This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Start up really slow

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, I'm having some problems on start up. My laptop is pretty good but it takes a while to load and like freezes for like 45 seconds to 2 minute once loaded. Also i have had virus in the past, but i think there all gone, but i think option in my windows setting have been changed. Is there anything that you can help me with? Regards Philo350
Hi and Welcome!! :wavey: My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

**Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.**

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
Let's get going!! :thumbup:

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

aswMBR

Lets get a scan of your Master Boot Record shall we:
  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply

In your next reply please post the logs to:
  • DDS
  • GMER
  • aswMBR
. DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 15:37:09.06 on Thu 05/12/2011 Internet Explorer: 9.0.8112.16421 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4023.2221 [GMT 10:00] . AV: Internet Security Anti-Virus *Enabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Internet Security Anti-Spyware *Enabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} FW: Internet Security Firewall *Disabled* {175D0B73-9F8F-2CA9-8BF1-62277A276DC9} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Hpservice.exe C:\Windows\system32\vcsFPService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe C:\Windows\system32\HPSIsvc.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe C:\Program Files (x86)\PC Tools Security\pctsSvc.exe c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\PC Tools Security\pctsGui.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\Steam\steam.exe C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskeng.exe c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Philo\Downloads\dds.scr C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uSearch Bar = Preserve uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = ;*.local uInternet Settings,ProxyServer = http=127.0.0.1:33440 uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll mURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll mWinlogon: Userinit=userinit.exe BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll BHO: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf} - C:\Program Files (x86)\vShare\vshare_toolbar.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: {99079a25-328f-4bd4-be04-00955acaa0a7} - Searchqu Toolbar BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll TB: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf} - C:\Program Files (x86)\vShare\vshare_toolbar.dll TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun: [ISTray] "C:\Program Files (x86)\PC Tools Security\pctsGui.exe" /hideGUI mRun: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\Users\Philo\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll LSP: C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll Handler: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files (x86)\vShare\vshare_toolbar.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File TB-X64: {043C5167-00BB-4324-AF7E-62013FAEDACF} - No File TB-X64: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File mRun-x64: [EPSON Stylus Photo RX530 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIAGP.EXE /F "C:\Windows\TEMP\E_S39A5.tmp" /EF "HKLM" mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" . ============= SERVICES / DRIVERS =============== . R0 PCTCore;PCTools KDS;C:\Windows\System32\drivers\PCTCore64.sys [2011-4-8 282440] R0 pctDS;PC Tools Data Store;C:\Windows\System32\drivers\pctDS64.sys [2011-4-8 452872] R0 pctEFA;PC Tools Extended File Attributes;C:\Windows\System32\drivers\pctEFA64.sys [2011-4-8 816016] R0 TfFsMon;TfFsMon;C:\Windows\System32\drivers\TfFsMon.sys [2011-4-20 65072] R0 TFSysMon;TFSysMon;C:\Windows\System32\drivers\TfSysMon.sys [2011-4-20 74824] R1 pctgntdi;pctgntdi;C:\Windows\System32\drivers\pctgntdi64.sys [2011-4-8 334976] R1 PCTSD;PC Tools Spyware Doctor Driver;C:\Windows\System32\drivers\PCTSD64.sys [2011-4-20 279344] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904] R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2010/03/23 20:09:02];C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2010-3-23 146928] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-3-2 89600] R2 Browser Defender Update Service;Browser Defender Update Service;C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2011-4-8 337872] R2 HPSIService;HP SI Service;C:\Windows\System32\HPSIsvc.exe [2010-8-7 126520] R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2010-7-16 30520] R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [2011-2-26 632792] R2 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe [2011-4-8 371472] R2 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\PC Tools Security\pctsSvc.exe [2011-4-8 1117144] R2 TVCapSvc;TV Background Capture Service (TVBCS);C:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [2009-10-6 296360] R2 TVSched;TV Task Scheduler (TVTS);C:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe [2009-10-6 169376] R2 vcsFPService;Validity VCS Fingerprint Service;C:\Windows\System32\vcsFPService.exe [2009-7-12 1924400] R3 AVerBDA6x_x64;AVerMedia SAA716x BDA Service;C:\Windows\System32\drivers\AVerBDA716x_x64.sys [2010-3-23 1354880] R3 enecir;ENE CIR Receiver;C:\Windows\System32\drivers\enecir.sys [2009-6-28 70656] R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2009-10-12 151040] R3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys [2009-7-20 140712] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2010-11-9 131688] R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;C:\Windows\System32\drivers\pctNdis-PacketFilter64.sys [2011-4-8 119688] R3 pctNdisMP;PC Tools Driver;C:\Windows\System32\drivers\pctNdis64.sys [2011-4-8 77784] R3 pctplfw;pctplfw;C:\Windows\System32\drivers\pctplfw64.sys [2011-4-8 179976] R3 pctplsg;pctplsg;C:\Windows\System32\drivers\pctplsg64.sys [2011-4-8 92896] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-11-9 349800] R3 TfNetMon;TfNetMon;C:\Windows\System32\drivers\TfNetMon.sys [2011-4-20 41888] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-14 17920] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-18 136176] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-18 136176] S3 mvusbews;USB EWS Device;C:\Windows\System32\drivers\mvusbews.sys [2010-8-7 20480] S3 pctNdis;PC Tools Firewall Intermediate Filter Service;C:\Windows\System32\drivers\pctNdis64.sys [2011-4-8 77784] S3 ThreatFire;ThreatFire;C:\Program Files (x86)\PC Tools Security\TFEngine\TFService.exe service –> C:\Program Files (x86)\PC Tools Security\TFEngine\TFService.exe service [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-4-9 59392] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-2-18 51712] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-4-20 1255736] . =============== Created Last 30 ================ . 2011-05-11 12:16:20 ——– d—–w- C:\b3f2f2e5e462e660198e4855 2011-05-10 04:35:01 ——– d—–w- C:\Users\Philo\AppData\Local\{4B888CB4-A891-4FE1-8EA0-6D60269883F3} 2011-05-09 03:59:26 608448 —-a-w- C:\Windows\SysWow64\comctl32.ocx 2011-05-09 03:59:25 137000 —-a-w- C:\Windows\SysWow64\msmapi32.ocx 2011-05-09 03:59:11 ——– d—–w- C:\Program Files (x86)\MyHeritage 2011-05-09 02:57:49 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-05-08 11:30:12 ——– d—–w- C:\Program Files (x86)\Windows iLivid Toolbar 2011-05-08 11:30:01 ——– d—–w- C:\Users\Philo\AppData\Local\PackageAware 2011-05-05 10:20:45 ——– d—–w- C:\Program Files\iPod 2011-05-05 10:20:44 ——– d—–w- C:\Program Files\iTunes 2011-05-05 10:20:44 ——– d—–w- C:\Program Files (x86)\iTunes 2011-05-05 10:19:06 ——– d—–w- C:\Program Files\Bonjour 2011-05-05 10:19:06 ——– d—–w- C:\Program Files (x86)\Bonjour 2011-05-02 02:29:27 ——– d—–w- C:\Program Files\Common Files\Deterministic Networks 2011-05-02 02:29:22 ——– d—–w- C:\Windows\5FDC06BF3D3D43678FFB4FAFCB61972D.TMP 2011-05-02 02:29:05 ——– d—–w- C:\Users\Philo\AppData\Local\Apps 2011-04-30 02:56:52 ——– d—–w- C:\Program Files (x86)\Cisco Systems 2011-04-30 02:56:44 ——– d—–w- C:\Windows\1CE60928832549A88B06633E48DD2B67.TMP 2011-04-28 09:31:38 ——– d—–w- C:\ffec33b81594b7decdf097677beb597f 2011-04-27 22:41:59 31232 —-a-w- C:\Windows\SysWow64\prevhost.exe 2011-04-27 22:41:59 31232 —-a-w- C:\Windows\System32\prevhost.exe 2011-04-21 08:38:44 ——– d—–w- C:\Users\Philo\FrostWire 2011-04-20 05:41:59 74824 —-a-w- C:\Windows\System32\drivers\TfSysMon.sys 2011-04-20 05:41:59 65072 —-a-w- C:\Windows\System32\drivers\TfFsMon.sys 2011-04-20 05:41:59 41888 —-a-w- C:\Windows\System32\drivers\TfNetMon.sys 2011-04-20 05:41:59 279344 —-a-w- C:\Windows\System32\drivers\PCTSD64.sys 2011-04-15 04:40:09 ——– d—–w- C:\Users\Philo\AppData\Local\{DA0B0C59-B92F-4E95-9D33-B11A81A15041} 2011-04-14 13:48:02 ——– d—–w- C:\21aadcace741d7d16463 2011-04-14 05:10:02 ——– d—–w- C:\Program Files (x86)\Ventrilo 2011-04-14 05:09:33 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard . ==================== Find3M ==================== . 2011-04-12 00:44:42 149456 —-a-w- C:\Windows\SGDetectionTool.dll 2011-04-12 00:44:40 2074576 —-a-w- C:\Windows\PCTBDCore.dll 2011-04-12 00:44:40 1533904 —-a-w- C:\Windows\PCTBDRes.dll 2011-04-12 00:44:34 767952 —-a-w- C:\Windows\BDTSupport.dll 2011-04-09 06:30:05 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll 2011-04-09 06:30:04 175616 —-a-w- C:\Windows\System32\msclmd.dll 2011-04-06 06:26:58 96544 —-a-w- C:\Windows\System32\dnssd.dll 2011-04-06 06:26:58 119584 —-a-w- C:\Windows\System32\dns-sd.exe 2011-04-06 06:20:16 91424 —-a-w- C:\Windows\SysWow64\dnssd.dll 2011-04-06 06:20:16 107808 —-a-w- C:\Windows\SysWow64\dns-sd.exe 2011-04-05 03:43:14 446464 —-a-w- C:\Users\Philo\TFC.exe 2011-03-24 02:39:32 140800 —-a-w- C:\Windows\System32\drivers\pctwfpfilter64.sys 2011-03-12 12:08:49 1465344 —-a-w- C:\Windows\System32\XpsPrint.dll 2011-03-12 11:23:45 870912 —-a-w- C:\Windows\SysWow64\XpsPrint.dll 2011-03-11 06:41:37 189824 —-a-w- C:\Windows\System32\drivers\storport.sys 2011-03-11 06:41:34 166272 —-a-w- C:\Windows\System32\drivers\nvstor.sys 2011-03-11 06:41:34 1659776 —-a-w- C:\Windows\System32\drivers\ntfs.sys 2011-03-11 06:41:34 148352 —-a-w- C:\Windows\System32\drivers\nvraid.sys 2011-03-11 06:41:26 410496 —-a-w- C:\Windows\System32\drivers\iaStorV.sys 2011-03-11 06:41:12 27008 —-a-w- C:\Windows\System32\drivers\amdxata.sys 2011-03-11 06:41:12 107904 —-a-w- C:\Windows\System32\drivers\amdsata.sys 2011-03-11 06:34:51 1359872 —-a-w- C:\Windows\System32\mfc42u.dll 2011-03-11 06:34:50 1395712 —-a-w- C:\Windows\System32\mfc42.dll 2011-03-11 06:33:29 2565632 —-a-w- C:\Windows\System32\esent.dll 2011-03-11 06:30:28 96768 —-a-w- C:\Windows\System32\fsutil.exe 2011-03-11 05:33:59 1164288 —-a-w- C:\Windows\SysWow64\mfc42u.dll 2011-03-11 05:33:59 1137664 —-a-w- C:\Windows\SysWow64\mfc42.dll 2011-03-11 05:33:09 1699328 —-a-w- C:\Windows\SysWow64\esent.dll 2011-03-11 05:31:07 74240 —-a-w- C:\Windows\SysWow64\fsutil.exe 2011-03-10 00:07:24 282440 —-a-w- C:\Windows\System32\drivers\PCTCore64.sys 2011-03-08 06:29:32 976896 —-a-w- C:\Windows\System32\inetcomm.dll 2011-03-08 05:28:29 741376 —-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-03-04 06:19:28 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2011-03-04 06:19:27 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2011-03-04 04:57:26 77784 —-a-w- C:\Windows\System32\drivers\pctNdis64.sys 2011-03-03 06:24:16 183296 —-a-w- C:\Windows\System32\dnsrslvr.dll 2011-03-03 06:21:57 30208 —-a-w- C:\Windows\System32\dnscacheugc.exe 2011-03-03 05:36:16 28672 —-a-w- C:\Windows\SysWow64\dnscacheugc.exe 2011-03-03 03:52:08 3135488 —-a-w- C:\Windows\System32\win32k.sys 2011-02-25 06:19:30 2871808 —-a-w- C:\Windows\explorer.exe 2011-02-25 05:30:54 2616320 —-a-w- C:\Windows\SysWow64\explorer.exe 2011-02-24 06:15:44 476160 —-a-w- C:\Windows\System32\XpsGdiConverter.dll 2011-02-24 05:38:54 288256 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2011-02-23 04:56:31 158208 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-02-23 04:56:27 467456 —-a-w- C:\Windows\System32\drivers\srv.sys 2011-02-23 04:56:03 411648 —-a-w- C:\Windows\System32\drivers\srv2.sys 2011-02-23 04:55:47 167936 —-a-w- C:\Windows\System32\drivers\srvnet.sys 2011-02-23 04:55:12 287744 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-02-23 04:55:12 128000 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-02-23 04:55:04 90624 —-a-w- C:\Windows\System32\drivers\bowser.sys 2011-02-19 12:05:15 1139200 —-a-w- C:\Windows\System32\FntCache.dll 2011-02-19 12:04:37 1544192 —-a-w- C:\Windows\System32\DWrite.dll 2011-02-19 12:04:17 902656 —-a-w- C:\Windows\System32\d2d1.dll 2011-02-19 12:03:46 46080 —-a-w- C:\Windows\System32\atmlib.dll 2011-02-19 09:00:32 367616 —-a-w- C:\Windows\System32\atmfd.dll 2011-02-19 06:30:51 1076736 —-a-w- C:\Windows\SysWow64\DWrite.dll 2011-02-19 06:30:50 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll 2011-02-19 06:30:46 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2011-02-19 04:34:54 294912 —-a-w- C:\Windows\SysWow64\atmfd.dll 2011-02-18 06:36:58 51712 —-a-w- C:\Windows\System32\drivers\usbaapl64.sys 2011-02-18 06:36:58 4184352 —-a-w- C:\Windows\System32\usbaaplrc.dll 2011-02-12 11:34:16 267776 —-a-w- C:\Windows\System32\FXSCOVER.exe 2010-05-18 01:17:03 562848 —-a-w- C:\Program Files\GoogleEarthSetup.exe . ============= FINISH: 15:39:39.76 ===============

Attachments:

aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-12 15:47:46 —————————– 15:47:46.635 OS Version: Windows x64 6.1.7601 Service Pack 1 15:47:46.636 Number of processors: 4 586 0x2502 15:47:46.636 ComputerName: PHILO-HP UserName: Philo 15:48:00.293 Initialize success 15:48:10.329 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 15:48:10.331 Disk 0 Vendor: SAMSUNG_ 2AJ1 Size: 610480MB BusType: 3 15:48:10.361 Disk 0 MBR read successfully 15:48:10.363 Disk 0 MBR scan 15:48:10.366 Disk 0 Windows 7 default MBR code 15:48:10.369 Service scanning 15:48:12.147 Disk 0 trace - called modules: 15:48:12.172 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys PCTCore64.sys iaStor.sys hal.dll 15:48:12.176 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005832790] 15:48:12.179 3 CLASSPNP.SYS[fffff88001a0143f] -> nt!IofCallDriver -> [0xfffffa80056dcb10] 15:48:12.182 5 hpdskflt.sys[fffff88001d842bd] -> nt!IofCallDriver -> [0xfffffa80056dacf0] 15:48:12.186 7 PCTCore64.sys[fffff880012f1894] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004a26050] 15:48:12.189 Scan finished successfully 15:48:55.302 Disk 0 MBR has been saved successfully to "C:\Users\Philo\Desktop\Fixing\MBR.dat" 15:48:55.307 The log file has been saved successfully to "C:\Users\Philo\Desktop\Fixing\aswMBR.txt"

Attachments:

Hi Philo350.

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.

In your next reply please post the log created by ComboFix. :thumbup:
ComboFix 11-05-13.02 - Philo 05/14/2011 12:22:14.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4023.2232 [GMT 10:00] Running from: c:\users\[removed]\Desktop\Fixing\ComboFix.exe AV: Internet Security Anti-Virus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} FW: Internet Security Firewall *Disabled* {175D0B73-9F8F-2CA9-8BF1-62277A276DC9} SP: Internet Security Anti-Spyware *Disabled/Outdated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Philo\AppData\Local\TempDIR c:\users\Philo\AppData\Roaming\SystemProc c:\users\Philo\TFC.exe c:\users\Philo\vshare-plugin.exe c:\windows\jestertb.dll . . ((((((((((((((((((((((((( Files Created from 2011-04-14 to 2011-05-14 ))))))))))))))))))))))))))))))) . . 2011-05-14 02:29 . 2011-05-14 02:29 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-05-12 06:21 . 2011-04-09 06:58 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-05-12 06:21 . 2011-04-09 05:56 123904 —-a-w- c:\windows\SysWow64\poqexec.exe 2011-05-11 12:16 . 2011-05-11 15:25 ——– d—–w- C:\b3f2f2e5e462e660198e4855 2011-05-11 05:27 . 2011-04-09 07:02 5562240 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-05-11 05:27 . 2011-04-09 06:02 3967872 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-05-11 05:27 . 2011-04-09 06:02 3912576 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-05-11 05:27 . 2011-03-25 03:29 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-11 05:27 . 2011-03-25 03:29 98816 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-11 05:27 . 2011-03-25 03:29 325120 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-05-11 05:27 . 2011-03-25 03:29 52736 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-11 05:27 . 2011-03-25 03:29 25600 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-05-11 05:27 . 2011-03-25 03:29 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-11 05:27 . 2011-03-25 03:28 7936 —-a-w- c:\windows\system32\drivers\usbd.sys 2011-05-10 04:35 . 2011-05-10 04:35 ——– d—–w- c:\users\Philo\AppData\Local\{4B888CB4-A891-4FE1-8EA0-6D60269883F3} 2011-05-09 03:59 . 2000-05-22 06:58 608448 —-a-w- c:\windows\SysWow64\comctl32.ocx 2011-05-09 03:59 . 1998-06-23 14:00 137000 —-a-w- c:\windows\SysWow64\msmapi32.ocx 2011-05-09 03:59 . 2011-05-09 05:38 ——– d—–w- c:\program files (x86)\MyHeritage 2011-05-09 02:57 . 2011-05-09 02:57 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-05-09 02:57 . 2011-04-13 19:07 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-05-08 11:30 . 2011-05-08 11:30 ——– d—–w- c:\program files (x86)\Windows iLivid Toolbar 2011-05-08 11:30 . 2011-05-08 11:30 ——– d—–w- c:\users\Philo\AppData\Local\PackageAware 2011-05-05 10:20 . 2011-05-05 10:20 ——– d—–w- c:\program files\iPod 2011-05-05 10:20 . 2011-05-05 10:21 ——– d—–w- c:\program files\iTunes 2011-05-05 10:20 . 2011-05-05 10:21 ——– d—–w- c:\program files (x86)\iTunes 2011-05-05 10:19 . 2011-05-05 10:19 ——– d—–w- c:\program files\Bonjour 2011-05-05 10:19 . 2011-05-05 10:19 ——– d—–w- c:\program files (x86)\Bonjour 2011-05-02 02:29 . 2011-05-02 02:29 ——– d—–w- c:\program files\Common Files\Deterministic Networks 2011-05-02 02:29 . 2011-05-02 02:29 ——– d—–w- c:\windows\5FDC06BF3D3D43678FFB4FAFCB61972D.TMP 2011-05-02 02:29 . 2011-05-02 02:29 ——– d—–w- c:\users\Philo\AppData\Local\Apps 2011-04-30 02:56 . 2011-04-30 02:56 ——– d—–w- c:\program files (x86)\Cisco Systems 2011-04-30 02:56 . 2011-05-02 02:07 ——– d—–w- c:\windows\1CE60928832549A88B06633E48DD2B67.TMP 2011-04-28 09:31 . 2011-04-28 09:33 ——– d—–w- C:\ffec33b81594b7decdf097677beb597f 2011-04-27 22:41 . 2011-02-18 10:51 31232 —-a-w- c:\windows\system32\prevhost.exe 2011-04-27 22:41 . 2011-02-18 05:39 31232 —-a-w- c:\windows\SysWow64\prevhost.exe 2011-04-21 08:38 . 2011-04-21 08:38 ——– d—–w- c:\users\Philo\FrostWire 2011-04-20 05:41 . 2011-03-09 23:08 279344 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2011-04-20 05:41 . 2011-01-20 03:27 74824 —-a-w- c:\windows\system32\drivers\TfSysMon.sys 2011-04-20 05:41 . 2011-01-20 03:27 65072 —-a-w- c:\windows\system32\drivers\TfFsMon.sys 2011-04-20 05:41 . 2011-01-20 03:27 41888 —-a-w- c:\windows\system32\drivers\TfNetMon.sys 2011-04-15 04:40 . 2011-04-15 04:40 ——– d—–w- c:\users\Philo\AppData\Local\{DA0B0C59-B92F-4E95-9D33-B11A81A15041} 2011-04-15 02:03 . 2011-04-15 02:03 ——– d—–w- c:\program files (x86)\Common Files\Adobe 2011-04-14 13:48 . 2011-04-14 13:49 ——– d—–w- C:\21aadcace741d7d16463 2011-04-14 05:10 . 2011-04-14 05:12 ——– d—–w- c:\users\Philo\AppData\Roaming\Ventrilo 2011-04-14 05:10 . 2011-04-14 05:10 ——– d—–w- c:\program files (x86)\Ventrilo 2011-04-14 05:09 . 2011-04-14 05:09 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-12 00:44 . 2011-04-08 04:36 149456 —-a-w- c:\windows\SGDetectionTool.dll 2011-04-12 00:44 . 2011-04-08 04:36 2074576 —-a-w- c:\windows\PCTBDCore.dll 2011-04-12 00:44 . 2011-04-08 04:36 1533904 —-a-w- c:\windows\PCTBDRes.dll 2011-04-12 00:44 . 2011-04-08 04:36 767952 —-a-w- c:\windows\BDTSupport.dll 2011-04-09 06:30 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll 2011-04-09 06:30 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll 2011-04-09 06:19 . 2011-04-09 06:19 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-04-09 06:19 . 2011-04-09 06:19 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-04-09 06:19 . 2011-04-09 06:19 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2011-04-09 06:19 . 2011-04-09 06:19 85504 —-a-w- c:\windows\system32\iesetup.dll 2011-04-09 06:19 . 2011-04-09 06:19 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2011-04-09 06:19 . 2011-04-09 06:19 76800 —-a-w- c:\windows\system32\tdc.ocx 2011-04-09 06:19 . 2011-04-09 06:19 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2011-04-09 06:19 . 2011-04-09 06:19 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2011-04-09 06:19 . 2011-04-09 06:19 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2011-04-09 06:19 . 2011-04-09 06:19 603648 —-a-w- c:\windows\system32\vbscript.dll 2011-04-09 06:19 . 2011-04-09 06:19 49664 —-a-w- c:\windows\system32\imgutil.dll 2011-04-09 06:19 . 2011-04-09 06:19 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2011-04-09 06:19 . 2011-04-09 06:19 48640 —-a-w- c:\windows\system32\mshtmler.dll 2011-04-09 06:19 . 2011-04-09 06:19 448512 —-a-w- c:\windows\system32\html.iec 2011-04-09 06:19 . 2011-04-09 06:19 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2011-04-09 06:19 . 2011-04-09 06:19 367104 —-a-w- c:\windows\SysWow64\html.iec 2011-04-09 06:19 . 2011-04-09 06:19 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2011-04-09 06:19 . 2011-04-09 06:19 30720 —-a-w- c:\windows\system32\licmgr10.dll 2011-04-09 06:19 . 2011-04-09 06:19 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-04-09 06:19 . 2011-04-09 06:19 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-04-09 06:19 . 2011-04-09 06:19 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2011-04-09 06:19 . 2011-04-09 06:19 2303488 —-a-w- c:\windows\system32\jscript9.dll 2011-04-09 06:19 . 2011-04-09 06:19 222208 —-a-w- c:\windows\system32\msls31.dll 2011-04-09 06:19 . 2011-04-09 06:19 1797632 —-a-w- c:\windows\SysWow64\jscript9.dll 2011-04-09 06:19 . 2011-04-09 06:19 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2011-04-09 06:19 . 2011-04-09 06:19 165888 —-a-w- c:\windows\system32\iexpress.exe 2011-04-09 06:19 . 2011-04-09 06:19 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2011-04-09 06:19 . 2011-04-09 06:19 160256 —-a-w- c:\windows\system32\wextract.exe 2011-04-09 06:19 . 2011-04-09 06:19 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2011-04-09 06:19 . 2011-04-09 06:19 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2011-04-09 06:19 . 2011-04-09 06:19 1492992 —-a-w- c:\windows\system32\inetcpl.cpl 2011-04-09 06:19 . 2011-04-09 06:19 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2011-04-09 06:19 . 2011-04-09 06:19 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2011-04-09 06:19 . 2011-04-09 06:19 1389056 —-a-w- c:\windows\system32\wininet.dll 2011-04-09 06:19 . 2011-04-09 06:19 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2011-04-09 06:19 . 2011-04-09 06:19 12288 —-a-w- c:\windows\system32\mshta.exe 2011-04-09 06:19 . 2011-04-09 06:19 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2011-04-09 06:19 . 2011-04-09 06:19 114176 —-a-w- c:\windows\system32\admparse.dll 2011-04-09 06:19 . 2011-04-09 06:19 1126912 —-a-w- c:\windows\SysWow64\wininet.dll 2011-04-09 06:19 . 2011-04-09 06:19 111616 —-a-w- c:\windows\system32\iesysprep.dll 2011-04-09 06:19 . 2011-04-09 06:19 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2011-04-09 06:19 . 2011-04-09 06:19 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2011-04-06 06:26 . 2011-04-06 06:26 96544 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 06:26 . 2011-04-06 06:26 119584 —-a-w- c:\windows\system32\dns-sd.exe 2011-04-06 06:20 . 2011-04-06 06:20 91424 —-a-w- c:\windows\SysWow64\dnssd.dll 2011-04-06 06:20 . 2011-04-06 06:20 107808 —-a-w- c:\windows\SysWow64\dns-sd.exe 2011-03-24 02:39 . 2011-04-08 04:33 140800 —-a-w- c:\windows\system32\drivers\pctwfpfilter64.sys 2011-03-11 06:34 . 2011-04-14 01:49 1359872 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-11 06:34 . 2011-04-14 01:49 1395712 —-a-w- c:\windows\system32\mfc42.dll 2011-03-11 05:33 . 2011-04-14 01:49 1137664 —-a-w- c:\windows\SysWow64\mfc42.dll 2011-03-11 05:33 . 2011-04-14 01:49 1164288 —-a-w- c:\windows\SysWow64\mfc42u.dll 2011-03-10 22:28 . 2010-06-24 01:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-03-10 00:07 . 2011-04-08 04:33 282440 —-a-w- c:\windows\system32\drivers\PCTCore64.sys 2011-03-08 06:29 . 2011-04-14 01:49 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-08 05:28 . 2011-04-14 01:49 741376 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-03-04 06:19 . 2011-04-27 22:42 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2011-03-04 06:19 . 2011-04-27 22:42 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2011-03-04 04:57 . 2011-04-08 04:33 77784 —-a-w- c:\windows\system32\drivers\pctNdis64.sys 2011-03-03 06:24 . 2011-04-14 01:49 183296 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-03-03 06:21 . 2011-04-14 01:49 30208 —-a-w- c:\windows\system32\dnscacheugc.exe 2011-03-03 05:36 . 2011-04-14 01:49 28672 —-a-w- c:\windows\SysWow64\dnscacheugc.exe 2011-03-03 03:52 . 2011-04-14 01:49 3135488 —-a-w- c:\windows\system32\win32k.sys 2011-02-24 06:15 . 2011-04-14 01:49 476160 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-02-24 05:38 . 2011-04-14 01:49 288256 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2011-02-23 15:04 . 2011-01-11 13:41 238968 —-a-w- c:\windows\system32\aswBoot.exe 2011-02-23 04:56 . 2011-04-14 01:49 158208 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-23 04:56 . 2011-04-14 01:49 467456 —-a-w- c:\windows\system32\drivers\srv.sys 2011-02-23 04:56 . 2011-04-14 01:49 411648 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-02-23 04:55 . 2011-04-14 01:49 167936 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-02-23 04:55 . 2011-04-14 01:49 287744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-02-23 04:55 . 2011-04-14 01:49 128000 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-02-23 04:55 . 2011-04-14 01:49 90624 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-02-19 12:05 . 2011-03-09 06:37 1139200 —-a-w- c:\windows\system32\FntCache.dll 2011-02-19 12:04 . 2011-03-09 06:37 1544192 —-a-w- c:\windows\system32\DWrite.dll 2011-02-19 12:04 . 2011-03-09 06:37 902656 —-a-w- c:\windows\system32\d2d1.dll 2011-02-19 12:03 . 2011-04-14 01:49 46080 —-a-w- c:\windows\system32\atmlib.dll 2011-02-19 09:00 . 2011-04-14 01:49 367616 —-a-w- c:\windows\system32\atmfd.dll 2011-02-19 06:30 . 2011-03-09 06:37 1076736 —-a-w- c:\windows\SysWow64\DWrite.dll 2011-02-19 06:30 . 2011-03-09 06:37 739840 —-a-w- c:\windows\SysWow64\d2d1.dll 2011-02-19 06:30 . 2011-04-14 01:49 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2011-02-19 04:34 . 2011-04-14 01:49 294912 —-a-w- c:\windows\SysWow64\atmfd.dll 2011-02-18 06:36 . 2011-02-18 06:36 51712 —-a-w- c:\windows\system32\drivers\usbaapl64.sys 2011-02-18 06:36 . 2011-02-18 06:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll 2010-05-18 01:17 . 2010-05-18 01:16 562848 —-a-w- c:\program files\GoogleEarthSetup.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "Steam"="c:\program files (x86)\Steam\steam.exe" [2010-11-16 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "SSDMonitor"="c:\program files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2010-11-15 112600] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "PCTools FGuard"="c:\program files (x86)\PC Tools Security\BDT\FGuard.exe" [2011-01-07 108496] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-26 421160] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] . c:\users\Philo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-18 136176] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-18 136176] R3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\DRIVERS\pctNdis64.sys [x] R3 pctplfw;pctplfw;c:\windows\System32\drivers\pctplfw64.sys [x] R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [x] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2011-02-18 371472] R3 ThreatFire;ThreatFire;c:\program files (x86)\PC Tools Security\TFEngine\TFService.exe service [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [x] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x] S0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [x] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys [x] S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2010/03/23 20:09];c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2009-09-09 06:38 146928] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-03-02 89600] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2011-04-12 337872] S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [x] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x] S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [2010-10-01 632792] S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [2009-10-06 296360] S2 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe [2009-10-06 169376] S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-07-12 1924400] S3 AVerBDA6x_x64;AVerMedia SAA716x BDA Service;c:\windows\system32\DRIVERS\AVerBDA716x_x64.sys [x] S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x] S3 mvusbews;USB EWS Device;c:\windows\system32\Drivers\mvusbews.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter64.sys [x] S3 pctNdisMP;PC Tools Driver;c:\windows\system32\DRIVERS\pctNdis64.sys [x] S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *Deregistered* - PCTSDInjDriver64 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-10-16 02:49 451872 —-a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2011-05-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-18 01:17] . 2011-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-18 01:17] . 2011-04-23 c:\windows\Tasks\HPCeeScheduleForPhilo.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-06 18:22] . 2011-05-11 c:\windows\Tasks\RMSchedule.job - c:\program files (x86)\Registry Mechanic\RegMech.exe [2011-02-25 07:05] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EPSON Stylus Photo RX530 Series"="c:\windows\system32\spool\DRIVERS\x64\3\E_FATIAGP.EXE" [2005-04-06 98304] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-01-07 2328944] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\system32\blank.htm uInternet Settings,ProxyOverride = ;*.local uInternet Settings,ProxyServer = http=127.0.0.1:33440 LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{55662437-DA8C-40c0-AADA-2C816A897A49}] "ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_10_2_161_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_10_2_161_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-05-14 12:31:28 ComboFix-quarantined-files.txt 2011-05-14 02:31 . Pre-Run: 483,054,161,920 bytes free Post-Run: 482,975,903,744 bytes free . - - End Of File - - FDBAE757AA71CBD9238B42705B05CA05
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DDS::
uInternet Settings,ProxyOverride = ;*.local
uInternet Settings,ProxyServer = http=127.0.0.1:33440

Folder::
c:\users\Philo\FrostWire


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
ComboFix 11-05-14.01 - Philo 05/15/2011 22:29:00.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4023.2417 [GMT 10:00] Running from: c:\users\[removed]\Desktop\Fixing\ComboFix.exe Command switches used :: c:\users\Philo\Desktop\Fixing\CFScript.txt AV: Internet Security Anti-Virus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} FW: Internet Security Firewall *Disabled* {175D0B73-9F8F-2CA9-8BF1-62277A276DC9} SP: Internet Security Anti-Spyware *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Philo\FrostWire c:\users\Philo\FrostWire\Saved\frostwire-4.21.2.windows.exe.torrent c:\users\Philo\FrostWire\Saved\frostwire-4.21.3.windows.exe.torrent . . ((((((((((((((((((((((((( Files Created from 2011-04-15 to 2011-05-15 ))))))))))))))))))))))))))))))) . . 2011-05-15 12:39 . 2011-05-15 12:39 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-05-12 06:21 . 2011-04-09 06:58 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-05-12 06:21 . 2011-04-09 05:56 123904 —-a-w- c:\windows\SysWow64\poqexec.exe 2011-05-11 12:16 . 2011-05-11 15:25 ——– d—–w- C:\b3f2f2e5e462e660198e4855 2011-05-11 05:27 . 2011-04-09 07:02 5562240 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-05-11 05:27 . 2011-04-09 06:02 3967872 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-05-11 05:27 . 2011-04-09 06:02 3912576 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-05-11 05:27 . 2011-03-25 03:29 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-11 05:27 . 2011-03-25 03:29 98816 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-11 05:27 . 2011-03-25 03:29 325120 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-05-11 05:27 . 2011-03-25 03:29 52736 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-11 05:27 . 2011-03-25 03:29 25600 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-05-11 05:27 . 2011-03-25 03:29 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-11 05:27 . 2011-03-25 03:28 7936 —-a-w- c:\windows\system32\drivers\usbd.sys 2011-05-10 04:35 . 2011-05-10 04:35 ——– d—–w- c:\users\Philo\AppData\Local\{4B888CB4-A891-4FE1-8EA0-6D60269883F3} 2011-05-09 03:59 . 2000-05-22 06:58 608448 —-a-w- c:\windows\SysWow64\comctl32.ocx 2011-05-09 03:59 . 1998-06-23 14:00 137000 —-a-w- c:\windows\SysWow64\msmapi32.ocx 2011-05-09 03:59 . 2011-05-09 05:38 ——– d—–w- c:\program files (x86)\MyHeritage 2011-05-09 02:57 . 2011-05-09 02:57 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-05-09 02:57 . 2011-04-13 19:07 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-05-08 11:30 . 2011-05-08 11:30 ——– d—–w- c:\program files (x86)\Windows iLivid Toolbar 2011-05-08 11:30 . 2011-05-08 11:30 ——– d—–w- c:\users\Philo\AppData\Local\PackageAware 2011-05-05 10:20 . 2011-05-05 10:20 ——– d—–w- c:\program files\iPod 2011-05-05 10:20 . 2011-05-05 10:21 ——– d—–w- c:\program files\iTunes 2011-05-05 10:20 . 2011-05-05 10:21 ——– d—–w- c:\program files (x86)\iTunes 2011-05-05 10:19 . 2011-05-05 10:19 ——– d—–w- c:\program files\Bonjour 2011-05-05 10:19 . 2011-05-05 10:19 ——– d—–w- c:\program files (x86)\Bonjour 2011-05-02 02:29 . 2011-05-02 02:29 ——– d—–w- c:\program files\Common Files\Deterministic Networks 2011-05-02 02:29 . 2011-05-02 02:29 ——– d—–w- c:\windows\5FDC06BF3D3D43678FFB4FAFCB61972D.TMP 2011-05-02 02:29 . 2011-05-02 02:29 ——– d—–w- c:\users\Philo\AppData\Local\Apps 2011-04-30 02:56 . 2011-04-30 02:56 ——– d—–w- c:\program files (x86)\Cisco Systems 2011-04-30 02:56 . 2011-05-02 02:07 ——– d—–w- c:\windows\1CE60928832549A88B06633E48DD2B67.TMP 2011-04-28 09:31 . 2011-04-28 09:33 ——– d—–w- C:\ffec33b81594b7decdf097677beb597f 2011-04-27 22:41 . 2011-02-18 10:51 31232 —-a-w- c:\windows\system32\prevhost.exe 2011-04-27 22:41 . 2011-02-18 05:39 31232 —-a-w- c:\windows\SysWow64\prevhost.exe 2011-04-20 05:41 . 2011-03-09 23:08 279344 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2011-04-20 05:41 . 2011-01-20 03:27 74824 —-a-w- c:\windows\system32\drivers\TfSysMon.sys 2011-04-20 05:41 . 2011-01-20 03:27 65072 —-a-w- c:\windows\system32\drivers\TfFsMon.sys 2011-04-20 05:41 . 2011-01-20 03:27 41888 —-a-w- c:\windows\system32\drivers\TfNetMon.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-12 00:44 . 2011-04-08 04:36 149456 —-a-w- c:\windows\SGDetectionTool.dll 2011-04-12 00:44 . 2011-04-08 04:36 2074576 —-a-w- c:\windows\PCTBDCore.dll 2011-04-12 00:44 . 2011-04-08 04:36 1533904 —-a-w- c:\windows\PCTBDRes.dll 2011-04-12 00:44 . 2011-04-08 04:36 767952 —-a-w- c:\windows\BDTSupport.dll 2011-04-09 06:30 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll 2011-04-09 06:30 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll 2011-04-09 06:19 . 2011-04-09 06:19 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-04-09 06:19 . 2011-04-09 06:19 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-04-09 06:19 . 2011-04-09 06:19 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2011-04-09 06:19 . 2011-04-09 06:19 85504 —-a-w- c:\windows\system32\iesetup.dll 2011-04-09 06:19 . 2011-04-09 06:19 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2011-04-09 06:19 . 2011-04-09 06:19 76800 —-a-w- c:\windows\system32\tdc.ocx 2011-04-09 06:19 . 2011-04-09 06:19 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2011-04-09 06:19 . 2011-04-09 06:19 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2011-04-09 06:19 . 2011-04-09 06:19 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2011-04-09 06:19 . 2011-04-09 06:19 603648 —-a-w- c:\windows\system32\vbscript.dll 2011-04-09 06:19 . 2011-04-09 06:19 49664 —-a-w- c:\windows\system32\imgutil.dll 2011-04-09 06:19 . 2011-04-09 06:19 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2011-04-09 06:19 . 2011-04-09 06:19 48640 —-a-w- c:\windows\system32\mshtmler.dll 2011-04-09 06:19 . 2011-04-09 06:19 448512 —-a-w- c:\windows\system32\html.iec 2011-04-09 06:19 . 2011-04-09 06:19 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2011-04-09 06:19 . 2011-04-09 06:19 367104 —-a-w- c:\windows\SysWow64\html.iec 2011-04-09 06:19 . 2011-04-09 06:19 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2011-04-09 06:19 . 2011-04-09 06:19 30720 —-a-w- c:\windows\system32\licmgr10.dll 2011-04-09 06:19 . 2011-04-09 06:19 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-04-09 06:19 . 2011-04-09 06:19 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-04-09 06:19 . 2011-04-09 06:19 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2011-04-09 06:19 . 2011-04-09 06:19 2303488 —-a-w- c:\windows\system32\jscript9.dll 2011-04-09 06:19 . 2011-04-09 06:19 222208 —-a-w- c:\windows\system32\msls31.dll 2011-04-09 06:19 . 2011-04-09 06:19 1797632 —-a-w- c:\windows\SysWow64\jscript9.dll 2011-04-09 06:19 . 2011-04-09 06:19 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2011-04-09 06:19 . 2011-04-09 06:19 165888 —-a-w- c:\windows\system32\iexpress.exe 2011-04-09 06:19 . 2011-04-09 06:19 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2011-04-09 06:19 . 2011-04-09 06:19 160256 —-a-w- c:\windows\system32\wextract.exe 2011-04-09 06:19 . 2011-04-09 06:19 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2011-04-09 06:19 . 2011-04-09 06:19 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2011-04-09 06:19 . 2011-04-09 06:19 1492992 —-a-w- c:\windows\system32\inetcpl.cpl 2011-04-09 06:19 . 2011-04-09 06:19 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2011-04-09 06:19 . 2011-04-09 06:19 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2011-04-09 06:19 . 2011-04-09 06:19 1389056 —-a-w- c:\windows\system32\wininet.dll 2011-04-09 06:19 . 2011-04-09 06:19 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2011-04-09 06:19 . 2011-04-09 06:19 12288 —-a-w- c:\windows\system32\mshta.exe 2011-04-09 06:19 . 2011-04-09 06:19 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2011-04-09 06:19 . 2011-04-09 06:19 114176 —-a-w- c:\windows\system32\admparse.dll 2011-04-09 06:19 . 2011-04-09 06:19 1126912 —-a-w- c:\windows\SysWow64\wininet.dll 2011-04-09 06:19 . 2011-04-09 06:19 111616 —-a-w- c:\windows\system32\iesysprep.dll 2011-04-09 06:19 . 2011-04-09 06:19 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2011-04-09 06:19 . 2011-04-09 06:19 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2011-04-06 06:26 . 2011-04-06 06:26 96544 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 06:26 . 2011-04-06 06:26 119584 —-a-w- c:\windows\system32\dns-sd.exe 2011-04-06 06:20 . 2011-04-06 06:20 91424 —-a-w- c:\windows\SysWow64\dnssd.dll 2011-04-06 06:20 . 2011-04-06 06:20 107808 —-a-w- c:\windows\SysWow64\dns-sd.exe 2011-03-24 02:39 . 2011-04-08 04:33 140800 —-a-w- c:\windows\system32\drivers\pctwfpfilter64.sys 2011-03-11 06:34 . 2011-04-14 01:49 1359872 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-11 06:34 . 2011-04-14 01:49 1395712 —-a-w- c:\windows\system32\mfc42.dll 2011-03-11 05:33 . 2011-04-14 01:49 1137664 —-a-w- c:\windows\SysWow64\mfc42.dll 2011-03-11 05:33 . 2011-04-14 01:49 1164288 —-a-w- c:\windows\SysWow64\mfc42u.dll 2011-03-10 22:28 . 2010-06-24 01:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-03-10 00:07 . 2011-04-08 04:33 282440 —-a-w- c:\windows\system32\drivers\PCTCore64.sys 2011-03-08 06:29 . 2011-04-14 01:49 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-08 05:28 . 2011-04-14 01:49 741376 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-03-04 06:19 . 2011-04-27 22:42 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2011-03-04 06:19 . 2011-04-27 22:42 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2011-03-04 04:57 . 2011-04-08 04:33 77784 —-a-w- c:\windows\system32\drivers\pctNdis64.sys 2011-03-03 06:24 . 2011-04-14 01:49 183296 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-03-03 06:21 . 2011-04-14 01:49 30208 —-a-w- c:\windows\system32\dnscacheugc.exe 2011-03-03 05:36 . 2011-04-14 01:49 28672 —-a-w- c:\windows\SysWow64\dnscacheugc.exe 2011-03-03 03:52 . 2011-04-14 01:49 3135488 —-a-w- c:\windows\system32\win32k.sys 2011-02-24 06:15 . 2011-04-14 01:49 476160 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-02-24 05:38 . 2011-04-14 01:49 288256 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2011-02-23 15:04 . 2011-01-11 13:41 238968 —-a-w- c:\windows\system32\aswBoot.exe 2011-02-23 04:56 . 2011-04-14 01:49 158208 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-23 04:56 . 2011-04-14 01:49 467456 —-a-w- c:\windows\system32\drivers\srv.sys 2011-02-23 04:56 . 2011-04-14 01:49 411648 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-02-23 04:55 . 2011-04-14 01:49 167936 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-02-23 04:55 . 2011-04-14 01:49 287744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-02-23 04:55 . 2011-04-14 01:49 128000 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-02-23 04:55 . 2011-04-14 01:49 90624 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-02-19 12:05 . 2011-03-09 06:37 1139200 —-a-w- c:\windows\system32\FntCache.dll 2011-02-19 12:04 . 2011-03-09 06:37 1544192 —-a-w- c:\windows\system32\DWrite.dll 2011-02-19 12:04 . 2011-03-09 06:37 902656 —-a-w- c:\windows\system32\d2d1.dll 2011-02-19 12:03 . 2011-04-14 01:49 46080 —-a-w- c:\windows\system32\atmlib.dll 2011-02-19 09:00 . 2011-04-14 01:49 367616 —-a-w- c:\windows\system32\atmfd.dll 2011-02-19 06:30 . 2011-03-09 06:37 1076736 —-a-w- c:\windows\SysWow64\DWrite.dll 2011-02-19 06:30 . 2011-03-09 06:37 739840 —-a-w- c:\windows\SysWow64\d2d1.dll 2011-02-19 06:30 . 2011-04-14 01:49 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2011-02-19 04:34 . 2011-04-14 01:49 294912 —-a-w- c:\windows\SysWow64\atmfd.dll 2011-02-18 06:36 . 2011-02-18 06:36 51712 —-a-w- c:\windows\system32\drivers\usbaapl64.sys 2011-02-18 06:36 . 2011-02-18 06:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll 2010-05-18 01:17 . 2010-05-18 01:16 562848 —-a-w- c:\program files\GoogleEarthSetup.exe . . ((((((((((((((((((((((((((((( SnapShot@2011-05-14_02.29.35 ))))))))))))))))))))))))))))))))))))))))) . - 2009-07-14 04:54 . 2011-05-14 00:13 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2011-05-15 12:29 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2011-05-15 12:29 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-05-14 00:13 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-05-14 00:13 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-05-15 12:29 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-03-23 02:52 . 2011-05-15 08:30 60312 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-05-15 08:29 38640 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-03-23 01:07 . 2011-05-15 08:29 17542 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3584129800-2309573062-3716894374-1000_UserData.bin - 2010-03-23 17:29 . 2011-05-11 04:44 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-03-23 17:29 . 2011-05-15 11:17 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-03-23 17:29 . 2011-05-15 11:17 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2010-03-23 17:29 . 2011-05-11 04:44 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-05-11 04:44 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-05-15 11:17 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-05-15 08:26 . 2011-05-15 08:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-05-13 23:39 . 2011-05-13 23:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-05-13 23:39 . 2011-05-13 23:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-05-15 08:26 . 2011-05-15 08:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2010-03-24 14:23 . 2011-05-15 10:52 361826 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2009-07-14 05:01 . 2011-05-15 08:25 389324 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2011-05-13 06:51 389324 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2011-02-25 23:37 . 2011-05-13 06:51 2702058 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3584129800-2309573062-3716894374-1000-8192.dat + 2011-02-25 23:37 . 2011-05-15 08:25 2702058 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3584129800-2309573062-3716894374-1000-8192.dat + 2011-04-09 15:04 . 2011-05-15 08:26 19757472 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3584129800-2309573062-3716894374-1000-4096.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "Steam"="c:\program files (x86)\Steam\steam.exe" [2010-11-16 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "SSDMonitor"="c:\program files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2010-11-15 112600] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "PCTools FGuard"="c:\program files (x86)\PC Tools Security\BDT\FGuard.exe" [2011-01-07 108496] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-26 421160] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] . c:\users\Philo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-18 136176] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-18 136176] R3 mvusbews;USB EWS Device;c:\windows\system32\Drivers\mvusbews.sys [x] R3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\DRIVERS\pctNdis64.sys [x] R3 pctplfw;pctplfw;c:\windows\System32\drivers\pctplfw64.sys [x] R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [x] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2011-02-18 371472] R3 ThreatFire;ThreatFire;c:\program files (x86)\PC Tools Security\TFEngine\TFService.exe service [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [x] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x] S0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [x] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys [x] S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2010/03/23 20:09];c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2009-09-09 06:38 146928] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-03-02 89600] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2011-04-12 337872] S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [x] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x] S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [2010-10-01 632792] S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [2009-10-06 296360] S2 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe [2009-10-06 169376] S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-07-12 1924400] S3 AVerBDA6x_x64;AVerMedia SAA716x BDA Service;c:\windows\system32\DRIVERS\AVerBDA716x_x64.sys [x] S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter64.sys [x] S3 pctNdisMP;PC Tools Driver;c:\windows\system32\DRIVERS\pctNdis64.sys [x] S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *Deregistered* - PCTSDInjDriver64 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-10-16 02:49 451872 —-a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2011-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-18 01:17] . 2011-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-18 01:17] . 2011-04-23 c:\windows\Tasks\HPCeeScheduleForPhilo.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-06 18:22] . 2011-05-15 c:\windows\Tasks\RMSchedule.job - c:\program files (x86)\Registry Mechanic\RegMech.exe [2011-02-25 07:05] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EPSON Stylus Photo RX530 Series"="c:\windows\system32\spool\DRIVERS\x64\3\E_FATIAGP.EXE" [2005-04-06 98304] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-01-07 2328944] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\system32\blank.htm LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{55662437-DA8C-40c0-AADA-2C816A897A49}] "ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_10_2_161_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_10_2_161_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-05-15 22:53:00 ComboFix-quarantined-files.txt 2011-05-15 12:52 ComboFix2.txt 2011-05-14 02:31 . Pre-Run: 483,025,240,064 bytes free Post-Run: 482,964,529,152 bytes free . - - End Of File - - 09354FA2D03958A6866B9BEF5F5D6AA5
Hi Philo350.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
http://www.eset.com/onlinescan/

In your next reply let me know how your system is running and post the logs to:
  • Malwarebytes
  • ESET Online Scanner
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6587 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 5/16/2011 1:10:31 PM mbam-log-2011-05-16 (13-10-31).txt Scan type: Quick scan Objects scanned: 167007 Time elapsed: 2 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) The ESET Online Scanner found no threats.
Great Job getting those logs! How is your system running now?

Please Right Click and Run as Administrator the DDS icon once more and post the log that is created. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI