001} 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\program files\iTunes 2011-03-25 19:32 . 2011-03-25 19:33 ——– d—–w- c:\program files (x86)\iTunes 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-03-25 19:31 . 2011-03-25 19:31 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-03-25 19:30 . 2011-03-25 19:31 ——– d—–w- c:\program files (x86)\QuickTime 2011-03-25 19:30 . 2011-03-25 19:32 ——– d—–w- c:\programdata\Apple Computer 2011-03-25 19:29 . 2011-03-25 19:29 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-03-25 19:29 . 2011-03-25 19:29 ——– d—–w- c:\program files\Common Files\Apple 2011-03-25 19:28 . 2011-03-25 19:29 ——– d—–w- c:\program files\Bonjour 2011-03-25 19:28 . 2011-03-25 19:29 ——– d—–w- c:\program files (x86)\Bonjour 2011-03-25 19:28 . 2011-03-25 21:02 ——– d—–w- c:\programdata\Apple 2011-03-25 19:28 . 2011-03-25 19:33 ——– d—–w- c:\program files (x86)\Common Files\Apple 2011-03-25 02:35 . 2011-03-25 02:35 ——– d—–w- c:\programdata\RegWork 2011-03-25 02:29 . 2011-04-15 02:15 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-03-25 02:29 . 2011-03-25 02:29 ——– d—–w- c:\program files (x86)\Java 2011-03-24 21:02 . 2011-03-24 21:02 ——– d—–w- c:\windows\SysWow64\Wat 2011-03-24 21:02 . 2011-03-24 21:02 ——– d—–w- c:\windows\system32\Wat 2011-03-24 18:53 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll 2011-03-24 18:53 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll 2011-03-24 18:48 . 2009-11-25 19:47 99176 —-a-w- c:\windows\SysWow64\PresentationHostProxy.dll 2011-03-24 18:48 . 2009-11-25 19:47 49472 —-a-w- c:\windows\SysWow64\netfxperf.dll 2011-03-24 18:48 . 2009-11-25 19:47 297808 —-a-w- c:\windows\SysWow64\mscoree.dll 2011-03-24 18:48 . 2009-11-25 19:47 295264 —-a-w- c:\windows\SysWow64\PresentationHost.exe 2011-03-24 18:48 . 2009-11-25 19:47 1130824 —-a-w- c:\windows\SysWow64\dfshim.dll 2011-03-24 18:48 . 2009-11-25 19:47 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll 2011-03-24 18:48 . 2009-11-25 19:47 444752 —-a-w- c:\windows\system32\mscoree.dll 2011-03-24 18:48 . 2009-11-25 19:47 320352 —-a-w- c:\windows\system32\PresentationHost.exe 2011-03-24 18:48 . 2009-11-25 19:47 48960 —-a-w- c:\windows\system32\netfxperf.dll 2011-03-24 18:48 . 2009-11-25 19:47 1942856 —-a-w- c:\windows\system32\dfshim.dll 2011-03-24 18:42 . 2010-03-04 04:40 184832 —-a-w- c:\windows\system32\drivers\usbvideo.sys 2011-03-24 18:42 . 2010-03-04 04:32 243712 —-a-w- c:\windows\system32\drivers\ks.sys 2011-03-23 02:14 . 2011-04-01 23:07 ——– d—–w- c:\program files (x86)\VitalSource Bookshelf 2011-03-23 00:25 . 2011-01-07 08:07 662528 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-23 00:25 . 2011-01-07 07:31 442880 —-a-w- c:\windows\SysWow64\XpsPrint.dll 2011-03-23 00:25 . 2011-01-07 08:07 475648 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-03-23 00:25 . 2011-01-07 07:31 288256 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2011-03-23 00:25 . 2010-08-21 06:29 558592 —-a-w- c:\windows\system32\spoolsv.exe 2011-03-23 00:23 . 2010-12-23 06:07 723968 —-a-w- c:\windows\system32\EncDec.dll 2011-03-23 00:22 . 2011-01-05 04:00 3127808 —-a-w- c:\windows\system32\win32k.sys 2011-03-23 00:22 . 2010-03-04 07:57 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-23 00:22 . 2010-03-04 07:57 2080256 —-a-w- c:\program files\Windows Mail\msoe.dll 2011-03-23 00:22 . 2010-03-04 07:33 1619968 —-a-w- c:\program files (x86)\Windows Mail\msoe.dll 2011-03-23 00:22 . 2010-03-04 07:33 740864 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-03-23 00:22 . 2010-08-04 07:07 552960 —-a-w- c:\windows\system32\msdri.dll 2011-03-23 00:22 . 2010-08-04 07:05 288256 —-a-w- c:\windows\system32\MSNP.ax 2011-03-23 00:22 . 2010-08-04 06:15 204288 —-a-w- c:\windows\SysWow64\MSNP.ax 2011-03-23 00:22 . 2010-08-21 06:36 340992 —-a-w- c:\windows\system32\schannel.dll 2011-03-23 00:22 . 2010-08-21 05:36 224256 —-a-w- c:\windows\SysWow64\schannel.dll 2011-03-23 00:22 . 2010-08-21 06:31 633856 —-a-w- c:\windows\system32\comctl32.dll 2011-03-23 00:22 . 2010-08-21 05:33 530432 —-a-w- c:\windows\SysWow64\comctl32.dll 2011-03-23 00:20 . 2010-11-02 05:12 1837568 —-a-w- c:\windows\system32\d3d10warp.dll 2011-03-23 00:19 . 2010-10-27 05:18 5510528 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-03-23 00:18 . 2010-10-16 04:33 987136 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll 2011-03-23 00:18 . 2010-10-16 04:33 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll 2011-03-23 00:18 . 2010-10-16 04:33 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll 2011-03-23 00:18 . 2010-10-16 04:33 208896 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll 2011-03-23 00:18 . 2010-08-27 03:38 463360 —-a-w- c:\windows\system32\drivers\srv.sys 2011-03-23 00:18 . 2010-08-27 03:37 402944 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-03-23 00:18 . 2010-08-27 06:14 236032 —-a-w- c:\windows\system32\srvsvc.dll 2011-03-23 00:18 . 2010-08-27 05:46 9728 —-a-w- c:\windows\SysWow64\sscore.dll 2011-03-23 00:18 . 2010-08-27 03:37 161792 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-03-23 00:11 . 2011-03-23 00:12 ——– dc-h–w- c:\programdata\{DC88B4E9-0A30-46AE-A4D5-38E7C0D304E4} 2011-03-22 06:46 . 2011-03-22 06:46 ——– d—–w- c:\programdata\Oberon Media 2011-03-22 06:06 . 2011-03-22 06:06 ——– d—–w- c:\program files (x86)\Common Files\Oberon Media 2011-03-22 06:06 . 2011-03-22 06:44 ——– d—–w- c:\program files (x86)\Oberon Media 2011-03-22 06:06 . 2011-04-10 03:42 ——– d—–w- c:\program files (x86)\Lenovo Games 2011-03-22 05:59 . 2011-03-22 05:59 ——– d—–w- c:\programdata\hssff 2011-03-22 05:55 . 2010-09-20 17:14 65816 ——w- c:\windows\system32\GIDLogonCP64.dll 2011-03-22 05:55 . 2010-09-20 17:13 442656 ——w- c:\windows\system32\GIDHookLogon64.dll 2011-03-22 05:48 . 2011-03-22 05:48 ——– d—–w- c:\programdata\IsolatedStorage 2011-03-22 05:47 . 2010-09-20 17:09 29288 ——w- c:\windows\system32\drivers\gidv2.sys 2011-03-22 05:47 . 2009-06-12 23:32 109064 ——w- c:\windows\system32\EasyHook64.dll 2011-03-22 05:47 . 2010-09-20 17:13 458520 ——w- c:\windows\system32\GIDHOOK64.DLL 2011-03-22 05:47 . 2010-09-20 17:12 100624 ——w- c:\windows\system32\GIDBIN3.DLL 2011-03-22 05:47 . 2010-09-20 17:12 204560 ——w- c:\windows\system32\GIDBIN1.DLL 2011-03-22 05:47 . 2011-03-22 05:47 ——– d—–w- c:\programdata\GID 2011-03-22 05:46 . 2011-03-22 05:46 ——– d—–w- c:\program files (x86)\SFT 2011-03-22 05:46 . 2011-03-22 05:54 ——– d—–w- c:\program files (x86)\ID Vault 2011-03-22 05:46 . 2011-03-22 05:54 ——– d—–w- c:\windows\ID Vault 2011-03-22 05:46 . 2011-03-22 05:46 ——– d—–w- c:\programdata\White Sky, Inc 2011-03-22 05:22 . 2011-03-22 05:23 ——– d—–w- c:\programdata\Symantec 2011-03-22 05:22 . 2011-03-22 05:22 ——– d—–w- c:\program files\Common Files\Symantec Shared 2011-03-22 05:22 . 2011-03-22 05:22 ——– d—–w- c:\program files (x86)\Symantec 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–r- c:\program files (x86)\Skype 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–w- c:\program files (x86)\Common Files\Skype 2011-03-22 05:04 . 2011-03-22 05:04 ——– d—–w- c:\programdata\Skype 2011-03-22 04:50 . 2011-03-22 04:50 0 —-a-w- c:\windows\SysWow64\ConduitEngine.tmp 2011-03-22 04:50 . 2011-03-22 04:50 ——– d—–w- c:\program files (x86)\ConduitEngine 2011-03-22 04:50 . 2011-04-14 01:39 ——– d—–w- c:\users\AppData 2011-03-22 01:22 . 2011-04-10 03:53 ——– d—–w- c:\programdata\CyberLink 2011-03-22 00:44 . 2011-03-22 00:44 ——– d—–w- c:\users\The 2011-03-22 00:43 . 2011-03-22 00:43 ——– d—–w- C:\Hotspot Shield 2011-03-22 00:30 . 2011-03-22 00:30 ——– d—–w- C:\Recovery . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-22 04:54 . 2010-06-24 11:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-02-18 23:36 . 2011-02-18 23:36 51712 —-a-w- c:\windows\system32\drivers\usbaapl64.sys 2011-02-18 23:36 . 2011-02-18 23:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-02-06 14:22 . 2011-02-06 14:22 2219520 —-a-w- c:\windows\system32\Apblend64.dll 2011-02-06 14:22 . 2011-02-06 14:22 1767936 —-a-w- c:\windows\system32\imagereog.dll 2011-02-06 14:22 . 2011-02-06 14:22 2110816 —-a-w- c:\windows\SysWow64\Apblend.dll 2011-02-06 14:22 . 2011-02-06 14:22 1398112 —-a-w- c:\windows\SysWow64\Imagereog.dll 2011-02-06 14:22 . 2011-02-06 14:22 1171456 —-a-w- c:\windows\SysWow64\PicNotify.dll 2011-02-06 14:22 . 2011-02-06 14:22 11104 —-a-w- c:\windows\SysWow64\biologon.dll 2011-02-06 14:22 . 2011-02-06 14:22 1025376 —-a-w- c:\windows\SysWow64\CamOpEx.dll 2011-02-06 14:22 . 2011-02-06 14:22 778240 —-a-w- c:\windows\system32\EncIcons.dll 2011-02-06 14:22 . 2011-02-06 14:22 622592 —-a-w- c:\windows\system32\SimpleExt.dll 2011-02-06 14:22 . 2011-02-06 14:22 1502720 —-a-w- c:\windows\system32\IcnOvrly.dll 2011-02-06 14:21 . 2011-02-06 14:21 876032 —-a-w- c:\windows\SysWow64\DevIL.dll 2011-02-06 14:21 . 2011-02-06 14:21 77824 —-a-w- c:\windows\SysWow64\ILU.dll 2011-02-06 14:21 . 2011-02-06 14:21 3727720 —-a-w- c:\windows\SysWow64\d3dx9_35.dll 2011-02-06 14:21 . 2011-02-06 14:21 32768 —-a-w- c:\windows\SysWow64\ILUT.dll 2011-02-06 14:21 . 2011-02-06 14:21 1044480 —-a-w- c:\windows\SysWow64\3DImageRenderer.dll 2011-02-06 05:28 . 2011-02-06 05:28 51712 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-02-06 05:28 . 2011-02-06 05:28 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-02-06 05:27 . 2011-02-06 05:27 52224 —-a-w- c:\windows\system32\rtutils.dll 2011-02-06 05:27 . 2011-02-06 05:27 37376 —-a-w- c:\windows\SysWow64\rtutils.dll 2011-02-06 05:27 . 2011-02-06 05:27 82944 —-a-w- c:\windows\SysWow64\iccvid.dll 2011-02-06 05:26 . 2011-02-06 05:26 410504 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2011-02-06 05:26 . 2011-02-06 05:26 27016 —-a-w- c:\windows\system32\drivers\amdxata.sys 2011-02-06 05:26 . 2011-02-06 05:26 2566144 —-a-w- c:\windows\system32\esent.dll 2011-02-06 05:26 . 2011-02-06 05:26 187264 —-a-w- c:\windows\system32\drivers\storport.sys 2011-02-06 05:26 . 2011-02-06 05:26 1686016 —-a-w- c:\windows\SysWow64\esent.dll 2011-02-06 05:26 . 2011-02-06 05:26 166280 —-a-w- c:\windows\system32\drivers\nvstor.sys 2011-02-06 05:26 . 2011-02-06 05:26 1657216 —-a-w- c:\windows\system32\drivers\ntfs.sys 2011-02-06 05:26 . 2011-02-06 05:26 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys 2011-02-06 05:26 . 2011-02-06 05:26 107912 —-a-w- c:\windows\system32\drivers\amdsata.sys 2011-02-06 05:25 . 2011-02-06 05:25 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2011-02-06 05:25 . 2011-02-06 05:25 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2011-02-06 05:25 . 2011-02-06 05:25 153160 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2011-02-06 05:25 . 2011-02-06 05:25 1446912 —-a-w- c:\windows\system32\lsasrv.dll 2011-02-06 05:25 . 2011-02-06 05:25 286720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-02-06 05:25 . 2011-02-06 05:25 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-06 05:25 . 2011-02-06 05:25 125952 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-02-06 05:24 . 2011-02-06 05:24 84992 —-a-w- c:\windows\system32\asycfilt.dll 2011-02-06 05:24 . 2011-02-06 05:24 67584 —-a-w- c:\windows\SysWow64\asycfilt.dll 2011-02-06 05:24 . 2011-02-06 05:24 139264 —-a-w- c:\windows\system32\cabview.dll 2011-02-06 05:24 . 2011-02-06 05:24 132608 —-a-w- c:\windows\SysWow64\cabview.dll 2011-02-06 05:23 . 2011-02-06 05:23 85504 —-a-w- c:\windows\SysWow64\secproc_ssp_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 85504 —-a-w- c:\windows\SysWow64\secproc_ssp.dll 2011-02-06 05:23 . 2011-02-06 05:23 424960 —-a-w- c:\windows\system32\secproc.dll 2011-02-06 05:23 . 2011-02-06 05:23 422912 —-a-w- c:\windows\system32\secproc_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 369152 —-a-w- c:\windows\SysWow64\secproc.dll 2011-02-06 05:23 . 2011-02-06 05:23 365568 —-a-w- c:\windows\SysWow64\secproc_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 357888 —-a-w- c:\windows\system32\RMActivate_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 356352 —-a-w- c:\windows\system32\RMActivate.exe 2011-02-06 05:23 . 2011-02-06 05:23 324608 —-a-w- c:\windows\SysWow64\RMActivate_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 320512 —-a-w- c:\windows\SysWow64\RMActivate.exe 2011-02-06 05:23 . 2011-02-06 05:23 306688 —-a-w- c:\windows\system32\RMActivate_ssp.exe 2011-02-06 05:23 . 2011-02-06 05:23 305152 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 280064 —-a-w- c:\windows\SysWow64\RMActivate_ssp.exe 2011-02-06 05:23 . 2011-02-06 05:23 277504 —-a-w- c:\windows\SysWow64\RMActivate_ssp_isv.exe 2011-02-06 05:23 . 2011-02-06 05:23 121856 —-a-w- c:\windows\system32\secproc_ssp_isv.dll 2011-02-06 05:23 . 2011-02-06 05:23 121856 —-a-w- c:\windows\system32\secproc_ssp.dll 2011-02-06 05:23 . 2011-02-06 05:23 1896832 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-02-06 05:23 . 2011-02-06 05:23 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2011-02-06 05:23 . 2011-02-06 05:23 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2011-02-06 05:23 . 2011-02-06 05:23 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-02-06 05:23 . 2011-02-06 05:23 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2011-02-06 05:23 . 2011-02-06 05:23 243200 —-a-w- c:\windows\system32\wow64.dll 2011-02-06 05:23 . 2011-02-06 05:23 2048 —-a-w- c:\windows\SysWow64\user.exe 2011-02-06 05:23 . 2011-02-06 05:23 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2011-02-06 05:23 . 2011-02-06 05:23 220672 —-a-w- c:\windows\system32\wintrust.dll 2011-02-06 05:23 . 2011-02-06 05:23 172032 —-a-w- c:\windows\SysWow64\wintrust.dll 2011-02-06 05:22 . 2011-02-06 05:22 613888 —-a-w- c:\windows\system32\psisdecd.dll 2011-02-06 05:22 . 2011-02-06 05:22 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll 2011-02-06 05:22 . 2011-02-06 05:22 389632 —-a-w- c:\windows\system32\winlogon.exe 2011-02-06 05:22 . 2011-02-06 05:22 2870272 —-a-w- c:\windows\explorer.exe 2011-02-06 05:22 . 2011-02-06 05:22 2614272 —-a-w- c:\windows\SysWow64\explorer.exe 2011-02-06 05:22 . 2011-02-06 05:22 14336 —-a-w- c:\windows\system32\drivers\sffp_sd.sys 2011-02-06 05:21 . 2011-02-06 05:21 91648 —-a-w- c:\windows\SysWow64\avifil32.dll 2011-02-06 05:21 . 2011-02-06 05:21 84480 —-a-w- c:\windows\SysWow64\mciavi32.dll 2011-02-06 05:21 . 2011-02-06 05:21 54272 —-a-w- c:\windows\system32\iyuv_32.dll 2011-02-06 05:21 . 2011-02-06 05:21 50176 —-a-w- c:\windows\SysWow64\iyuv_32.dll 2011-02-06 05:21 . 2011-02-06 05:21 38912 —-a-w- c:\windows\system32\msvidc32.dll 2011-02-06 05:21 . 2011-02-06 05:21 31744 —-a-w- c:\windows\SysWow64\msvidc32.dll 2011-02-06 05:21 . 2011-02-06 05:21 25088 —-a-w- c:\windows\system32\msyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 22016 —-a-w- c:\windows\SysWow64\msyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 16384 —-a-w- c:\windows\system32\msrle32.dll 2011-02-06 05:21 . 2011-02-06 05:21 1572352 —-a-w- c:\windows\system32\quartz.dll 2011-02-06 05:21 . 2011-02-06 05:21 14848 —-a-w- c:\windows\system32\tsbyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 13312 —-a-w- c:\windows\SysWow64\msrle32.dll 2011-02-06 05:21 . 2011-02-06 05:21 1328640 —-a-w- c:\windows\SysWow64\quartz.dll 2011-02-06 05:21 . 2011-02-06 05:21 12288 —-a-w- c:\windows\SysWow64\tsbyuv.dll 2011-02-06 05:21 . 2011-02-06 05:21 70656 —-a-w- c:\windows\SysWow64\fontsub.dll 2011-02-06 05:21 . 2011-02-06 05:21 100864 —-a-w- c:\windows\system32\fontsub.dll 2011-02-06 05:20 . 2011-02-06 05:20 311808 —-a-w- c:\windows\system32\msv1_0.dll 2011-02-06 05:20 . 2011-02-06 05:20 257024 —-a-w- c:\windows\SysWow64\msv1_0.dll 2011-02-06 05:20 . 2011-02-06 05:20 46592 —-a-w- c:\windows\system32\msasn1.dll 2011-02-06 05:20 . 2011-02-06 05:20 34816 —-a-w- c:\windows\SysWow64\msasn1.dll 2011-02-06 05:19 . 2011-02-06 05:19 1975296 —-a-w- c:\windows\system32\CertEnroll.dll 2011-02-06 05:19 . 2011-02-06 05:19 1320960 —-a-w- c:\windows\SysWow64\CertEnroll.dll . . ((((((((((((((((((((((((((((( SnapShot@2011-04-14_01.37.37 ))))))))))))))))))))))))))))))))))))))))) . - 2009-07-14 04:54 . 2011-04-14 01:22 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2011-04-20 21:17 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-04-14 01:22 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-04-20 21:17 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-04-20 21:17 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2011-04-14 01:22 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-02-06 13:44 . 2011-04-14 01:43 39074 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-04-15 01:58 33916 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin - 2011-03-22 01:51 . 2011-04-14 01:22 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-03-22 01:51 . 2011-04-20 21:23 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-03-22 01:51 . 2011-04-14 01:22 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-03-22 01:51 . 2011-04-20 21:23 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-03-22 01:51 . 2011-04-14 01:22 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-22 01:51 . 2011-04-20 21:23 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-22 01:51 . 2011-04-20 21:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-03-22 01:51 . 2011-04-14 01:22 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-03-22 01:51 . 2011-04-14 01:22 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-22 01:51 . 2011-04-20 21:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-22 05:45 . 2011-04-15 01:58 5908 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3339888093-537584527-826026314-1000_UserData.bin + 2011-04-16 22:47 . 2011-04-16 22:47 9560 c:\windows\system32\NetworkList\Icons\{0C6BE01A-79A9-43F4-8C72-B413F2635F65}_48.bin + 2011-04-16 22:47 . 2011-04-16 22:47 4280 c:\windows\system32\NetworkList\Icons\{0C6BE01A-79A9-43F4-8C72-B413F2635F65}_32.bin + 2011-04-16 22:47 . 2011-04-16 22:47 2456 c:\windows\system32\NetworkList\Icons\{0C6BE01A-79A9-43F4-8C72-B413F2635F65}_24.bin - 2011-04-14 01:22 . 2011-04-14 01:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2011-04-20 21:20 . 2011-04-20 21:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-04-14 01:22 . 2011-04-14 01:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-04-20 21:20 . 2011-04-20 21:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-03-25 02:29 . 2011-03-25 02:29 157472 c:\windows\SysWOW64\javaws.exe + 2011-04-15 02:15 . 2011-04-15 02:15 157472 c:\windows\SysWOW64\javaws.exe - 2011-03-25 02:29 . 2011-03-25 02:29 145184 c:\windows\SysWOW64\javaw.exe + 2011-04-15 02:15 . 2011-04-15 02:15 145184 c:\windows\SysWOW64\javaw.exe - 2011-03-25 02:29 . 2011-03-25 02:29 145184 c:\windows\SysWOW64\java.exe + 2011-04-15 02:15 . 2011-04-15 02:15 145184 c:\windows\SysWOW64\java.exe + 2011-03-22 01:48 . 2011-04-16 22:45 273062 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin + 2011-03-23 01:57 . 2011-04-17 00:33 269660 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2009-07-14 02:36 . 2011-04-14 00:36 624178 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-04-20 20:43 624178 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-04-20 20:43 106522 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2011-04-14 00:36 106522 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2011-04-14 01:17 403804 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2011-04-20 21:18 403804 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-04-20 21:18 . 2011-04-20 21:18 403804 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3339888093-537584527-826026314-1000-8192.dat + 2011-04-15 02:15 . 2011-04-15 02:15 183808 c:\windows\Installer\125a9f.msi + 2011-03-22 05:39 . 2011-04-15 01:53 1373544 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat - 2011-03-22 05:39 . 2011-04-14 01:17 1373544 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat + 2009-07-14 02:34 . 2011-04-20 21:03 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT - 2009-07-14 02:34 . 2011-04-14 00:44 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT + 2011-04-15 02:13 . 2011-04-15 02:13 12565504 c:\windows\Installer\125a99.msi . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-03-23 136176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696] "331BigDog"="c:\program files (x86)\USB Camera\VM331_STI.EXE" [2010-01-15 536576] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-12-03 35184] "VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2011-02-06 3122528] "UCam_Menu"="c:\program files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "YouCam Mirror Tray icon"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2010-03-02 171104] "UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408] "GIDDesktop"="c:\program files (x86)\SFT\GuardedID\gidd.exe" [2010-09-20 391944] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-03-07 421160] "ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2009-02-03 115560] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] . c:\users\The\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 227712] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2009-8-11 1080608] ID Vault.lnk - c:\program files (x86)\ID Vault\IDVault.exe [2010-12-4 2879816] Lenovo Smile Dock.lnk - c:\program files (x86)\DDNi\Lenovo Smile Dock\Delay.exe [2010-6-30 9728] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer5"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [x] R3 IGRS;IGRS;c:\program files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152] R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192] R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [x] S1 GIDv2;GIDv2; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336] S2 IDVaultSvc;IDVault Service;c:\program files (x86)\ID Vault\IDVaultSvc.exe [2010-12-04 42312] S2 Oasis2Service;Oasis2Service;c:\program files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe [2010-06-23 46080] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-12-09 2320920] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [x] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-06-17 132656] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys [x] S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg] 2010-09-20 17:15 432904 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe . Contents of the 'Scheduled Tasks' folder . 2011-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3339888093-537584527-826026314-1000Core.job - c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-23 02:03] . 2011-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3339888093-537584527-826026314-1000UA.job - c:\users\The\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-23 02:03] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc] @="{771C7324-DA80-49D3-8017-753B0AF60951}" [HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}] 2011-02-06 14:22 1502720 —-a-w- c:\windows\System32\IcnOvrly.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-05-07 16416360] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272] "ETDWare"="%ProgramFiles%\Elantech\ETDCtrl.exe" [BU] "OnekeyStudio"="c:\program files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe" [2009-12-19 776608] "EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\utility.exe" [2010-04-12 4462496] "Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2010-03-18 7056800] . ——- Supplementary Scan ——- . uStart Page = hxxp://lenovo.msn.com uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://lenovo.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Send image to &Bluetooth Device… - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm TCP: {007C9D54-1894-4DC7-8D9F-C4D8201BF272} = 10.1.24.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL FF - ProfilePath - c:\users\The\AppData\Roaming\Mozilla\Firefox\Profiles\atuefuve.default\ FF - user.js: general.useragent.extra.brc - . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) AddRemove-HotspotShield - c:\program files (x86)\Hotspot Shield\Uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Symantec Shared\ccSvcHst.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\program files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe c:\program files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe c:\program files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe c:\program files (x86)\DDNI\Lenovo Smile Dock\CenterStage.exe . ************************************************************************** . Completion time: 2011-04-20 14:24:49 - machine was rebooted ComboFix-quarantined-files.txt 2011-04-20 21:24 ComboFix2.txt 2011-04-15 02:00 ComboFix3.txt 2011-04-14 01:39 . Pre-Run: 414,982,324,224 bytes free Post-Run: 414,574,702,592 bytes free . - - End Of File - - AD505224E9903C73B40138AF4C7FBFC1
1) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

2) ESET
  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

3) What You Will Need To Post:
  • MBAM log
  • ESET log
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6420 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 4/22/2011 11:03:58 AM mbam-log-2011-04-22 (11-03-58).txt Scan type: Quick scan Objects scanned: 174250 Time elapsed: 2 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=6f4fff14e9657a4fbcc8d55ed54ddc80 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-04-22 06:57:36 # local_time=2011-04-22 11:57:36 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=5893 16776638 100 94 165557 55039303 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=108650 # found=2 # cleaned=0 # scan_time=2803 C:\Qoobox\Quarantine\C\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe.vir a variant of Win32/HotSpotShield application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\ProgramData\8a20288c-45f6-4e38-9aba-510671b53074.dat.vir a variant of Win32/TrojanDownloader.FakeAlert.BKA trojan (unable to clean) 00000000000000000000000000000000 I
Raktor is away for the weekend and asked if I'd assist


The items found by ESET are in quarantine which will be cleaned up shortly.

please do the following

Visit ADOBEand download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


Please post a fresh DDS Log and advise how the computer is running now and if there are any outstanding issues

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI