This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search Results re-directing and awful performance

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently I noticed that my search results from Bing or Yahoo were redirecting me to other websites that are not what they are supposed to be. After about a week, the performace of my laptop started to degrade really badly, and now, I can't even use it without it being in safe-mode.

I've tried to follow some other posts to resolve my problem, but nothing has helped yet.

Below is the log from OTL.exe

OTL logfile created on: 5/13/2011 4:36:32 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Travis\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.86 Gb Total Space | 99.35 Gb Free Space | 34.63% Space Free | Partition Type: NTFS
Drive Q: | 9.77 Gb Total Space | 2.38 Gb Free Space | 24.34% Space Free | Partition Type: NTFS
Drive S: | 1.46 Gb Total Space | 0.77 Gb Free Space | 52.70% Space Free | Partition Type: NTFS

Computer Name: TRAVIS-PC | User Name: Travis | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/13 16:28:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Travis\Desktop\OTL.exe
PRC - [2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2010/11/11 13:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe


========== Modules (SafeList) ==========

MOD - [2011/05/13 16:28:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Travis\Desktop\OTL.exe
MOD - [2010/11/20 07:55:09 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/03/15 19:59:46 | 000,658,432 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2011/02/18 18:09:02 | 000,028,672 | —- | M] (Lenovo Group Limited) [Auto | Stopped] – C:\Program Files\Lenovo\System Update\SUService.exe – (SUService)
SRV - [2011/02/04 03:45:00 | 000,128,360 | —- | M] (Lenovo.) [On_Demand | Stopped] – C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE – (DozeSvc)
SRV - [2011/02/04 03:45:00 | 000,079,208 | —- | M] (Lenovo) [On_Demand | Stopped] – C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE – (Power Manager DBC Service)
SRV - [2010/12/03 11:57:38 | 000,099,328 | —- | M] (Lenovo Group Limited) [Auto | Stopped] – C:\Program Files\Lenovo\HOTKEY\tphkload.exe – (TPHKLOAD)
SRV - [2010/12/02 13:55:54 | 000,064,440 | —- | M] (Lenovo Group Limited) [Auto | Stopped] – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe – (TPHKSVC)
SRV - [2010/11/24 16:34:24 | 000,045,496 | —- | M] (Lenovo Group Limited) [Auto | Stopped] – C:\Program Files\Lenovo\HOTKEY\micmute.exe – (LENOVO.MICMUTE)
SRV - [2010/11/11 13:26:42 | 000,206,360 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV - [2010/11/11 13:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/10/23 01:50:14 | 000,176,128 | —- | M] (AMD) [Auto | Stopped] – C:\Windows\System32\atiesrxx.exe – (AMD External Events Utility)
SRV - [2010/10/21 03:07:36 | 000,098,304 | —- | M] () [Auto | Stopped] – C:\Windows\System32\DTS.exe – (dtsvc)
SRV - [2010/10/21 03:07:32 | 000,106,496 | —- | M] () [On_Demand | Stopped] – C:\Windows\System32\ADMonitor.exe – (ADMonitor)
SRV - [2010/10/21 03:04:08 | 001,824,064 | —- | M] (AuthenTec, Inc.) [Auto | Stopped] – C:\Windows\System32\AtService.exe – (ATService)
SRV - [2010/10/19 15:25:18 | 000,866,576 | —- | M] (Intel® Corporation) [Auto | Stopped] – C:\Program Files\Intel\WiFi\bin\EvtEng.exe – (EvtEng) Intel®
SRV - [2010/10/19 15:02:42 | 000,477,456 | —- | M] (Intel® Corporation) [Auto | Stopped] – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe – (RegSrvc) Intel®
SRV - [2010/09/24 13:19:16 | 000,444,656 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\ZuneWlanCfgSvc.exe – (ZuneWlanCfgSvc)
SRV - [2010/09/24 13:19:16 | 000,268,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Zune\WMZuneComm.exe – (WMZuneComm)
SRV - [2010/09/24 13:19:08 | 006,351,600 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Zune\ZuneNss.exe – (ZuneNetworkSvc)
SRV - [2010/07/27 14:51:56 | 000,074,088 | —- | M] (Lenovo Group Limited) [Auto | Stopped] – C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe – (LENOVO.TPKNRSVC)
SRV - [2010/07/27 14:51:42 | 000,050,536 | —- | M] (Lenovo Group Limited) [Auto | Stopped] – C:\Program Files\Lenovo\Communications Utility\CamMute.exe – (LENOVO.CAMMUTE)
SRV - [2010/04/07 14:37:38 | 000,093,032 | —- | M] (Lenovo Group Limited) [Auto | Stopped] – C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe – (Lenovo.VIRTSCRLSVC)
SRV - [2010/02/25 20:41:24 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/02/04 12:14:20 | 002,058,776 | —- | M] (Intel Corporation) [Auto | Stopped] – C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/02/04 12:14:06 | 000,174,616 | —- | M] (Intel Corporation) [Auto | Stopped] – C:\Program Files\Intel\AMT\LMS.exe – (LMS) Intel®
SRV - [2009/09/25 17:11:08 | 001,028,096 | —- | M] (Lenovo Group Limited) [Auto | Stopped] – C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe – (ThinkVantage Registry Monitor Service)
SRV - [2009/08/07 06:29:36 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Stopped] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/07/13 21:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/06/07 13:20:20 | 000,061,440 | —- | M] (Nalpeiron Ltd.) [Auto | Stopped] – C:\Windows\System32\NlsSrv32.exe – (nlsX86cc)
SRV - [2009/02/20 17:01:40 | 000,567,848 | —- | M] (Broadcom Corporation.) [Auto | Stopped] – C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe – (btwdins)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Stopped] – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/04/25 11:15:24 | 001,120,752 | —- | M] (Sonic Solutions) [On_Demand | Stopped] – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe – (RoxMediaDB10)
SRV - [2008/01/11 20:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe – (BcmSqlStartupSvc)
SRV - [2007/01/04 22:48:52 | 000,112,152 | R— | M] (InterVideo) [Auto | Stopped] – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe – (IviRegMgr)


========== Driver Services (SafeList) ==========

DRV - [2011/05/13 16:18:37 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsl80cdbc1f.sys – (MpKsl80cdbc1f)
DRV - [2011/05/13 16:06:24 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsle88e4bbe.sys – (MpKsle88e4bbe)
DRV - [2011/05/13 15:54:38 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKslaa3bbad1.sys – (MpKslaa3bbad1)
DRV - [2011/04/12 13:01:38 | 000,045,464 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\dc3d.sys – (dc3d) MS Hardware Device Detection Driver (USB)
DRV - [2011/03/22 17:00:57 | 000,049,408 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ipod2car.sys – (IPOD2CAR)
DRV - [2011/02/04 03:45:00 | 000,025,968 | —- | M] (Lenovo.) [Kernel | Boot | Running] – C:\Windows\System32\DRIVERS\DozeHDD.sys – (DozeHDD)
DRV - [2011/02/04 03:45:00 | 000,013,424 | —- | M] (Lenovo Group Limited) [Kernel | System | Stopped] – C:\Windows\System32\drivers\TPPWR32V.SYS – (TPPWRIF)
DRV - [2010/12/09 19:09:16 | 000,021,744 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] – c:\Program Files\PC-Doctor\pcdsrvc.pkms – (PCDSRVC{3037D694-FD904ACA-06020101}_0)
DRV - [2010/11/20 08:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 08:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 08:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 06:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 06:21:14 | 000,015,872 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV - [2010/11/20 05:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\WinUSB.SYS – (WinUSB)
DRV - [2010/11/20 05:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 05:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/10/24 22:25:38 | 000,054,144 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2010/10/24 22:25:38 | 000,043,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\MpNWMon.sys – (MpNWMon)
DRV - [2010/10/23 02:11:48 | 005,882,880 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (atikmdag)
DRV - [2010/10/23 02:11:48 | 005,882,880 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (amdkmdag)
DRV - [2010/10/23 01:17:16 | 008,758,272 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\igdpmd32.sys – (intelkmd)
DRV - [2010/10/23 01:16:36 | 000,210,944 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmpag.sys – (amdkmdap)
DRV - [2010/10/21 05:54:16 | 000,659,968 | —- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ATSwpWDF.sys – (ATSwpWDF)
DRV - [2010/10/18 03:20:48 | 007,122,944 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\NETwNs32.sys – (NETwNs32) ___ Intel®
DRV - [2010/09/07 14:09:06 | 000,013,680 | —- | M] (Lenovo Group Limited) [Kernel | System | Stopped] – C:\Windows\System32\drivers\smiif32.sys – (lenovo.smi)
DRV - [2010/08/15 21:19:10 | 000,691,696 | —- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/05/21 00:09:58 | 000,009,040 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\rdpdispm.sys – (RDPDISPM)
DRV - [2010/03/17 22:21:16 | 006,758,912 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NETw5s32.sys – (NETw5s32) Intel®
DRV - [2009/12/08 07:17:05 | 000,033,088 | —- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psadd.sys – (psadd)
DRV - [2009/10/09 12:12:02 | 000,120,360 | —- | M] (Lenovo.) [Kernel | Boot | Running] – C:\Windows\System32\DRIVERS\Apsx86.sys – (Shockprf)
DRV - [2009/10/09 12:10:24 | 000,020,520 | —- | M] (Lenovo.) [Kernel | Boot | Running] – C:\Windows\System32\DRIVERS\ApsHM86.sys – (TPDIGIMN)
DRV - [2009/08/21 14:59:22 | 000,232,472 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\iaNvStor.sys – (iaNvStor) Intel®
DRV - [2009/07/13 19:52:10 | 000,014,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vwifimp.sys – (vwifimp)
DRV - [2009/07/13 19:51:29 | 000,050,688 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BTHPRINT.SYS – (BTHprint)
DRV - [2009/07/13 19:12:52 | 000,030,720 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\tpm.sys – (TPM)
DRV - [2009/07/13 18:02:51 | 004,231,168 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\netw5v32.sys – (netw5v32) Intel®
DRV - [2009/07/02 11:16:22 | 000,038,336 | —- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\tvti2c.sys – (TVTI2C)
DRV - [2009/06/23 13:49:58 | 000,040,832 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HECI.sys – (HECI) Intel®
DRV - [2009/01/05 00:35:58 | 000,128,104 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\WimFltr.sys – (WimFltr)
DRV - [2008/11/25 20:37:48 | 001,754,368 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\snp2uvc.sys – (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2008/09/12 10:03:34 | 000,540,288 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emBDA.sys – (USB28xxBGA)
DRV - [2008/09/12 10:03:34 | 000,443,520 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emOEM.sys – (USB28xxOEM)
DRV - [2008/08/22 02:10:32 | 000,225,408 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\e1y6032.sys – (e1yexpress) Intel®
DRV - [2008/02/15 05:01:00 | 000,046,592 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/07/29 22:54:00 | 000,038,400 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/07/29 21:42:00 | 000,043,008 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2007/06/18 19:29:56 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Stopped] – C:\Windows\System32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2007/06/18 19:29:10 | 000,035,064 | —- | M] (Roxio) [File_System | Auto | Stopped] – C:\Windows\System32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2007/06/18 19:29:08 | 000,093,752 | —- | M] (Roxio) [File_System | Auto | Stopped] – C:\Windows\System32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2007/06/18 19:29:06 | 000,098,136 | —- | M] (Roxio) [File_System | Auto | Stopped] – C:\Windows\System32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2007/06/18 19:29:04 | 000,026,744 | —- | M] (Roxio) [File_System | Auto | Stopped] – C:\Windows\System32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2007/06/18 19:28:58 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Stopped] – C:\Windows\System32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2007/06/18 19:28:54 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Stopped] – C:\Windows\System32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2007/06/18 19:28:52 | 000,105,048 | —- | M] (Roxio) [File_System | Auto | Stopped] – C:\Windows\System32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2007/02/08 23:05:30 | 000,028,120 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2007/02/08 23:05:30 | 000,012,856 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLACDBHM.SYS – (DLACDBHM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========




O1 HOSTS File: ([2011/04/27 19:02:01 | 000,433,231 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14912 more lines…
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O4 - HKLM..\Run: [CreateLMBCShortCut] C:\Program Files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe ()
O4 - HKLM..\Run: [FingerPrintSoftware] C:\Program Files\Lenovo Fingerprint Software\fpapp.exe (AuthenTec)
O4 - HKLM..\Run: [FingerPrintSoftwareSplashScreen] C:\Program Files\Lenovo Fingerprint Software\SplashScreen.exe (AuthenTec, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe (Intel Corporation)
O4 - HKLM..\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [picon] C:\Program Files\Common Files\Intel\Privacy Icon\PIconStartup.exe ()
O4 - HKLM..\Run: [PWMTRV] C:\Program Files\ThinkPad\Utilities\PWMTR32V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [NvCplDaemonTool] C:\Users\Travis\yload87.dll ()
O4 - HKCU..\Run: [Switcher] File not found
O4 - Startup: C:\Users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Travis\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scanwdiskh21.dll ()
O4 - Startup: C:\Users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scanxdiskbb36.dll (Comp)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 1 = @biocpl.dll,-1 (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…20Installer.cab (Support.com Configuration Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O24 - Desktop WallPaper: C:\SWTOOLS\Wallpaper\ThinkDots1680x1050.jpg
O24 - Desktop BackupWallPaper: C:\SWTOOLS\Wallpaper\ThinkDots1680x1050.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/06/10 12:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF – [ NTFS ]
O32 - AutoRun File - [2008/06/02 18:46:54 | 000,000,049 | -HS- | M] () - S:\AUTORUN.INF – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.444p - C:\Program Files\t@b\0.958\686\tabdec.dll ()
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.mpng - C:\Program Files\t@b\0.958\686\tabdec.dll ()
Drivers32: vidc.mvjp - C:\Program Files\t@b\0.958\686\tabdec.dll ()


========== Files/Folders - Created Within 30 Days ==========

[2011/05/13 16:28:03 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Travis\Desktop\OTL.exe
[2011/05/12 22:52:45 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/05/12 22:52:06 | 000,000,000 | -HSD | C] – C:\Windows\System32\%APPDATA%
[2011/05/12 22:49:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/05/12 22:49:10 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2011/05/12 22:48:56 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/05/12 22:48:56 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/05/12 22:48:56 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/05/12 22:48:04 | 003,967,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/05/12 22:48:04 | 003,912,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/05/12 19:05:47 | 000,000,000 | —D | C] – C:\Users\Travis\Desktop\tdsskiller
[2011/04/29 23:23:26 | 000,000,000 | —D | C] – C:\Users\Travis\Documents\gegl-0.0
[2011/04/28 16:44:17 | 000,000,000 | —D | C] – C:\Users\Travis\AppData\Local\assembly
[2011/04/28 16:41:36 | 000,000,000 | —D | C] – C:\Users\Travis\AppData\Local\Temporary Projects
[2011/04/27 17:07:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/04/20 19:48:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse
[2011/04/20 19:47:56 | 000,000,000 | —D | C] – C:\Program Files\Microsoft IntelliPoint
[2011/04/19 20:43:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Keyboard
[2011/04/19 20:42:38 | 000,000,000 | —D | C] – C:\Program Files\Microsoft IntelliType Pro
[2011/01/20 21:12:02 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2009/08/04 22:50:02 | 000,225,280 | —- | C] ( ) – C:\Windows\System32\rsnp2uvc.dll
[2009/08/04 22:50:02 | 000,176,128 | —- | C] ( ) – C:\Windows\System32\csnp2uvc.dll
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/13 16:28:55 | 000,664,834 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/13 16:28:55 | 000,122,602 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/13 16:28:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Travis\Desktop\OTL.exe
[2011/05/13 16:23:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/13 16:23:46 | 1981,816,832 | -HS- | M] () – C:\hiberfil.sys
[2011/05/13 16:21:31 | 000,001,082 | —- | M] () – C:\Users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk
[2011/05/13 16:14:05 | 000,011,104 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/13 16:14:05 | 000,011,104 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/12 22:35:59 | 000,000,528 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/05/12 15:01:30 | 000,000,382 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/04/29 23:24:31 | 000,001,496 | —- | M] () – C:\Users\Travis\.recently-used.xbel
[2011/04/29 22:45:39 | 000,026,977 | —- | M] () – C:\Users\Travis\Documents\bookmark.htm
[2011/04/27 19:12:37 | 000,465,288 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/27 19:02:01 | 000,433,231 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/04/14 05:08:11 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/14 05:08:10 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/14 05:08:09 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/14 05:07:59 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/29 23:24:31 | 000,001,496 | —- | C] () – C:\Users\Travis\.recently-used.xbel
[2011/04/29 22:45:39 | 000,026,977 | —- | C] () – C:\Users\Travis\Documents\bookmark.htm
[2011/04/18 17:09:55 | 000,001,082 | —- | C] () – C:\Users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk
[2011/03/16 18:27:16 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2011/03/16 18:24:19 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/01/20 21:12:03 | 000,982,240 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2011/01/20 21:12:03 | 000,208,896 | —- | C] () – C:\Windows\System32\iglhsip32.dll
[2011/01/20 21:12:03 | 000,143,360 | —- | C] () – C:\Windows\System32\iglhcp32.dll
[2011/01/20 21:12:02 | 000,092,356 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2011/01/20 21:12:01 | 000,439,308 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2011/01/20 21:12:00 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config
[2011/01/20 21:11:59 | 000,002,857 | —- | C] () – C:\Windows\System32\atipblag.dat
[2011/01/20 21:11:57 | 000,205,156 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2010/10/21 03:07:36 | 000,098,304 | —- | C] () – C:\Windows\System32\DTS.exe
[2010/10/21 03:07:32 | 000,106,496 | —- | C] () – C:\Windows\System32\ADMonitor.exe
[2010/08/04 20:54:22 | 000,303,104 | —- | C] () – C:\Windows\System32\glew32.dll
[2010/04/13 22:28:42 | 000,007,602 | —- | C] () – C:\Users\Travis\AppData\Local\Resmon.ResmonCfg
[2010/03/23 15:08:42 | 000,000,600 | —- | C] () – C:\Users\Travis\AppData\Local\PUTTY.RND
[2010/03/22 23:45:16 | 000,000,600 | —- | C] () – C:\Users\Travis\AppData\Roaming\winscp.rnd
[2009/12/25 11:16:06 | 000,013,312 | —- | C] () – C:\Users\Travis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/09 01:15:53 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/12/08 03:25:22 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2009/12/07 23:43:05 | 000,134,592 | —- | C] () – C:\Windows\System32\igfcg500.bin
[2009/08/04 23:44:54 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/08/04 23:05:08 | 000,056,056 | —- | C] () – C:\Windows\System32\DLAAPI_W.DLL
[2009/08/04 23:05:08 | 000,000,120 | —- | C] () – C:\Windows\wininit.ini
[2009/08/04 23:02:52 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2009/08/04 23:02:52 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2009/08/04 23:02:52 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2009/08/04 23:02:52 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2009/08/04 23:02:52 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2009/08/04 23:02:52 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2009/08/04 22:50:02 | 001,754,368 | —- | C] () – C:\Windows\System32\drivers\snp2uvc.sys
[2009/08/04 22:50:02 | 000,028,800 | —- | C] () – C:\Windows\System32\drivers\sncduvc.sys
[2009/08/04 22:50:02 | 000,015,497 | —- | C] () – C:\Windows\snp2uvc.ini
[2009/08/04 22:37:18 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2009/08/04 22:14:22 | 000,016,896 | —- | C] () – C:\Windows\Eventclr.exe
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/14 00:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,465,288 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,664,834 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,122,602 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/06/04 16:51:10 | 000,000,542 | —- | C] () – C:\Windows\System32\atipblup.dat

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/05/13 16:23:46 | 1981,816,832 | -HS- | M] () – C:\hiberfil.sys
[2011/01/10 21:18:22 | 000,000,450 | —- | M] () – C:\INSTALL.LOG
[2010/08/15 21:31:45 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/15 21:31:45 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/06/04 11:55:54 | 000,000,549 | —- | M] () – C:\NTDClient.log
[2011/05/13 16:23:50 | 2642,423,808 | -HS- | M] () – C:\pagefile.sys
[2009/12/19 10:40:31 | 000,000,188 | —- | M] () – C:\setup.log
[2009/12/08 05:51:36 | 000,001,188 | —- | M] () – C:\sysiclog.txt
[2011/05/12 19:07:03 | 000,081,250 | —- | M] () – C:\TDSSKiller.2.5.0.0_12.05.2011_19.06.03_log.txt
[2011/05/12 22:49:38 | 000,081,250 | —- | M] () – C:\TDSSKiller.2.5.0.0_12.05.2011_22.41.35_log.txt
[2011/03/20 13:13:12 | 000,001,732 | —- | M] () – C:\tvtpktfilter.dat

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/06/22 19:58:20 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 22:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 08:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2007/09/19 18:41:11 | 000,004,096 | —- | M] () – C:\Windows\System32\Thumbs.db
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/08 03:58:16 | 000,000,221 | -HS- | M] () – C:\Users\Travis\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/03/28 17:28:29 | 000,000,221 | -HS- | M] () – C:\Users\Travis\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/05/13 16:28:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Travis\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2006/05/19 14:53:02 | 000,013,022 | —- | M] () – C:\Windows\snp2uvc.src
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-13 02:53:13

========== Alternate Data Streams ==========

@Alternate Data Stream - 128 bytes -> C:\Windows:nlsPreferences

< End of report >


OTL Extras

OTL Extras logfile created on: 5/13/2011 4:36:32 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Travis\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.86 Gb Total Space | 99.35 Gb Free Space | 34.63% Space Free | Partition Type: NTFS
Drive Q: | 9.77 Gb Total Space | 2.38 Gb Free Space | 24.34% Space Free | Partition Type: NTFS
Drive S: | 1.46 Gb Total Space | 0.77 Gb Free Space | 52.70% Space Free | Partition Type: NTFS

Computer Name: TRAVIS-PC | User Name: Travis| Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007BECB0-17DD-4230-9D2F-185287262B14}" = Microsoft XNA Game Studio 3.1 (Platformer)
"{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}" = Java DB 10.5.3.0
"{022CBB38-CEF0-42BA-906A-A49BEFAE0BEE}" = RICOH R5U230 Media Driver ver.2.02.02.01
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{052E244C-3674-8907-D9C3-092C89521B94}" = Catalyst Control Center Localization Korean
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
"{09FF8CD4-A447-CDD6-DFB2-4CF6F7BD1C1B}" = ccc-utility
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B4CC538-B423-B589-123E-74A0F4894364}" = PX Profile Update
"{0D56C859-89B9-3F17-9925-BD134CE6AECA}" = CCC Help English
"{0DC16794-7E69-4534-82FA-9DD0500FF338}" = Microsoft XNA Game Studio 3.1 (Redists)
"{11432CAF-EA32-4102-9AEE-5D31F2E9F762}" = Microsoft XNA Game Studio 3.1 Zune Extensions
"{13A5E785-5197-4EAD-8EE3-D660271E49BC}" = Feedback Tool
"{1433371A-F983-9562-3947-92420A72849D}" = Catalyst Control Center Graphics Previews Vista
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1C76C745-0A3E-648F-439C-611DB86BCB3E}" = ATI Catalyst Install Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{23146B80-2B64-023D-0696-A753E5C45FB4}" = Catalyst Control Center Graphics Full Existing
"{25C64847-B900-48AD-A164-1B4F9B774650}" = System Update
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 25
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2D440AF4-7330-43F0-A085-35DE1A90E703}" = Lenovo Fingerprint Software
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Drag-to-Disc
"{31423F74-36B2-4d24-B10D-CD00BFB7C118}" = Intel® Turbo Memory
"{32A3A4F4-B792-11D6-A78A-00B0D0160200}" = Java™ SE Development Kit 6 Update 20
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{38A92088-9F3B-166D-5396-B0001A9041F1}" = Catalyst Control Center Graphics Previews Vista
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Integrated Camera
"{3BA37E38-B53D-4520-B8DA-1DD62AD3A74E}" = Microsoft XNA Game Studio 3.1 (VCSExpress)
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{4335AECB-5FDC-40CB-777D-52E383BAAE7A}" = Catalyst Control Center InstallProxy
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{46F8CF66-AB83-38A7-99B2-A5BE507EE472}" = Microsoft Visual C++ 2010 Express - ENU
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AB5764A-3894-49A2-BAA8-C4665F74CD4C}" = Registry patch to improve USB device detection on resume from sleep for Windows Vista
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4F4D62A0-CB7B-B503-D7FC-0F89F3BB7D19}" = CCC Help Japanese
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{5371B188-D016-37B0-4C71-986B5D33E762}" = CCC Help Portuguese
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Creator Business Edition
"{54B09E60-18E3-1A58-505D-FEE0DAB14AD9}" = Catalyst Control Center Localization All
"{55C47B52-A03C-32FB-8FC8-BEF5A7A66FF5}" = Microsoft Visual C++ 2010 Beta 2 x86 Redistributable - 10.0.21006
"{58ED9767-2CE7-7A05-8C89-813B3557F112}" = CCC Help Chinese Traditional
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5U8xx Media Driver ver.3.64.02
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5E335FB1-87E8-41DF-AF8D-6B51E03A36AA}" = PCTV Package - Windows Media Center
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{6583D00E-0924-4950-8BE9-5D09FE70B333}" = MTX
"{65C0025A-2CDE-43C5-82D0-C7A56EF0DB39}" = Bing Bar Platform
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{668ACF05-E455-4932-A2D2-5822A8206FEB}" = Camera Center
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6ADC5DFC-24AA-D4E1-478A-5CD6337F8051}" = Catalyst Control Center Localization Italian
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{7006ED29-58F2-40C3-AE87-039287AD20B6}" = Zune
"{7210BCFE-ED8D-4261-8537-81B5A4BDFA2A}" = Rosetta Stone V3
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Central Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{7B2A21FD-A47F-4200-99BC-0E4C2B77433A}" = ccc-core-static
"{7B647582-EE62-8275-9D76-15692741C585}" = Catalyst Control Center Localization Chinese Traditional
"{7FD30AE7-281D-455F-AF9F-0C6C5E334EAD}" = Microsoft XNA Game Studio 3.1 Documentation
"{821456F8-EB18-41A8-DED5-695096B7D9D6}" = Catalyst Control Center Localization Chinese Standard
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88B2F404-F553-ABE3-4443-D9E5E1B2CE4F}" = CCC Help Dutch
"{88C6A6D9-324C-46E8-BA87-563D14021442}_is1" = ThinkVantage Communications Utility
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACB5112-A58B-7283-B771-6271A0D9471D}" = Catalyst Control Center Core Implementation
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager and Intel® Turbo Memory
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{90FABD40-E741-446F-839D-CEAE905D63BE}" = ThinkPad Mobility Center Customization
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{94B1AD86-8764-8853-F4BB-7F92D5E94AA3}" = Catalyst Control Center Graphics Full New
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007F-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96056420-DDF3-46A7-AA8D-BC2D1AE5290B}" = Microsoft IntelliType Pro 8.1
"{97BBF90F-A852-4AA0-872B-42D13AA22D94}" = Mobile Broadband Connect
"{986F64DC-FF15-449D-998F-EE3BCEC6666A}" = Help Center
"{98BAADEA-0316-4C5D-A308-F6FFAF4DD681}" = Catalyst Control Center - Branding
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B14495A-E66F-3D68-3B03-D40A6862D6D7}" = ccc-utility
"{9C2F9B2C-1585-43AD-9EF9-48AAD60DFC04}" = Microsoft IntelliPoint 8.1
"{9CC74D41-2163-AC60-608E-8FD3E7096493}" = CCC Help Spanish
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{9FCE66F0-EE03-43BD-916E-66EDF0DBC18C}" = Catalyst Control Center - Branding
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A4418082-E601-3954-805B-D56A2B50EC8B}" = Microsoft Visual C# 2008 Express Edition with SP1 - ENU
"{A8314F91-FF66-4ACA-AC3A-2B06F4900A15}" = RenderMonkey 1.82
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{ABC6E084-55EA-5860-4654-B21FFE886B1B}" = PX Profile Update
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AE2832A3-8108-F2BF-7086-BE66D29106E7}" = Catalyst Control Center Graphics Light
"{AF9BDE67-11A5-449A-B9F0-BE572A093DDB}" = Microsoft XNA Game Studio 3.1 (Shared Components)
"{B05B22B8-72AE-4DC3-8D6F-FBC2233CAF41}" = Roxio Creator Business Edition
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B334D9AE-1393-423E-97C0-3BDC3360E692}" = Sonic Icons for Lenovo
"{B383F243-0ABC-4E56-AA30-923B8D85076E}" = Rescue and Recovery
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
"{B743728C-6BF6-8562-E102-7602F5F59FFD}" = CCC Help German
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{BE03D78B-D3A5-81FA-E33D-6C20334507D4}" = CCC Help Korean
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{BED4CEEC-863F-4AB3-BA23-541764E2D2CE}" = Microsoft XNA Game Studio Platform Tools
"{BF1ECD50-5A11-B18B-4AA0-20E41E7C20F7}" = Catalyst Control Center Localization Japanese
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C6FA39A7-26B1-480A-BC74-6D17531AC222}" = Access Help
"{C710E77E-6AC2-608B-214C-CEF6B9CDBA6E}" = Catalyst Control Center InstallProxy
"{C7259A62-8533-1E89-9C95-D6B19329D925}" = CCC Help Italian
"{C945C17F-2E78-4511-ABB6-EF637D2EE8FB}" = Skins
"{CAB81583-0310-43E1-8E33-0864985EDD67}" = trakAxPC
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CCCF9048-DAFD-F1F5-B860-9B5C32FBD2D6}" = Catalyst Control Center Localization Portuguese
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D22E6706-136E-4810-AF2E-359AE30A7323}" = ThinkVantage Status Gadget
"{D239B547-8B20-4BDE-888D-C9CCA823FFD8}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D75AEB5B-FA18-4BD4-9EED-54CA46DB5AE8}" = Intel® PROSet/Wireless WiFi Software
"{D8087907-E255-3A41-A46D-D0F798709C71}" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
"{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = ThinkPad Power Manager
"{DB71210F-8314-4AE3-B7A7-EBAF85BD30E9}" = Wallpapers
"{DD622B1D-A78E-3FE8-9C8C-246F5764B0D0}" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DFAE9340-E8BB-4433-9A08-C8334DAFE1B9}" = Star Wars Republic Commando
"{DFB81F19-ED3A-4DA5-AFE4-1B999E2A8DC5}" = Microsoft XNA Game Studio 3.1 (XnaLiveProxy)
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1D78366-91DA-4AD0-B417-28155743CC22}" = Microsoft XNA Game Studio 3.1 (ARP entry)
"{E4CB66D5-C29E-9612-5E32-6807E91A82CD}" = Catalyst Control Center Localization Swedish
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{E6D6B669-1D41-ECBF-C5CA-00B6EBA003D8}" = CCC Help Swedish
"{E7E836B8-4BDD-454F-82E6-5FEA17C83AD4}" = Message Center
"{EA5AB32C-970E-D7C4-C896-1C927FB3E384}" = Catalyst Control Center Localization Dutch
"{EBE96946-9AC3-6454-82CC-02602343955A}" = CCC Help Chinese Standard
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{F1F1A2AD-A1CE-4D9D-B510-31F280B45E0B}" = Microsoft Expression Encoder 3
"{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F419591C-F000-EBBA-D8DE-DE6141B723D3}" = CCC Help French
"{F9230D65-8EED-B6DD-F9FB-8AEFDE06579C}" = Catalyst Control Center Localization French
"{FA62B4C2-6CFD-462F-9B59-68A730001AB3}" = Product Recovery Disc Burning Utility
"{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}" = Message Center Plus
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"05FBE63CF9C9B3424152207E7278CD6DA193C56C" = Windows Driver Package - AuthenTec Inc. (ATSwpWDF) Biometric (07/02/2010 8.6.0.29)
"0A7603E3091C168CDE422A2B3481A2F7D17D0954" = Windows Driver Package - Intel hdc (02/20/2008 6.9.1.1001)
"1205965EF392C9B0D5A9BDB139035F058E76359E" = Windows Driver Package - Ricoh Company MMC Host Controller (02/15/2008 6.00.03.05)
"1A96FF9D9E5F19776E6749D8F6557FCC437EB294" = Windows Driver Package - Ricoh Company MS Host Controller (07/30/2007 6.00.01.11)
"25A4FC9EFE7A8860FCF6F86FFABDD9334A2619E3" = Windows Driver Package - Intel (e1yexpress) Net (08/22/2008 9.52.10.1001)
"3EB6CB625B5778835F0A66A7529E69050E0EE033" = Windows Driver Package - Lenovo 1.53 (03/19/2009 1.53)
"432D918ED17EA51B73E8491A0369730C0076A292" = Windows Driver Package - Intel System (02/20/2008 8.6.1.1002)
"464CE3922A214073AAEE00DEB23EA5C750AF8CE8" = Windows Driver Package - Intel USB (02/05/2007 8.3.0.1011)
"513C7D1BF4530B30EC84716327E4D7E76810DCC5" = Windows Driver Package - Intel System (02/20/2008 8.7.0.1007)
"5A4D4FF375E24E41AE5D2D907E67E0884BE2CAF4" = Windows Driver Package - Intel System (01/30/2008 8.6.1.1001)
"778DAA8FB0D52FC214BC306BBDC33E26ACAB6F44" = Windows Driver Package - Ricoh Company xD Host Controller (07/30/2007 6.00.01.13)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATI Uninstaller" = ATI Uninstaller
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"CCleaner" = CCleaner
"Dipmon" = Registry Patch of Enabling Device Initiated Power Management(DIPM) on SATA for Windows Vista
"E6CEFD9A59425A2A27E92572AB367B28C371D3D8" = Windows Driver Package - Intel System (09/15/2006 7.0.0.1011)
"EC1E678D1EFB79A1D02C312390944027C715CD5C" = Windows Driver Package - Intel (iaStor) hdc (02/11/2009 8.8.0.1009)
"Encoder_3.0.1332.0" = Microsoft Expression Encoder 3
"FPIRPOn" = Registry patch of Changing Timing of IDLE IRP by Finger Print Driver for Windows Vista
"HECI" = Intel® Management Engine Interface
"Lenovo Registration" = Lenovo Registration
"Lenovo Welcome_is1" = Lenovo Welcome
"LENOVO.SMIIF" = Lenovo System Interface Driver
"LenovoAutoScrollUtility" = Lenovo Auto Scroll Utility
"MESOL" = Intel® Active Management Technology
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft IntelliPoint 8.1" = Microsoft IntelliPoint 8.1
"Microsoft IntelliType Pro 8.1" = Microsoft IntelliType Pro 8.1
"Microsoft Security Client" = Microsoft Security Essentials
"Microsoft Visual Basic 2008 Express Edition with SP1 - ENU" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"Microsoft Visual C# 2008 Express Edition with SP1 - ENU" = Microsoft Visual C# 2008 Express Edition with SP1 - ENU
"Microsoft Visual C++ 2008 Express Edition with SP1 - ENU" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
"Microsoft Visual C++ 2010 Express - ENU" = Microsoft Visual C++ 2010 Express - ENU
"MilkShape 3D 1.8.5" = MilkShape 3D 1.8.5
"OnScreenDisplay" = On Screen Display
"PC-Doctor for Windows" = Lenovo ThinkVantage Toolbox
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"t@b ZS4 Video Editor_is1" = t@b ZS4 Video Editor v0.958-686
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"ULTIMATER" = Microsoft Office Ultimate 2007
"USBPMon" = Registry patch for Windows Vista USB S3 PM Enablement
"Verizon Help and Support" = Verizon Help and Support Tool
"VLC media player" = VLC media player 1.0.3
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"XNA Game Studio 3.1" = Microsoft XNA Game Studio 3.1
"Zune" = Zune
"Zwei-Stein_is1" = Zwei-Stein Video Compositor 3.01 (Beta 2).

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"L3DT Professional (v2.7.0.0)" = L3DT Professional v2.7.0.0 (remove only)

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >



Any help is greatly appreciated.

Thank you!!
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply
Hello mowman. Thank you so much for your help! Here is the log from aswMBR, before my PC locked up. aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-13 21:31:14 —————————– 21:31:14.138 OS Version: Windows 6.1.7601 Service Pack 1 21:31:14.138 Number of processors: 2 586 0x170A 21:31:14.138 ComputerName: TRAVIS-PC UserName: Travis 21:32:27.957 Initialize success 21:32:34.961 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 21:32:34.961 Disk 0 Vendor: Size: 0MB BusType: 0 21:32:34.961 Disk 1 \Device\Harddisk1\DR1 -> \Device\RobsonImd-0 21:32:34.977 Disk 1 Vendor: Size: 1405MB BusType: 0 21:32:34.977 Disk 0 MBR read error 0 21:32:34.977 Disk 0 MBR scan 21:32:34.977 Disk 0 unknown MBR code 21:32:34.977 MBR BIOS signature not found 0 21:32:34.977 Disk 0 scanning C:\Windows\system32\drivers 21:32:48.268 Service scanning 21:32:50.234 Disk 0 trace - called modules: 21:32:50.265 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys spwn.sys >>UNKNOWN [0x8579e938]<< 21:32:50.280 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x889e1908] 21:32:50.280 3 CLASSPNP.SYS[8ac7559e] -> nt!IofCallDriver -> [0x8658c350] 21:32:50.296 5 ACPI.sys[837af3d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x86562028] 21:32:50.296 Scan finished successfully 21:33:08.408 Disk 0 MBR has been saved successfully to "C:\Users\Travis\Desktop\MBR.dat" 21:33:08.423 The log file has been saved successfully to "C:\Users\Travis\Desktop\aswMBR.txt"
Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Here is the log from TDSSKiller Only one suspisious file was found. 2011/05/14 14:56:40.0900 5624 TDSS rootkit removing tool 2.5.1.0 May 13 2011 13:20:29 2011/05/14 14:56:41.0399 5624 ================================================================================ 2011/05/14 14:56:41.0399 5624 SystemInfo: 2011/05/14 14:56:41.0399 5624 2011/05/14 14:56:41.0399 5624 OS Version: 6.1.7601 ServicePack: 1.0 2011/05/14 14:56:41.0399 5624 Product type: Workstation 2011/05/14 14:56:41.0399 5624 ComputerName: TRAVIS-PC 2011/05/14 14:56:41.0399 5624 UserName: Travis 2011/05/14 14:56:41.0399 5624 Windows directory: C:\Windows 2011/05/14 14:56:41.0399 5624 System windows directory: C:\Windows 2011/05/14 14:56:41.0399 5624 Processor architecture: Intel x86 2011/05/14 14:56:41.0399 5624 Number of processors: 2 2011/05/14 14:56:41.0399 5624 Page size: 0x1000 2011/05/14 14:56:41.0399 5624 Boot type: Normal boot 2011/05/14 14:56:41.0399 5624 ================================================================================ 2011/05/14 14:56:42.0179 5624 Initialize success 2011/05/14 14:56:53.0333 5676 ================================================================================ 2011/05/14 14:56:53.0333 5676 Scan started 2011/05/14 14:56:53.0333 5676 Mode: Manual; 2011/05/14 14:56:53.0333 5676 ================================================================================ 2011/05/14 14:56:54.0472 5676 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys 2011/05/14 14:56:54.0737 5676 61883 (beb5e6a8c17c3c7485563281e0f9e77e) C:\Windows\system32\DRIVERS\61883.sys 2011/05/14 14:56:54.0956 5676 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys 2011/05/14 14:56:55.0065 5676 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys 2011/05/14 14:56:55.0283 5676 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 2011/05/14 14:56:55.0471 5676 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 2011/05/14 14:56:55.0845 5676 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 2011/05/14 14:56:56.0001 5676 AFD (1151fd4fb0216cfed887bfde29ebd516) C:\Windows\system32\drivers\afd.sys 2011/05/14 14:56:56.0126 5676 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys 2011/05/14 14:56:56.0235 5676 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 2011/05/14 14:56:56.0453 5676 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys 2011/05/14 14:56:56.0625 5676 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys 2011/05/14 14:56:56.0921 5676 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys 2011/05/14 14:56:57.0046 5676 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 2011/05/14 14:56:57.0748 5676 amdkmdag (0bf46ec91b8dcd68a99dc7a7c2c7693c) C:\Windows\system32\DRIVERS\atikmdag.sys 2011/05/14 14:56:58.0216 5676 amdkmdap (94642df0550c7004c6afbd857c955050) C:\Windows\system32\DRIVERS\atikmpag.sys 2011/05/14 14:56:58.0466 5676 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 2011/05/14 14:56:58.0637 5676 amdsata (e7f4d42d8076ec60e21715cd11743a0d) C:\Windows\system32\drivers\amdsata.sys 2011/05/14 14:56:58.0747 5676 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 2011/05/14 14:56:58.0981 5676 amdxata (146459d2b08bfdcbfa856d9947043c81) C:\Windows\system32\drivers\amdxata.sys 2011/05/14 14:56:59.0137 5676 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys 2011/05/14 14:56:59.0402 5676 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 2011/05/14 14:56:59.0495 5676 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 2011/05/14 14:56:59.0698 5676 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/05/14 14:56:59.0792 5676 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys 2011/05/14 14:57:00.0665 5676 atikmdag (0bf46ec91b8dcd68a99dc7a7c2c7693c) C:\Windows\system32\DRIVERS\atikmdag.sys 2011/05/14 14:57:01.0040 5676 ATSwpWDF (51d379db1c53c2a55fdf9372e748e5c7) C:\Windows\system32\Drivers\ATSwpWDF.sys 2011/05/14 14:57:01.0243 5676 Avc (c44bdd77e06053cf5afe046f3a47c16b) C:\Windows\system32\DRIVERS\avc.sys 2011/05/14 14:57:01.0477 5676 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 2011/05/14 14:57:01.0617 5676 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 2011/05/14 14:57:01.0867 5676 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 2011/05/14 14:57:01.0960 5676 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 2011/05/14 14:57:02.0147 5676 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys 2011/05/14 14:57:02.0225 5676 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2011/05/14 14:57:02.0444 5676 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2011/05/14 14:57:02.0600 5676 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 2011/05/14 14:57:02.0662 5676 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 2011/05/14 14:57:02.0787 5676 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 2011/05/14 14:57:02.0943 5676 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 2011/05/14 14:57:03.0146 5676 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\drivers\BthEnum.sys 2011/05/14 14:57:03.0286 5676 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 2011/05/14 14:57:03.0520 5676 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys 2011/05/14 14:57:04.0066 5676 BTHPORT (195c41cc67e9e1cedd960ccb74925920) C:\Windows\System32\Drivers\BTHport.sys 2011/05/14 14:57:04.0300 5676 BTHprint (f185df7dec1777686e43c8c8c66f7883) C:\Windows\system32\DRIVERS\bthprint.sys 2011/05/14 14:57:04.0519 5676 BTHUSB (43b3206dd654e783aa7e4ead340a43b8) C:\Windows\System32\Drivers\BTHUSB.sys 2011/05/14 14:57:04.0659 5676 btwaudio (cfde80a2f2a598c9e71b37c2540cb119) C:\Windows\system32\drivers\btwaudio.sys 2011/05/14 14:57:04.0909 5676 btwavdt (9961051afcf130aee786981face4d7ec) C:\Windows\system32\DRIVERS\btwavdt.sys 2011/05/14 14:57:05.0065 5676 btwl2cap (54c2ee0a3cec586629035d771aacae67) C:\Windows\system32\DRIVERS\btwl2cap.sys 2011/05/14 14:57:05.0189 5676 btwrchid (58c6d944f65df260515e56bd21d795f6) C:\Windows\system32\DRIVERS\btwrchid.sys 2011/05/14 14:57:05.0299 5676 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 2011/05/14 14:57:05.0392 5676 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys 2011/05/14 14:57:05.0579 5676 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 2011/05/14 14:57:05.0798 5676 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 2011/05/14 14:57:06.0703 5676 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/05/14 14:57:06.0952 5676 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys 2011/05/14 14:57:07.0108 5676 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 2011/05/14 14:57:07.0358 5676 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 2011/05/14 14:57:07.0576 5676 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys 2011/05/14 14:57:07.0701 5676 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 2011/05/14 14:57:08.0075 5676 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys 2011/05/14 14:57:08.0325 5676 dc3d (734bbe7c66e6fd6047a1bd29b9343b30) C:\Windows\system32\DRIVERS\dc3d.sys 2011/05/14 14:57:08.0606 5676 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys 2011/05/14 14:57:08.0809 5676 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 2011/05/14 14:57:08.0918 5676 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 2011/05/14 14:57:09.0089 5676 DLABMFSM (5b149ccfe275f4de0b4b8ec6b9f6821e) C:\Windows\system32\DLA\DLABMFSM.SYS 2011/05/14 14:57:09.0323 5676 DLABOIOM (ad4cb3d783634c90a9d0ce360933a63c) C:\Windows\system32\DLA\DLABOIOM.SYS 2011/05/14 14:57:09.0464 5676 DLACDBHM (5230cdb7e715f3a3b4a882e254cdd35d) C:\Windows\system32\Drivers\DLACDBHM.SYS 2011/05/14 14:57:09.0635 5676 DLADResM (93d03238cc3f0ee3c0b3985d110ec575) C:\Windows\system32\DLA\DLADResM.SYS 2011/05/14 14:57:09.0916 5676 DLAIFS_M (6a82f77c4a6f5235bf352f0028e2ef52) C:\Windows\system32\DLA\DLAIFS_M.SYS 2011/05/14 14:57:10.0103 5676 DLAOPIOM (0e6052c0ada37504896a847231a3907d) C:\Windows\system32\DLA\DLAOPIOM.SYS 2011/05/14 14:57:10.0353 5676 DLAPoolM (29670bb4e2b973c5b55a76107d4910b2) C:\Windows\system32\DLA\DLAPoolM.SYS 2011/05/14 14:57:10.0540 5676 DLARTL_M (77fe51f0f8d86804cb81f6ef6bfb86dd) C:\Windows\system32\Drivers\DLARTL_M.SYS 2011/05/14 14:57:10.0759 5676 DLAUDFAM (6b087732b86c1d866d69dbbe463ea90a) C:\Windows\system32\DLA\DLAUDFAM.SYS 2011/05/14 14:57:10.0993 5676 DLAUDF_M (bbeecb95f2841ae4a3e3690d46d7153d) C:\Windows\system32\DLA\DLAUDF_M.SYS 2011/05/14 14:57:11.0211 5676 DozeHDD (6d279bb0de1d8e34f454e1b353f4d738) C:\Windows\system32\DRIVERS\DozeHDD.sys 2011/05/14 14:57:11.0429 5676 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 2011/05/14 14:57:11.0601 5676 DRVMCDB (83106585494d5eb96f59187200c144bd) C:\Windows\system32\Drivers\DRVMCDB.SYS 2011/05/14 14:57:12.0007 5676 DRVNDDM (ffc371525aa55d1bae18715ebcb8797c) C:\Windows\system32\Drivers\DRVNDDM.SYS 2011/05/14 14:57:12.0209 5676 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys 2011/05/14 14:57:12.0553 5676 e1yexpress (c90ce29df8b9836cc6514ce9f53d0eb5) C:\Windows\system32\DRIVERS\e1y6032.sys 2011/05/14 14:57:13.0099 5676 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 2011/05/14 14:57:13.0457 5676 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 2011/05/14 14:57:13.0723 5676 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys 2011/05/14 14:57:14.0269 5676 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 2011/05/14 14:57:14.0425 5676 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 2011/05/14 14:57:14.0534 5676 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 2011/05/14 14:57:14.0861 5676 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 2011/05/14 14:57:15.0111 5676 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 2011/05/14 14:57:15.0673 5676 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/05/14 14:57:16.0125 5676 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 2011/05/14 14:57:16.0499 5676 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 2011/05/14 14:57:16.0936 5676 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 2011/05/14 14:57:17.0342 5676 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys 2011/05/14 14:57:17.0701 5676 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 2011/05/14 14:57:18.0075 5676 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 2011/05/14 14:57:18.0418 5676 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys 2011/05/14 14:57:18.0699 5676 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys 2011/05/14 14:57:18.0777 5676 HECI (30d57ee84e1e169d41a6e873b549a096) C:\Windows\system32\DRIVERS\HECI.sys 2011/05/14 14:57:19.0136 5676 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 2011/05/14 14:57:19.0417 5676 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 2011/05/14 14:57:19.0713 5676 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 2011/05/14 14:57:20.0150 5676 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys 2011/05/14 14:57:20.0680 5676 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys 2011/05/14 14:57:21.0039 5676 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys 2011/05/14 14:57:21.0226 5676 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys 2011/05/14 14:57:21.0382 5676 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys 2011/05/14 14:57:21.0694 5676 iaNvStor (d0310c79c5a9d42b96e37c5c510c6a5c) C:\Windows\system32\DRIVERS\iaNvStor.sys 2011/05/14 14:57:21.0803 5676 iaStor (01446278d4563b3013c92830ae6cbb26) C:\Windows\system32\DRIVERS\iaStor.sys 2011/05/14 14:57:22.0053 5676 iaStorV (a3cae5d281db4cff7cff8233507ee5ad) C:\Windows\system32\drivers\iaStorV.sys 2011/05/14 14:57:22.0459 5676 IBMPMDRV (fa3d0a6da7bb7968efe5c5bc267f0e55) C:\Windows\system32\DRIVERS\ibmpmdrv.sys 2011/05/14 14:57:23.0504 5676 igfx (8e9da2e49347af49901526dcd4d0f397) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/05/14 14:57:24.0019 5676 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 2011/05/14 14:57:24.0112 5676 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys 2011/05/14 14:57:25.0033 5676 intelkmd (8e9da2e49347af49901526dcd4d0f397) C:\Windows\system32\DRIVERS\igdpmd32.sys 2011/05/14 14:57:25.0516 5676 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 2011/05/14 14:57:25.0844 5676 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/05/14 14:57:26.0281 5676 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys 2011/05/14 14:57:26.0686 5676 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 2011/05/14 14:57:27.0123 5676 IPOD2CAR (197f37f729af3bd2e4c1e8ef5a95499c) C:\Windows\system32\Drivers\ipod2car.sys 2011/05/14 14:57:27.0466 5676 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 2011/05/14 14:57:27.0638 5676 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys 2011/05/14 14:57:28.0246 5676 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys 2011/05/14 14:57:28.0683 5676 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/05/14 14:57:29.0042 5676 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/05/14 14:57:29.0338 5676 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys 2011/05/14 14:57:29.0962 5676 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys 2011/05/14 14:57:30.0664 5676 lenovo.smi (9aac267a225f3caebb9e633f7eb16e4b) C:\Windows\system32\DRIVERS\smiif32.sys 2011/05/14 14:57:31.0241 5676 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/05/14 14:57:31.0756 5676 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 2011/05/14 14:57:32.0177 5676 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 2011/05/14 14:57:32.0536 5676 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2011/05/14 14:57:32.0973 5676 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2011/05/14 14:57:33.0191 5676 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 2011/05/14 14:57:33.0800 5676 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 2011/05/14 14:57:34.0190 5676 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 2011/05/14 14:57:34.0611 5676 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 2011/05/14 14:57:34.0939 5676 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 2011/05/14 14:57:35.0110 5676 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 2011/05/14 14:57:35.0547 5676 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 2011/05/14 14:57:36.0046 5676 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys 2011/05/14 14:57:36.0405 5676 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\Windows\system32\DRIVERS\MpFilter.sys 2011/05/14 14:57:36.0795 5676 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys 2011/05/14 14:57:37.0060 5676 MpKsl05e0ff50 (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsl05e0ff50.sys 2011/05/14 14:57:37.0232 5676 MpKsl19cdc5a8 (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsl19cdc5a8.sys 2011/05/14 14:57:37.0544 5676 MpKsl80cdbc1f (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsl80cdbc1f.sys 2011/05/14 14:57:37.0669 5676 MpKsl8465d98e (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsl8465d98e.sys 2011/05/14 14:57:37.0809 5676 MpKslaa3bbad1 (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKslaa3bbad1.sys 2011/05/14 14:57:38.0121 5676 MpKsle88e4bbe (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsle88e4bbe.sys 2011/05/14 14:57:38.0511 5676 MpNWMon (f32e2d6a1640a469a9ed4f1929a4a861) C:\Windows\system32\DRIVERS\MpNWMon.sys 2011/05/14 14:57:38.0683 5676 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 2011/05/14 14:57:39.0041 5676 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys 2011/05/14 14:57:39.0509 5676 mrxsmb (ed3d3419b064f28d812995ed8cadc541) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/05/14 14:57:39.0915 5676 mrxsmb10 (dc914446049169a964e27fd8888ffaee) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/05/14 14:57:40.0274 5676 mrxsmb20 (e7d90388d14fae057c166c1801e0bf94) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/05/14 14:57:40.0430 5676 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys 2011/05/14 14:57:40.0679 5676 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys 2011/05/14 14:57:41.0179 5676 MSDV (114b67c324d64c8195fd3bf93b4df02a) C:\Windows\system32\DRIVERS\msdv.sys 2011/05/14 14:57:41.0272 5676 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 2011/05/14 14:57:41.0693 5676 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 2011/05/14 14:57:42.0068 5676 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys 2011/05/14 14:57:42.0380 5676 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 2011/05/14 14:57:42.0614 5676 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/05/14 14:57:42.0692 5676 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 2011/05/14 14:57:42.0910 5676 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 2011/05/14 14:57:43.0097 5676 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys 2011/05/14 14:57:43.0285 5676 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 2011/05/14 14:57:43.0378 5676 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 2011/05/14 14:57:43.0565 5676 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 2011/05/14 14:57:43.0987 5676 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 2011/05/14 14:57:44.0455 5676 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys 2011/05/14 14:57:45.0172 5676 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 2011/05/14 14:57:45.0765 5676 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/05/14 14:57:45.0999 5676 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/05/14 14:57:46.0576 5676 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/05/14 14:57:46.0732 5676 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys 2011/05/14 14:57:46.0997 5676 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 2011/05/14 14:57:47.0278 5676 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys 2011/05/14 14:57:48.0292 5676 NETw5s32 (3577b851e59da59e6d65419a057c9914) C:\Windows\system32\DRIVERS\NETw5s32.sys 2011/05/14 14:57:49.0213 5676 netw5v32 (58218ec6b61b1169cf54aab0d00f5fe2) C:\Windows\system32\DRIVERS\netw5v32.sys 2011/05/14 14:57:50.0211 5676 NETwNs32 (83553135ad346d247c482f1b8aca921f) C:\Windows\system32\DRIVERS\NETwNs32.sys 2011/05/14 14:57:50.0773 5676 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 2011/05/14 14:57:51.0007 5676 NisDrv (17e2c08c5ecfbe94a7c67b1c275ee9d9) C:\Windows\system32\DRIVERS\NisDrvWFP.sys 2011/05/14 14:57:51.0163 5676 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 2011/05/14 14:57:51.0225 5676 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 2011/05/14 14:57:51.0365 5676 Ntfs (33c3093d09017cfe2e219f2472bff6eb) C:\Windows\system32\drivers\Ntfs.sys 2011/05/14 14:57:51.0521 5676 NuidFltr (9620a1d8160a550f064bbaf48d0f97cc) C:\Windows\system32\DRIVERS\NuidFltr.sys 2011/05/14 14:57:51.0646 5676 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 2011/05/14 14:57:51.0927 5676 nvraid (af2eec9580c1d32fb7eaf105d9784061) C:\Windows\system32\drivers\nvraid.sys 2011/05/14 14:57:52.0130 5676 nvstor (9283c58ebaa2618f93482eb5dabcec82) C:\Windows\system32\drivers\nvstor.sys 2011/05/14 14:57:52.0364 5676 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys 2011/05/14 14:57:52.0582 5676 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys 2011/05/14 14:57:52.0863 5676 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 2011/05/14 14:57:52.0941 5676 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys 2011/05/14 14:57:53.0035 5676 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 2011/05/14 14:57:53.0175 5676 PCDSRVC{3037D694-FD904ACA-06020101}_0 (92fddbed716bf5c3cb766101563cfce5) c:\program files\pc-doctor\pcdsrvc.pkms 2011/05/14 14:57:53.0596 5676 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys 2011/05/14 14:57:53.0737 5676 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys 2011/05/14 14:57:53.0924 5676 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 2011/05/14 14:57:54.0064 5676 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 2011/05/14 14:57:54.0127 5676 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 2011/05/14 14:57:54.0595 5676 Point32 (7d7a9c17d5455203dea11e5ef886cc59) C:\Windows\system32\DRIVERS\point32.sys 2011/05/14 14:57:54.0766 5676 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 2011/05/14 14:57:54.0797 5676 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 2011/05/14 14:57:54.0922 5676 psadd (72de205cd4006dc45b1401859c506679) C:\Windows\system32\DRIVERS\psadd.sys 2011/05/14 14:57:55.0031 5676 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 2011/05/14 14:57:55.0219 5676 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys 2011/05/14 14:57:55.0499 5676 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 2011/05/14 14:57:55.0889 5676 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 2011/05/14 14:57:56.0139 5676 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 2011/05/14 14:57:56.0607 5676 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 2011/05/14 14:57:56.0872 5676 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 2011/05/14 14:57:57.0028 5676 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/05/14 14:57:57.0215 5676 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/05/14 14:57:57.0496 5676 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 2011/05/14 14:57:57.0761 5676 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys 2011/05/14 14:57:57.0871 5676 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 2011/05/14 14:57:58.0105 5676 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/05/14 14:57:58.0245 5676 RDPDISPM (a862a3a8d7d2d75bdc41b556325e9876) C:\Windows\system32\DRIVERS\rdpdispm.sys 2011/05/14 14:57:58.0370 5676 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys 2011/05/14 14:57:58.0510 5676 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 2011/05/14 14:57:58.0822 5676 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 2011/05/14 14:57:59.0243 5676 RdpVideoMiniport (68a0387f58e226deee23d9715955572a) C:\Windows\system32\drivers\rdpvideominiport.sys 2011/05/14 14:57:59.0618 5676 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys 2011/05/14 14:57:59.0977 5676 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys 2011/05/14 14:58:00.0445 5676 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys 2011/05/14 14:58:00.0897 5676 rimmptsk (c2ef513bbe069f0d4ee0938a76f975d3) C:\Windows\system32\DRIVERS\rimmptsk.sys 2011/05/14 14:58:01.0349 5676 rimsptsk (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys 2011/05/14 14:58:01.0708 5676 rismxdp (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys 2011/05/14 14:58:02.0254 5676 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 2011/05/14 14:58:02.0582 5676 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys 2011/05/14 14:58:02.0925 5676 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys 2011/05/14 14:58:03.0331 5676 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys 2011/05/14 14:58:03.0705 5676 sdbus (0328be1c7f1cba23848179f8762e391c) C:\Windows\system32\drivers\sdbus.sys 2011/05/14 14:58:04.0282 5676 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/05/14 14:58:04.0688 5676 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 2011/05/14 14:58:04.0937 5676 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 2011/05/14 14:58:05.0203 5676 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 2011/05/14 14:58:05.0452 5676 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys 2011/05/14 14:58:05.0530 5676 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys 2011/05/14 14:58:05.0873 5676 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys 2011/05/14 14:58:06.0201 5676 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 2011/05/14 14:58:06.0685 5676 Shockprf (486a1bd22dd66d0a8542ebb0cd792bdb) C:\Windows\system32\DRIVERS\Apsx86.sys 2011/05/14 14:58:06.0981 5676 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys 2011/05/14 14:58:07.0355 5676 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2011/05/14 14:58:07.0761 5676 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 2011/05/14 14:58:08.0167 5676 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 2011/05/14 14:58:09.0103 5676 SNP2UVC (1ef34706531b188d1ce12127d8233e87) C:\Windows\system32\DRIVERS\snp2uvc.sys 2011/05/14 14:58:09.0446 5676 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 2011/05/14 14:58:10.0148 5676 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys 2011/05/14 14:58:10.0148 5676 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 2011/05/14 14:58:10.0163 5676 sptd - detected LockedFile.Multi.Generic (1) 2011/05/14 14:58:10.0460 5676 srv (4e636465a8653ba3bf29f929aa578e6f) C:\Windows\system32\DRIVERS\srv.sys 2011/05/14 14:58:10.0834 5676 srv2 (4e4e17a3865f650ee8c67726872d9431) C:\Windows\system32\DRIVERS\srv2.sys 2011/05/14 14:58:11.0177 5676 SrvHsfHDA (e00fdfaff025e94f9821153750c35a6d) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 2011/05/14 14:58:11.0567 5676 SrvHsfV92 (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS 2011/05/14 14:58:11.0973 5676 SrvHsfWinac (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 2011/05/14 14:58:12.0254 5676 srvnet (1346dff5be932939997d373d61a35626) C:\Windows\system32\DRIVERS\srvnet.sys 2011/05/14 14:58:12.0488 5676 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 2011/05/14 14:58:12.0550 5676 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys 2011/05/14 14:58:12.0831 5676 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys 2011/05/14 14:58:13.0112 5676 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys 2011/05/14 14:58:13.0658 5676 SynTP (d7dc30b8b41e7a913c3fccc0631e72ec) C:\Windows\system32\DRIVERS\SynTP.sys 2011/05/14 14:58:14.0017 5676 Tcpip (37e8fa3779668837ca9e2c36d2415949) C:\Windows\system32\drivers\tcpip.sys 2011/05/14 14:58:14.0375 5676 TCPIP6 (37e8fa3779668837ca9e2c36d2415949) C:\Windows\system32\DRIVERS\tcpip.sys 2011/05/14 14:58:14.0578 5676 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys 2011/05/14 14:58:14.0672 5676 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys 2011/05/14 14:58:15.0093 5676 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys 2011/05/14 14:58:15.0483 5676 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys 2011/05/14 14:58:15.0826 5676 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys 2011/05/14 14:58:16.0154 5676 TPDIGIMN (20a439d6475d6fe1909159c0143d0466) C:\Windows\system32\DRIVERS\ApsHM86.sys 2011/05/14 14:58:16.0466 5676 TPM (5ad05191dc8b444a7ba4d79b76c42a30) C:\Windows\system32\drivers\tpm.sys 2011/05/14 14:58:17.0074 5676 TPPWRIF (c16ec6a5390904d3971179553852025b) C:\Windows\system32\drivers\Tppwr32v.sys 2011/05/14 14:58:17.0620 5676 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/05/14 14:58:18.0104 5676 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys 2011/05/14 14:58:18.0712 5676 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys 2011/05/14 14:58:19.0227 5676 TVTI2C (cac5d5979850c9ad41a88033013bc806) C:\Windows\system32\DRIVERS\Tvti2c.sys 2011/05/14 14:58:19.0742 5676 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 2011/05/14 14:58:20.0272 5676 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys 2011/05/14 14:58:20.0756 5676 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys 2011/05/14 14:58:21.0130 5676 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys 2011/05/14 14:58:21.0427 5676 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 2011/05/14 14:58:21.0879 5676 USB28xxBGA (cd45a3dcc813b998b933340c3de53316) C:\Windows\system32\DRIVERS\emBDA.sys 2011/05/14 14:58:22.0207 5676 USB28xxOEM (3220a10970b5819aac56cb445db551fd) C:\Windows\system32\DRIVERS\emOEM.sys 2011/05/14 14:58:22.0441 5676 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys 2011/05/14 14:58:22.0550 5676 usbccgp (7e72e7d7e0757d59481d530fd2b0bfae) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/05/14 14:58:22.0862 5676 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys 2011/05/14 14:58:23.0080 5676 usbehci (cfbce999c057d78979a181c9c60f208e) C:\Windows\system32\drivers\usbehci.sys 2011/05/14 14:58:23.0455 5676 usbhub (9d22aad9ac6a07c691a1113e5f860868) C:\Windows\system32\drivers\usbhub.sys 2011/05/14 14:58:23.0969 5676 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 2011/05/14 14:58:24.0422 5676 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 2011/05/14 14:58:24.0968 5676 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys 2011/05/14 14:58:25.0467 5676 usbser (31181de6190b39fc8007dffd1a48ffd6) C:\Windows\system32\DRIVERS\usbser.sys 2011/05/14 14:58:25.0904 5676 USBSTOR (bf63ebfc6979fefb2bc03df7989a0c1a) C:\Windows\system32\drivers\USBSTOR.SYS 2011/05/14 14:58:26.0263 5676 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\drivers\usbuhci.sys 2011/05/14 14:58:26.0824 5676 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys 2011/05/14 14:58:27.0277 5676 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys 2011/05/14 14:58:27.0698 5676 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/05/14 14:58:28.0103 5676 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 2011/05/14 14:58:28.0868 5676 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys 2011/05/14 14:58:29.0273 5676 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys 2011/05/14 14:58:29.0663 5676 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 2011/05/14 14:58:30.0163 5676 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys 2011/05/14 14:58:30.0443 5676 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys 2011/05/14 14:58:30.0740 5676 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys 2011/05/14 14:58:31.0083 5676 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys 2011/05/14 14:58:31.0333 5676 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 2011/05/14 14:58:31.0551 5676 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys 2011/05/14 14:58:31.0879 5676 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 2011/05/14 14:58:31.0972 5676 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys 2011/05/14 14:58:32.0331 5676 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys 2011/05/14 14:58:32.0737 5676 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys 2011/05/14 14:58:32.0939 5676 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 2011/05/14 14:58:33.0189 5676 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 2011/05/14 14:58:33.0220 5676 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 2011/05/14 14:58:33.0485 5676 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 2011/05/14 14:58:33.0735 5676 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 2011/05/14 14:58:34.0078 5676 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 2011/05/14 14:58:34.0203 5676 WimFltr (f9ad3a5e3fd7e0bdb18b8202b0fdd4e4) C:\Windows\system32\DRIVERS\wimfltr.sys 2011/05/14 14:58:34.0406 5676 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 2011/05/14 14:58:35.0061 5676 WinUSB (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\drivers\WinUSB.SYS 2011/05/14 14:58:35.0607 5676 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys 2011/05/14 14:58:36.0184 5676 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/05/14 14:58:36.0621 5676 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys 2011/05/14 14:58:37.0651 5676 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/05/14 14:58:38.0056 5676 ================================================================================ 2011/05/14 14:58:38.0056 5676 Scan finished 2011/05/14 14:58:38.0056 5676 ================================================================================ 2011/05/14 14:58:38.0072 3632 Detected object count: 1 2011/05/14 14:58:54.0920 3632 LockedFile.Multi.Generic(sptd) - User select action: Skip
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Here is the log from Combofix.

ComboFix 11-05-13.03 - Travis 05/14/2011 16:51:48.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2520.1287 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk
c:\users\Travis\yload87.dll
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\Thumbs.db
Q:\Autorun.inf
S:\AUTORUN.INF
.
.
((((((((((((((((((((((((( Files Created from 2011-04-14 to 2011-05-14 )))))))))))))))))))))))))))))))
.
.
2011-05-14 20:43 . 2011-05-14 20:43 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F4723C29-29BA-433A-AD7F-DCBD682D889B}\MpKsl31053b2a.sys
2011-05-14 20:43 . 2011-04-11 07:04 7071056 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F4723C29-29BA-433A-AD7F-DCBD682D889B}\mpengine.dll
2011-05-13 02:52 . 2011-05-13 02:52 ——– d-sh–w- c:\windows\system32\%APPDATA%
2011-05-13 02:49 . 2011-05-13 02:49 ——– d—–w- c:\program files\Common Files\Java
2011-05-13 02:49 . 2011-05-13 02:49 ——– d—–w- c:\program files\MSECache
2011-05-13 02:48 . 2011-04-09 06:02 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-13 02:48 . 2011-04-09 06:02 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-28 20:44 . 2011-04-28 20:44 ——– d—–w- c:\users\Travis\AppData\Local\assembly
2011-04-28 20:41 . 2011-04-28 22:43 ——– d—–w- c:\users\Travis\AppData\Local\Temporary Projects
2011-04-20 23:47 . 2011-04-20 23:48 ——– d—–w- c:\program files\Microsoft IntelliPoint
2011-04-20 00:42 . 2011-04-20 00:42 ——– d—–w- c:\program files\Microsoft IntelliType Pro
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 09:07 . 2010-06-07 00:30 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-13 19:03 . 2011-04-13 19:03 21792 —-a-w- c:\windows\system32\drivers\nuidfltr.sys
2011-04-13 19:02 . 2011-04-13 19:02 40984 —-a-w- c:\windows\system32\drivers\point32.sys
2011-04-12 17:01 . 2011-04-12 17:01 45464 —-a-w- c:\windows\system32\drivers\dc3d.sys
2011-04-11 07:04 . 2009-12-10 12:12 7071056 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-09 03:02 . 2011-04-09 03:02 391168 —-a-w- c:\windows\system32\itpcoin815.dll
2011-04-09 03:02 . 2011-04-09 03:02 390656 —-a-w- c:\windows\system32\ipcoin815.dll
2011-03-28 21:27 . 2011-03-28 21:27 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-03-28 21:27 . 2011-03-28 21:27 86528 —-a-w- c:\windows\system32\iesysprep.dll
2011-03-28 21:27 . 2011-03-28 21:27 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-03-28 21:27 . 2011-03-28 21:27 74752 —-a-w- c:\windows\system32\iesetup.dll
2011-03-28 21:27 . 2011-03-28 21:27 63488 —-a-w- c:\windows\system32\tdc.ocx
2011-03-28 21:27 . 2011-03-28 21:27 48640 —-a-w- c:\windows\system32\mshtmler.dll
2011-03-28 21:27 . 2011-03-28 21:27 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-28 21:27 . 2011-03-28 21:27 367104 —-a-w- c:\windows\system32\html.iec
2011-03-28 21:27 . 2011-03-28 21:27 35840 —-a-w- c:\windows\system32\imgutil.dll
2011-03-28 21:27 . 2011-03-28 21:27 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-03-28 21:27 . 2011-03-28 21:27 23552 —-a-w- c:\windows\system32\licmgr10.dll
2011-03-28 21:27 . 2011-03-28 21:27 1797632 —-a-w- c:\windows\system32\jscript9.dll
2011-03-28 21:27 . 2011-03-28 21:27 161792 —-a-w- c:\windows\system32\msls31.dll
2011-03-28 21:27 . 2011-03-28 21:27 152064 —-a-w- c:\windows\system32\wextract.exe
2011-03-28 21:27 . 2011-03-28 21:27 150528 —-a-w- c:\windows\system32\iexpress.exe
2011-03-28 21:27 . 2011-03-28 21:27 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2011-03-28 21:27 . 2011-03-28 21:27 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2011-03-28 21:27 . 2011-03-28 21:27 11776 —-a-w- c:\windows\system32\mshta.exe
2011-03-28 21:27 . 2011-03-28 21:27 1126912 —-a-w- c:\windows\system32\wininet.dll
2011-03-28 21:27 . 2011-03-28 21:27 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-03-28 21:27 . 2011-03-28 21:27 101888 —-a-w- c:\windows\system32\admparse.dll
2011-03-22 21:00 . 2009-08-12 11:44 49408 —-a-w- c:\windows\system32\drivers\ipod2car.sys
2011-03-16 23:51 . 2010-06-24 15:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-16 22:44 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll
2011-03-11 05:33 . 2011-04-13 19:55 1164288 —-a-w- c:\windows\system32\mfc42u.dll
2011-03-11 05:33 . 2011-04-13 19:55 1137664 —-a-w- c:\windows\system32\mfc42.dll
2011-03-08 05:28 . 2011-04-13 19:56 741376 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-03 05:38 . 2011-04-13 19:56 132608 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:36 . 2011-04-13 19:56 28672 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-03-03 03:42 . 2011-04-13 19:55 2333184 —-a-w- c:\windows\system32\win32k.sys
2011-02-23 04:48 . 2011-04-13 19:55 311808 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-23 04:48 . 2011-04-13 19:55 310272 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-02-23 04:47 . 2011-04-13 19:55 114176 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-02-23 04:47 . 2011-04-13 19:55 223232 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-02-23 04:47 . 2011-04-13 19:55 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-02-23 04:47 . 2011-04-13 19:55 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-23 04:47 . 2011-04-13 19:55 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-02-19 06:30 . 2011-03-15 02:26 805376 —-a-w- c:\windows\system32\FntCache.dll
2011-02-19 06:30 . 2011-03-15 02:26 1076736 —-a-w- c:\windows\system32\DWrite.dll
2011-02-19 06:30 . 2011-03-15 02:26 739840 —-a-w- c:\windows\system32\d2d1.dll
2011-02-19 06:30 . 2011-04-13 19:55 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-02-19 04:34 . 2011-04-13 19:55 294912 —-a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Travis\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Travis\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Travis\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemonTool"="c:\users\TRAVIS~1\peload3E.dll" [2010-11-20 593920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe \s" [X]
"FingerPrintSoftwareSplashScreen"="c:\program files\Lenovo Fingerprint Software\SplashScreen.exe \s" [X]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-04-23 1725736]
"CreateLMBCShortCut"="c:\program files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe" [2009-05-15 40960]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-08-07 186904]
"IaNvSrv"="c:\program files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2009-10-06 33304]
"Message Center Plus"="c:\program files\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-05-28 49976]
"RoxioDragToDisc"="c:\program files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 1116920]
"TpShocks"="TpShocks.exe" [2009-12-11 337256]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PIconStartup.exe" [2010-02-04 111640]
"LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2010-07-27 62312]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-09-24 159472]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-23 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-23 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-23 170008]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-10-22 98304]
"PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2011-02-04 1254760]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-04-13 1298320]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
.
c:\users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Travis\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
scandisk.lnk - c:\windows\system32\rundll32.exe [2009-7-13 44544]
scanwdiskh21.dll [2010-11-20 581632]
scanxdiskbb36.dll [2010-11-20 593920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2009-2-20 789032]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisallowCpl"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2010-11-24 45496]
R3 ADMonitor;AD Monitor;c:\windows\system32\ADMonitor.exe [2010-10-21 106496]
R3 BTHprint;Microsoft Bluetooth Printer Class;c:\windows\system32\DRIVERS\bthprint.sys [2009-07-13 50688]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-02-27 29736]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2011-04-12 45464]
R3 IPOD2CAR;ipod2car.sys driver;c:\windows\system32\Drivers\ipod2car.sys [2011-03-22 49408]
R3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2010-03-18 6758912]
R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 PCDSRVC{3037D694-FD904ACA-06020101}_0;PCDSRVC{3037D694-FD904ACA-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc.pkms [2010-12-09 21744]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.EXE [2011-02-04 79208]
R3 RDPDISPM;RDPDISPM;c:\windows\system32\DRIVERS\rdpdispm.sys [2010-05-21 9040]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-02-26 1343400]
R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2010-09-24 268528]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 DozeHDD;DozeHDD;c:\windows\System32\DRIVERS\DozeHDD.sys [2011-02-04 25968]
S0 iaNvStor;Intel® Turbo Memory Controller;c:\windows\system32\DRIVERS\iaNvStor.sys [2009-08-21 232472]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-16 691696]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2009-10-09 20520]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2010-09-07 13680]
S1 MpKsl05e0ff50;MpKsl05e0ff50;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsl05e0ff50.sys [x]
S1 MpKsl31053b2a;MpKsl31053b2a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F4723C29-29BA-433A-AD7F-DCBD682D889B}\MpKsl31053b2a.sys [2011-05-14 28752]
S1 MpKsl80cdbc1f;MpKsl80cdbc1f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsl80cdbc1f.sys [x]
S1 MpKsl8465d98e;MpKsl8465d98e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsl8465d98e.sys [x]
S1 MpKslaa3bbad1;MpKslaa3bbad1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKslaa3bbad1.sys [x]
S1 MpKsle88e4bbe;MpKsle88e4bbe;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{430F553C-AA17-472C-B324-E9AD92342278}\MpKsle88e4bbe.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-10-23 176128]
S2 ATService;AuthenTec Fingerprint Service;c:\windows\system32\AtService.exe [2010-10-21 1824064]
S2 dtsvc;Data Transfer Service;c:\windows\system32\DTS.exe [2010-10-21 98304]
S2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [2010-07-27 50536]
S2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [2010-07-27 74088]
S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [2010-04-07 93032]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NlsSrv32.exe [2009-06-07 61440]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [2010-12-03 99328]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2010-12-02 64440]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2010-02-04 2058776]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-10-23 5882880]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-10-23 210944]
S3 ATSwpWDF;AuthenTec TruePrint USB Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2010-10-21 659968]
S3 DozeSvc;Lenovo Doze Mode Service;c:\program files\ThinkPad\Utilities\DOZESVC.EXE [2011-02-04 128360]
S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y6032.sys [2008-08-22 225408]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd32.sys [2010-10-23 8758272]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
S3 NETwNs32;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETwNs32.sys [2010-10-18 7122944]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2009-07-02 38336]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL19CDC5A8
*NewlyCreated* - MPKSL31053B2A
*Deregistered* - klmd25
*Deregistered* - MpKsl19cdc5a8
*Deregistered* - tvtfilter
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-13 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\uaclauncher.exe [2010-12-09 23:09]
.
2011-05-14 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdrcui.exe [2010-12-09 23:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bing.com/
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Switcher - c:\program files\Switcher\Switcher.exe
AddRemove-Verizon Help and Support - c:\program files\Verizon\Uninstall.exe
.
.
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
copy of MBR has been found in sector 1 !
copy of MBR has been found in sector 8 !
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{3037D694-FD904ACA-06020101}_0]
"ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-05-14 17:01:29
ComboFix-quarantined-files.txt 2011-05-14 21:01
.
Pre-Run: 106,536,849,408 bytes free
Post-Run: 106,475,278,336 bytes free
.
- - End Of File - - E56B86BF1029CF6B12EF921847B18339

Attachments:

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.







Re run aswMBR and post the new log







Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
Hi mowman, Here is the new log from aswMBR aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-14 19:16:25 —————————– 19:16:25.036 OS Version: Windows 6.1.7601 Service Pack 1 19:16:25.036 Number of processors: 2 586 0x170A 19:16:25.036 ComputerName: TRAVIS-PC UserName: Travis 19:17:14.192 Initialize success 19:17:33.006 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 19:17:33.006 Disk 0 Vendor: Size: 0MB BusType: 0 19:17:33.021 Disk 1 \Device\Harddisk1\DR1 -> \Device\RobsonImd-0 19:17:33.021 Disk 1 Vendor: Size: 1405MB BusType: 0 19:17:33.037 Disk 0 MBR read successfully 19:17:33.037 Disk 0 MBR scan 19:17:33.053 Disk 0 unknown MBR code 19:17:33.053 Disk 0 MBR hidden 19:17:33.068 Disk 0 scanning C:\Windows\system32\drivers 19:17:48.668 Service scanning 19:17:50.353 Disk 0 trace - called modules: 19:17:50.369 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys iaNvStor.sys intelppm.sys 19:17:50.384 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8875e030] 19:17:50.400 3 CLASSPNP.SYS[8a7b859e] -> nt!IofCallDriver -> [0x86345900] 19:17:50.415 5 ACPI.sys[8a0b13d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x86316028] 19:17:50.431 Scan finished successfully 19:18:20.071 Disk 0 MBR has been saved successfully to "C:\Users\Travis\Desktop\MBR.dat" 19:18:20.071 The log file has been saved successfully to "C:\Users\Travis\Desktop\aswMBR2.txt" … and here is the log from MBRCheck MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows 7 Ultimate Edition Windows Information: Service Pack 1 (build 7601), 32-bit Base Board Manufacturer: LENOVO BIOS Manufacturer: LENOVO System Manufacturer: LENOVO System Product Name: 2764CTO Logical Drives Mask: 0x00050004 Kernel Drivers (total 225): 0x8300B000 \SystemRoot\system32\ntkrnlpa.exe 0x8341D000 \SystemRoot\system32\halmacpi.dll 0x80BC0000 \SystemRoot\system32\kdcom.dll 0x8363A000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x836BF000 \SystemRoot\system32\PSHED.dll 0x836D0000 \SystemRoot\system32\BOOTVID.dll 0x836D8000 \SystemRoot\system32\CLFS.SYS 0x8371A000 \SystemRoot\system32\CI.dll 0x8A029000 \SystemRoot\system32\drivers\Wdf01000.sys 0x8A09A000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x8A0A8000 \SystemRoot\system32\drivers\ACPI.sys 0x8A0F0000 \SystemRoot\system32\drivers\WMILIB.SYS 0x8A0F9000 \SystemRoot\system32\drivers\msisadrv.sys 0x8A101000 \SystemRoot\system32\drivers\vdrvroot.sys 0x8A10C000 \SystemRoot\system32\drivers\pci.sys 0x8A136000 \SystemRoot\System32\drivers\partmgr.sys 0x8A147000 \SystemRoot\system32\drivers\volmgr.sys 0x8A157000 \SystemRoot\System32\drivers\volmgrx.sys 0x8A1A2000 \SystemRoot\system32\DRIVERS\pcmcia.sys 0x8A1D0000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x8A1D8000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x8A1E3000 \SystemRoot\System32\drivers\mountmgr.sys 0x837C5000 \SystemRoot\system32\drivers\vmbus.sys 0x8A000000 \SystemRoot\system32\drivers\winhv.sys 0x8A23C000 \SystemRoot\system32\DRIVERS\iaStor.sys 0x8A316000 \SystemRoot\system32\DRIVERS\iaNvStor.sys 0x8A361000 \SystemRoot\system32\drivers\amdxata.sys 0x8A36A000 \SystemRoot\system32\drivers\fltmgr.sys 0x8A39E000 \SystemRoot\system32\drivers\fileinfo.sys 0x8A3AF000 \SystemRoot\System32\Drivers\DRVMCDB.SYS 0x8A3C6000 \SystemRoot\System32\Drivers\PxHelp20.sys 0x8A41A000 \SystemRoot\System32\Drivers\Ntfs.sys 0x8A549000 \SystemRoot\System32\Drivers\msrpc.sys 0x8A574000 \SystemRoot\System32\Drivers\ksecdd.sys 0x8A587000 \SystemRoot\System32\Drivers\cng.sys 0x8A5E4000 \SystemRoot\System32\drivers\pcw.sys 0x8A5F2000 \SystemRoot\System32\DRIVERS\DozeHDD.sys 0x8A5F7000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x8A612000 \SystemRoot\system32\drivers\ndis.sys 0x8A6C9000 \SystemRoot\system32\drivers\NETIO.SYS 0x8A707000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x8A836000 \SystemRoot\System32\drivers\tcpip.sys 0x8A980000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x8A9B1000 \SystemRoot\system32\drivers\vmstorfl.sys 0x8A9BA000 \SystemRoot\system32\drivers\volsnap.sys 0x8A800000 \SystemRoot\System32\DRIVERS\ApsHM86.sys 0x8A809000 \SystemRoot\System32\Drivers\spldr.sys 0x8A72C000 \SystemRoot\System32\drivers\rdyboost.sys 0x8A811000 \SystemRoot\System32\DRIVERS\Apsx86.sys 0x8A759000 \SystemRoot\System32\Drivers\mup.sys 0x8A769000 \SystemRoot\System32\drivers\hwpolicy.sys 0x8A771000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x8A7A3000 \SystemRoot\system32\DRIVERS\disk.sys 0x8A7B4000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x8F119000 \SystemRoot\system32\DRIVERS\MpFilter.sys 0x8F140000 \SystemRoot\System32\Drivers\DLACDBHM.SYS 0x8F142000 \SystemRoot\System32\Drivers\Null.SYS 0x8F149000 \SystemRoot\System32\Drivers\Beep.SYS 0x8F150000 \SystemRoot\System32\Drivers\DLARTL_M.SYS 0x8F156000 \SystemRoot\System32\drivers\vga.sys 0x8F162000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8F183000 \SystemRoot\System32\drivers\watchdog.sys 0x8F190000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8F198000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8F1A0000 \SystemRoot\system32\drivers\rdprefmp.sys 0x8F1A8000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8F1B3000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8F1C1000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8F1D8000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8F427000 \SystemRoot\system32\drivers\afd.sys 0x8F481000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8F4B3000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x8F4BA000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8F4D9000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x8F4EA000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8F4F8000 \SystemRoot\system32\DRIVERS\serial.sys 0x8F512000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8F525000 \SystemRoot\System32\drivers\Tppwr32v.sys 0x8F52C000 \SystemRoot\system32\drivers\termdd.sys 0x8F53D000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8F57E000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8F588000 \SystemRoot\system32\drivers\mssmbios.sys 0x8F592000 \SystemRoot\system32\DRIVERS\smiif32.sys 0x8F594000 \SystemRoot\System32\drivers\discache.sys 0x8FE25000 \SystemRoot\system32\drivers\csc.sys 0x8FE89000 \SystemRoot\System32\Drivers\dfsc.sys 0x8FEA1000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x8FEAF000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8FED0000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x8FEE2000 \SystemRoot\system32\DRIVERS\atikmpag.sys 0x9080F000 \SystemRoot\system32\DRIVERS\atikmdag.sys 0x9862E000 \SystemRoot\system32\DRIVERS\igdpmd32.sys 0x98F0A000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x98FC1000 \SystemRoot\System32\drivers\dxgmms1.sys 0x98600000 \SystemRoot\system32\DRIVERS\HECI.sys 0x9860A000 \SystemRoot\system32\DRIVERS\serenum.sys 0x8FF1B000 \SystemRoot\system32\DRIVERS\e1y6032.sys 0x98614000 \SystemRoot\system32\drivers\usbuhci.sys 0x8FF55000 \SystemRoot\system32\drivers\USBPORT.SYS 0x9861F000 \SystemRoot\system32\drivers\usbehci.sys 0x8FFA0000 \SystemRoot\system32\drivers\HDAudBus.sys 0x99C28000 \SystemRoot\system32\DRIVERS\NETwNs32.sys 0x9A2FD000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x9A307000 \SystemRoot\system32\drivers\1394ohci.sys 0x9A334000 \SystemRoot\system32\drivers\sdbus.sys 0x9A34D000 \SystemRoot\system32\DRIVERS\rimmptsk.sys 0x9A35E000 \SystemRoot\system32\DRIVERS\rimsptsk.sys 0x9A372000 \SystemRoot\system32\DRIVERS\rixdptsk.sys 0x9A3C4000 \SystemRoot\system32\drivers\i8042prt.sys 0x9A3DC000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8FFBF000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x9A3E9000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x9A3EB000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x99C00000 \SystemRoot\system32\drivers\tpm.sys 0x99C0C000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x99C10000 \SystemRoot\system32\DRIVERS\ibmpmdrv.sys 0x99C17000 \SystemRoot\system32\drivers\wmiacpi.sys 0x90800000 \SystemRoot\system32\drivers\CompositeBus.sys 0x8FE00000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x8F5A0000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8FE12000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8F5B8000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8F5DA000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8F400000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8F1E4000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8F417000 \SystemRoot\system32\DRIVERS\rdpbus.sys 0x99C20000 \SystemRoot\system32\DRIVERS\psadd.sys 0x9A3F8000 \SystemRoot\system32\DRIVERS\Tvti2c.sys 0x98FFA000 \SystemRoot\system32\drivers\swenum.sys 0x8A200000 \SystemRoot\system32\drivers\ks.sys 0x8F5F2000 \SystemRoot\system32\drivers\umbus.sys 0x8220C000 \SystemRoot\system32\drivers\usbhub.sys 0x82250000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x82261000 \SystemRoot\system32\drivers\HdAudio.sys 0x822B1000 \SystemRoot\system32\drivers\portcls.sys 0x822E0000 \SystemRoot\system32\drivers\drmk.sys 0x822F9000 \SystemRoot\system32\DRIVERS\VSTAZL3.SYS 0x82600000 \SystemRoot\system32\DRIVERS\VSTDPV3.SYS 0x82702000 \SystemRoot\system32\DRIVERS\VSTCNXT3.SYS 0x827B7000 \SystemRoot\system32\drivers\modem.sys 0x9AC70000 \SystemRoot\System32\win32k.sys 0x827C4000 \SystemRoot\System32\drivers\Dxapi.sys 0x827CE000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8F000000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0x827DB000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x827EC000 \SystemRoot\system32\DRIVERS\monitor.sys 0x9AED0000 \SystemRoot\System32\TSDDD.dll 0x9AF00000 \SystemRoot\System32\cdd.dll 0x9AF20000 \SystemRoot\System32\ATMFD.DLL 0x82336000 \SystemRoot\System32\Drivers\ATSwpWDF.sys 0x9142C000 \SystemRoot\system32\DRIVERS\snp2uvc.sys 0x915D9000 \SystemRoot\system32\DRIVERS\STREAM.SYS 0x915E7000 \SystemRoot\system32\DRIVERS\sncduvc.SYS 0x91400000 \SystemRoot\system32\drivers\luafv.sys 0x9141B000 \SystemRoot\System32\Drivers\DRVNDDM.SYS 0x91426000 \SystemRoot\System32\DLA\DLADResM.SYS 0x823D7000 \SystemRoot\System32\DLA\DLAIFS_M.SYS 0x91427000 \SystemRoot\System32\DLA\DLAOPIOM.SYS 0x915EF000 \SystemRoot\System32\DLA\DLAPoolM.SYS 0x8F0DA000 \SystemRoot\system32\drivers\WudfPf.sys 0x915F1000 \SystemRoot\System32\DLA\DLABMFSM.SYS 0x915F8000 \SystemRoot\System32\DLA\DLABOIOM.SYS 0x8A7E6000 \SystemRoot\System32\DLA\DLAUDFAM.SYS 0x8A400000 \SystemRoot\System32\DLA\DLAUDF_M.SYS 0x823EF000 \SystemRoot\system32\DRIVERS\lltdio.sys 0xB0A18000 \SystemRoot\system32\DRIVERS\nwifi.sys 0xB0A5E000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xB0A6E000 \SystemRoot\system32\DRIVERS\rspndr.sys 0xB0A81000 \SystemRoot\system32\drivers\HTTP.sys 0xB0B06000 \SystemRoot\system32\DRIVERS\bowser.sys 0xB0B1F000 \SystemRoot\System32\drivers\mpsdrv.sys 0xB0B31000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xB0B54000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0xB0B8F000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0xB0BC2000 \SystemRoot\system32\DRIVERS\vwifimp.sys 0xB6E1A000 \SystemRoot\system32\drivers\peauth.sys 0xB6EB1000 \SystemRoot\System32\Drivers\secdrv.SYS 0xB6EBB000 \SystemRoot\System32\DRIVERS\srvnet.sys 0xB6EDC000 \SystemRoot\System32\drivers\tcpipreg.sys 0xB6EED000 \SystemRoot\System32\DRIVERS\srv2.sys 0xB6F3D000 \SystemRoot\System32\DRIVERS\srv.sys 0xB6F8F000 \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{94E04EAB-4FAA-4F87-9FAF-61CACD70B397}\MpKsl4f970464.sys 0xB6F95000 \SystemRoot\System32\Drivers\fastfat.SYS 0xB6FCB000 \??\C:\Users\TRAVIS\AppData\Local\Temp\aswMBR.sys 0xC4821000 \SystemRoot\system32\drivers\spsys.sys 0xC488B000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0x77720000 \Windows\System32\ntdll.dll 0x47880000 \Windows\System32\smss.exe 0x77960000 \Windows\System32\apisetschema.dll 0x00C30000 \Windows\System32\autochk.exe 0x77940000 \Windows\System32\psapi.dll 0x77870000 \Windows\System32\msctf.dll 0x775C0000 \Windows\System32\ole32.dll 0x77520000 \Windows\System32\usp10.dll 0x77440000 \Windows\System32\kernel32.dll 0x773F0000 \Windows\System32\Wldap32.dll 0x77340000 \Windows\System32\msvcrt.dll 0x772F0000 \Windows\System32\gdi32.dll 0x772B0000 \Windows\System32\ws2_32.dll 0x77200000 \Windows\System32\rpcrt4.dll 0x77170000 \Windows\System32\clbcatq.dll 0x77050000 \Windows\System32\wininet.dll 0x77020000 \Windows\System32\imagehlp.dll 0x76FC0000 \Windows\System32\difxapi.dll 0x76EF0000 \Windows\System32\user32.dll 0x77860000 \Windows\System32\nsi.dll 0x76EE0000 \Windows\System32\lpk.dll 0x76DD0000 \Windows\System32\urlmon.dll 0x76DC0000 \Windows\System32\normaliz.dll 0x76D60000 \Windows\System32\shlwapi.dll 0x76110000 \Windows\System32\shell32.dll 0x75F50000 \Windows\System32\iertutil.dll 0x75DB0000 \Windows\System32\setupapi.dll 0x75D10000 \Windows\System32\advapi32.dll 0x75C80000 \Windows\System32\oleaut32.dll 0x75C60000 \Windows\System32\sechost.dll 0x75BE0000 \Windows\System32\comdlg32.dll 0x75BC0000 \Windows\System32\imm32.dll 0x75BA0000 \Windows\System32\devobj.dll 0x75B70000 \Windows\System32\wintrust.dll 0x75A50000 \Windows\System32\crypt32.dll 0x759C0000 \Windows\System32\comctl32.dll 0x75970000 \Windows\System32\KernelBase.dll 0x75940000 \Windows\System32\cfgmgr32.dll 0x75930000 \Windows\System32\msasn1.dll Processes (total 102): 0 System Idle Process 4 System 372 C:\Windows\System32\smss.exe 508 csrss.exe 560 C:\Windows\System32\wininit.exe 572 csrss.exe 608 C:\Windows\System32\services.exe 624 C:\Windows\System32\lsass.exe 632 C:\Windows\System32\lsm.exe 716 C:\Windows\System32\winlogon.exe 776 C:\Windows\System32\svchost.exe 864 C:\Windows\System32\DTS.exe 888 C:\Windows\System32\ibmpmsvc.exe 928 C:\Windows\System32\AtService.exe 976 C:\Windows\System32\svchost.exe 1024 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe 1112 C:\Windows\System32\atiesrxx.exe 1172 C:\Windows\System32\svchost.exe 1260 C:\Windows\System32\svchost.exe 1288 C:\Windows\System32\svchost.exe 1368 C:\Windows\System32\audiodg.exe 1444 C:\Windows\System32\svchost.exe 1552 C:\Windows\System32\atieclxx.exe 1684 C:\Windows\System32\svchost.exe 1856 C:\Windows\System32\wlanext.exe 1864 C:\Windows\System32\conhost.exe 1964 C:\Windows\System32\spoolsv.exe 520 C:\Windows\System32\svchost.exe 1284 C:\Program Files\Lenovo\HOTKEY\tphkload.exe 1528 C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe 1796 C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe 1744 C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe 2028 C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 2124 C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe 2204 C:\Windows\System32\dwm.exe 2212 C:\Windows\System32\taskhost.exe 2264 C:\Windows\explorer.exe 2336 C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe 2408 C:\Program Files\Lenovo\ZOOM\TpScrex.exe 2588 C:\Program Files\Lenovo\Communications Utility\CamMute.exe 2636 C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe 2672 C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe 2724 C:\PROGRA~1\Lenovo\VIRTSCRL\virtscrl.exe 2752 C:\Windows\System32\NlsSrv32.exe 2804 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 2844 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2900 C:\Windows\System32\svchost.exe 2948 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE 3108 C:\Program Files\Intel\WiFi\bin\EvtEng.exe 3156 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE 3200 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe 3520 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe 3568 unsecapp.exe 3664 WmiPrvSE.exe 3940 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 3960 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe 3968 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe 4000 C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe 4008 C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe 4032 C:\Windows\System32\TpShocks.exe 2132 C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe 2444 C:\Program Files\Zune\ZuneLauncher.exe 112 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe 1648 C:\Program Files\Microsoft Security Client\msseces.exe 2556 C:\Windows\System32\igfxtray.exe 3256 C:\Windows\System32\hkcmd.exe 3288 C:\Windows\System32\igfxpers.exe 3764 C:\Windows\System32\rundll32.exe 3888 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 4028 C:\Program Files\Microsoft IntelliType Pro\itype.exe 1752 C:\Program Files\Microsoft IntelliPoint\ipoint.exe 1776 C:\Windows\System32\rundll32.exe 808 C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe 4068 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe 1920 C:\Users\Travis\AppData\Roaming\Dropbox\bin\Dropbox.exe 4208 C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE 4544 C:\Windows\System32\SearchIndexer.exe 4628 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe 4852 C:\PROGRA~1\ThinkPad\UTILIT~1\SCHTASK.EXE 4900 C:\Windows\System32\igfxext.exe 5164 C:\Windows\System32\igfxsrvc.exe 5180 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 5656 C:\Windows\System32\svchost.exe 5720 C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE 5772 C:\Windows\System32\svchost.exe 5820 C:\Program Files\Windows Media Player\wmpnetwk.exe 2180 C:\Windows\System32\SearchProtocolHost.exe 5068 C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe 380 C:\Program Files\Intel\AMT\LMS.exe 3808 C:\Windows\System32\sppsvc.exe 3812 C:\Program Files\Lenovo\System Update\SUService.exe 4272 C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe 5876 C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe 180 C:\Windows\servicing\TrustedInstaller.exe 3216 C:\Windows\System32\notepad.exe 2036 C:\Windows\System32\wuauclt.exe 3584 C:\Windows\System32\SearchFilterHost.exe 3564 dllhost.exe 1896 dllhost.exe 1524 C:\Users\Travis\Desktop\MBRCheck.exe 5096 C:\Windows\System32\conhost.exe 2680 C:\Windows\System32\dllhost.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`5dc00000 (NTFS) \\.\Q: –> \\.\PhysicalDrive0 at offset 0x00000048`14c00000 (NTFS) \\.\S: –> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS) PhysicalDrive0 Model Number: HITACHIHTS543232L9SA00, Rev: FB4ZC4EC Size Device Name MBR Status ——————————————– 298 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: C726DB20F04911E4394A2CB9ED1A318C9655E501 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Alright, I re-ran aswMBR and selected FixMBR. Here is the log from that. aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-14 19:45:17 —————————– 19:45:17.900 OS Version: Windows 6.1.7601 Service Pack 1 19:45:17.900 Number of processors: 2 586 0x170A 19:45:17.900 ComputerName: TRAVIS-PC UserName: Travis 19:45:19.476 Initialize success 19:46:28.662 Disk 0 Windows 601 MBR fixed successfully 19:46:51.001 Disk 0 MBR has been saved successfully to "C:\Users\Travis\Desktop\MBR.dat" 19:46:51.001 The log file has been saved successfully to "C:\Users\Travis\Desktop\aswMBR3.txt"
Can you run a aswMBR scan one more time and post the log please




Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please








Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.






After running these scans,please tell me how the computer is running now.
Here is the log from aswMBR aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-14 20:06:02 —————————– 20:06:02.789 OS Version: Windows 6.1.7601 Service Pack 1 20:06:02.789 Number of processors: 2 586 0x170A 20:06:02.790 ComputerName: TRAVIS-PC UserName: Travis 20:06:06.491 Initialize success 20:06:15.993 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 20:06:15.995 Disk 0 Vendor: Size: 0MB BusType: 0 20:06:15.997 Disk 1 \Device\Harddisk1\DR1 -> \Device\RobsonImd-0 20:06:15.999 Disk 1 Vendor: Size: 1405MB BusType: 0 20:06:16.012 Disk 0 MBR read successfully 20:06:16.014 Disk 0 MBR scan 20:06:16.017 Disk 0 Windows 7 default MBR code 20:06:16.019 Disk 0 MBR hidden 20:06:16.023 Disk 0 scanning C:\Windows\system32\drivers 20:06:22.206 Service scanning 20:06:23.392 Disk 0 trace - called modules: 20:06:23.423 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys iaNvStor.sys 20:06:23.423 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8875e030] 20:06:23.423 3 CLASSPNP.SYS[8a7b859e] -> nt!IofCallDriver -> [0x86345900] 20:06:23.423 5 ACPI.sys[8a0b13d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x86316028] 20:06:23.439 Scan finished successfully 20:06:36.886 Disk 0 MBR has been saved successfully to "C:\Users\Travis\Desktop\MBR.dat" 20:06:36.886 The log file has been saved successfully to "C:\Users\Travis\Desktop\aswMBR4.txt" …and the log from Malwarebytes Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6580 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 5/14/2011 8:21:34 PM mbam-log-2011-05-14 (20-21-34).txt Scan type: Quick scan Objects scanned: 163338 Time elapsed: 2 minute(s), 54 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl\1 (Malware.Trace) -> Value: 1 -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NvCplDaemonTool (Trojan.Agent.WIMP) -> Value: NvCplDaemonTool -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Users\travis\AppData\Roaming\microsoft\Windows\start menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Users\travis\peload3E.dll (Trojan.Agent.WIMP) -> Delete on reboot. .. and last the log from ESET C:\Qoobox\Quarantine\C\Users\Travis\yload87.dll.vir a variant of Win32/Kryptik.NAD trojan cleaned by deleting - quarantined C:\Users\Travis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2ZP3RLX9\QQkFBwQEAgABBQEHEkcJBQcEAAUHAgYBBw==[1].htm JS/Exploit.Agent.NCQ trojan cleaned by deleting - quarantined C:\Users\Travis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\7e1a1108-7838b4cd a variant of Win32/Kryptik.NAD trojan cleaned by deleting - quarantined C:\Users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scanwdiskh21.dll a variant of Win32/Kryptik.NAD trojan cleaned by deleting - quarantined My computer seems to be running much better and the searches are working normally again!! The only problem that I am experiencing is that when the computer starts, I get a RunDLL message box that tells me that there was a problem starting peload3E.dll.

I get a RunDLL message box that tells me that there was a problem starting peload3E.dll.

c:\Users\travis\peload3E.dll (Trojan.Agent.WIMP) -> Delete on reboot.

Run MBAM again and make sure that entry has gone,then reboot and see if that error has gone away.Also post a new OTL log please.
I re-ran MBAM and it found a registry entry. I fixed it and I no longer get the error!!

Here is the log from that

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6580

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

5/15/2011 10:10:45 AM
mbam-log-2011-05-15 (10-10-45).txt

Scan type: Quick scan
Objects scanned: 162792
Time elapsed: 5 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NvCplDaemonTool (Trojan.Agent.WIMP) -> Value: NvCplDaemonTool -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




And here is the new log from OTL

OTL logfile created on: 5/15/2011 10:29:13 AM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Travis\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
5.00 Gb Paging File | 3.00 Gb Available in Paging File | 66.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.86 Gb Total Space | 98.91 Gb Free Space | 34.48% Space Free | Partition Type: NTFS
Drive Q: | 9.77 Gb Total Space | 2.38 Gb Free Space | 24.34% Space Free | Partition Type: NTFS
Drive S: | 1.46 Gb Total Space | 0.77 Gb Free Space | 52.70% Space Free | Partition Type: NTFS

Computer Name: TRAVIS-PC | User Name: Travis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Travis\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10o_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
PRC - C:\Program Files\ThinkPad\Utilities\SCHTASK.EXE (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Windows\System32\DTS.exe ()
PRC - C:\Windows\System32\AtService.exe (AuthenTec, Inc.)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe (Lenovo Group Limited)
PRC - C:\Users\Travis\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
PRC - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files\Intel\AMT\LMS.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Windows\System32\NlsSrv32.exe (Nalpeiron Ltd.)
PRC - C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe ()
PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe (Roxio)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (SafeList) ==========

MOD - C:\Users\Travis\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\fms.dll (Windows ® Codename Longhorn DDK provider)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (SUService) – C:\Program Files\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
SRV - (DozeSvc) – C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
SRV - (Power Manager DBC Service) – C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE (Lenovo)
SRV - (TPHKLOAD) – C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited)
SRV - (TPHKSVC) – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) – C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (dtsvc) – C:\Windows\System32\DTS.exe ()
SRV - (ADMonitor) – C:\Windows\System32\ADMonitor.exe ()
SRV - (ATService) – C:\Windows\System32\AtService.exe (AuthenTec, Inc.)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (ZuneWlanCfgSvc) – C:\Windows\System32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) – c:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (LENOVO.TPKNRSVC) – C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.CAMMUTE) – C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited)
SRV - (Lenovo.VIRTSCRLSVC) – C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe (Lenovo Group Limited)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files\Intel\AMT\LMS.exe (Intel Corporation)
SRV - (ThinkVantage Registry Monitor Service) – C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (nlsX86cc) – C:\Windows\System32\NlsSrv32.exe (Nalpeiron Ltd.)
SRV - (btwdins) – C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (RoxMediaDB10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (BcmSqlStartupSvc) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (dc3d) MS Hardware Device Detection Driver (USB) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (IPOD2CAR) – C:\Windows\System32\drivers\ipod2car.sys (Windows ® 2000 DDK provider)
DRV - (DozeHDD) – C:\Windows\System32\DRIVERS\DozeHDD.sys (Lenovo.)
DRV - (TPPWRIF) – C:\Windows\System32\drivers\TPPWR32V.SYS (Lenovo Group Limited)
DRV - (PCDSRVC{3037D694-FD904ACA-06020101}_0) – c:\Program Files\PC-Doctor\pcdsrvc.pkms (PC-Doctor, Inc.)
DRV - (vmbus) – C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (WinUSB) – C:\Windows\system32\drivers\WinUSB.SYS (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (intelkmd) – C:\Windows\System32\drivers\igdpmd32.sys (Intel Corporation)
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (ATSwpWDF) – C:\Windows\System32\drivers\ATSwpWDF.sys (AuthenTec, Inc.)
DRV - (NETwNs32) ___ Intel® – C:\Windows\System32\drivers\NETwNs32.sys (Intel Corporation)
DRV - (lenovo.smi) – C:\Windows\System32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (RDPDISPM) – C:\Windows\System32\drivers\rdpdispm.sys (Microsoft Corporation)
DRV - (NETw5s32) Intel® – C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation)
DRV - (psadd) – C:\Windows\System32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (Shockprf) – C:\Windows\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\Windows\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (iaNvStor) Intel® – C:\Windows\system32\DRIVERS\iaNvStor.sys (Intel Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (BTHprint) – C:\Windows\System32\drivers\BTHPRINT.SYS (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (netw5v32) Intel® – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (TVTI2C) – C:\Windows\System32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (HECI) Intel® – C:\Windows\System32\drivers\HECI.sys (Intel Corporation)
DRV - (WimFltr) – C:\Windows\System32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\Windows\System32\drivers\snp2uvc.sys ()
DRV - (USB28xxBGA) – C:\Windows\System32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM) – C:\Windows\System32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (e1yexpress) Intel® – C:\Windows\System32\drivers\e1y6032.sys (Intel Corporation)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (DLADResM) – C:\Windows\System32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\Windows\System32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDFAM) – C:\Windows\System32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\Windows\System32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAOPIOM) – C:\Windows\System32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\Windows\System32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\Windows\System32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\Windows\System32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\Windows\System32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\Windows\System32\drivers\DLACDBHM.SYS (Roxio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========




O1 HOSTS File: ([2011/05/14 17:00:02 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O4 - HKLM..\Run: [CreateLMBCShortCut] C:\Program Files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe ()
O4 - HKLM..\Run: [FingerPrintSoftware] C:\Program Files\Lenovo Fingerprint Software\fpapp.exe (AuthenTec)
O4 - HKLM..\Run: [FingerPrintSoftwareSplashScreen] C:\Program Files\Lenovo Fingerprint Software\SplashScreen.exe (AuthenTec, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe (Intel Corporation)
O4 - HKLM..\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [picon] C:\Program Files\Common Files\Intel\Privacy Icon\PIconStartup.exe ()
O4 - HKLM..\Run: [PWMTRV] C:\Program Files\ThinkPad\Utilities\PWMTR32V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Travis\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Users\Travis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scanxdiskbb36.dll (Comp)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…20Installer.cab (Support.com Configuration Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O24 - Desktop WallPaper: C:\SWTOOLS\Wallpaper\ThinkDots1680x1050.jpg
O24 - Desktop BackupWallPaper: C:\SWTOOLS\Wallpaper\ThinkDots1680x1050.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/14 20:10:29 | 000,000,000 | —D | C] – C:\Users\Travis\AppData\Roaming\Malwarebytes
[2011/05/14 20:09:36 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/14 20:09:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/14 20:09:36 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/14 20:09:33 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/05/14 20:09:33 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/14 20:08:28 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\Travis\Desktop\mbam-setup-1.50.1.1100.exe
[2011/05/14 17:01:32 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/05/14 17:01:31 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/05/14 16:49:49 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/05/14 16:49:49 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/05/14 16:49:49 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/05/14 16:49:40 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/05/14 16:49:40 | 000,000,000 | —D | C] – C:\ComboFix
[2011/05/14 16:48:23 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/14 16:48:09 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2011/05/14 14:56:21 | 000,000,000 | —D | C] – C:\Users\Travis\Desktop\tdsskiller
[2011/05/13 21:27:10 | 000,589,632 | —- | C] (AVAST Software) – C:\Users\Travis\Desktop\aswMBR.exe
[2011/05/13 16:28:03 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Travis\Desktop\OTL.exe
[2011/05/13 13:21:28 | 001,407,280 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Travis\Desktop\TDSSKiller.exe
[2011/05/12 22:52:45 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/05/12 22:52:06 | 000,000,000 | -HSD | C] – C:\Windows\System32\%APPDATA%
[2011/05/12 22:49:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/05/12 22:49:10 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2011/05/12 22:48:56 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/05/12 22:48:56 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/05/12 22:48:56 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/05/12 22:48:04 | 003,967,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/05/12 22:48:04 | 003,912,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/04/29 23:23:26 | 000,000,000 | —D | C] – C:\Users\Travis\Documents\gegl-0.0
[2011/04/28 16:44:17 | 000,000,000 | —D | C] – C:\Users\Travis\AppData\Local\assembly
[2011/04/28 16:41:36 | 000,000,000 | —D | C] – C:\Users\Travis\AppData\Local\Temporary Projects
[2011/04/27 17:07:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/04/20 19:48:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse
[2011/04/20 19:47:56 | 000,000,000 | —D | C] – C:\Program Files\Microsoft IntelliPoint
[2011/04/19 20:43:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Keyboard
[2011/04/19 20:42:38 | 000,000,000 | —D | C] – C:\Program Files\Microsoft IntelliType Pro
[2011/01/20 21:12:02 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2009/08/04 22:50:02 | 000,225,280 | —- | C] ( ) – C:\Windows\System32\rsnp2uvc.dll
[2009/08/04 22:50:02 | 000,176,128 | —- | C] ( ) – C:\Windows\System32\csnp2uvc.dll
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/15 10:21:33 | 000,011,104 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/15 10:21:33 | 000,011,104 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/15 10:13:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/15 10:13:43 | 1981,816,832 | -HS- | M] () – C:\hiberfil.sys
[2011/05/15 10:03:34 | 000,000,382 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/05/14 22:42:51 | 000,665,084 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/14 22:42:51 | 000,122,820 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/14 20:09:36 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/14 20:08:36 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Travis\Desktop\mbam-setup-1.50.1.1100.exe
[2011/05/14 20:06:36 | 000,000,512 | —- | M] () – C:\Users\Travis\Desktop\MBR.dat
[2011/05/14 19:07:44 | 000,000,020 | —- | M] () – C:\Users\Travis\defogger_reenable
[2011/05/14 19:06:41 | 000,080,384 | —- | M] () – C:\Users\Travis\Desktop\MBRCheck.exe
[2011/05/14 19:06:23 | 000,050,477 | —- | M] () – C:\Users\Travis\Desktop\Defogger.exe
[2011/05/14 17:00:02 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/05/14 16:43:48 | 004,347,991 | R— | M] () – C:\Users\Travis\Desktop\ComboFix.exe
[2011/05/14 14:56:26 | 001,407,280 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Travis\Desktop\TDSSKiller.exe
[2011/05/14 14:56:12 | 001,280,208 | —- | M] () – C:\Users\Travis\Desktop\tdsskiller.zip
[2011/05/13 21:27:11 | 000,589,632 | —- | M] (AVAST Software) – C:\Users\Travis\Desktop\aswMBR.exe
[2011/05/13 16:28:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Travis\Desktop\OTL.exe
[2011/05/12 22:35:59 | 000,000,528 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/04/29 23:24:31 | 000,001,496 | —- | M] () – C:\Users\Travis\.recently-used.xbel
[2011/04/29 22:45:39 | 000,026,977 | —- | M] () – C:\Users\Travis\Documents\bookmark.htm
[2011/04/27 19:12:37 | 000,465,288 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/14 20:09:36 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/14 19:07:24 | 000,000,020 | —- | C] () – C:\Users\Travis\defogger_reenable
[2011/05/14 19:06:41 | 000,080,384 | —- | C] () – C:\Users\Travis\Desktop\MBRCheck.exe
[2011/05/14 19:06:23 | 000,050,477 | —- | C] () – C:\Users\Travis\Desktop\Defogger.exe
[2011/05/14 16:49:49 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/05/14 16:49:49 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/05/14 16:49:49 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/05/14 16:49:49 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/05/14 16:49:49 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/05/14 16:44:29 | 004,347,991 | R— | C] () – C:\Users\Travis\Desktop\ComboFix.exe
[2011/05/14 14:55:59 | 001,280,208 | —- | C] () – C:\Users\Travis\Desktop\tdsskiller.zip
[2011/05/13 21:33:08 | 000,000,512 | —- | C] () – C:\Users\Travis\Desktop\MBR.dat
[2011/04/29 23:24:31 | 000,001,496 | —- | C] () – C:\Users\Travis\.recently-used.xbel
[2011/04/29 22:45:39 | 000,026,977 | —- | C] () – C:\Users\Travis\Documents\bookmark.htm
[2011/03/16 18:27:16 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2011/03/16 18:24:19 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/01/20 21:12:03 | 000,982,240 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2011/01/20 21:12:03 | 000,208,896 | —- | C] () – C:\Windows\System32\iglhsip32.dll
[2011/01/20 21:12:03 | 000,143,360 | —- | C] () – C:\Windows\System32\iglhcp32.dll
[2011/01/20 21:12:02 | 000,092,356 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2011/01/20 21:12:01 | 000,439,308 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2011/01/20 21:12:00 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config
[2011/01/20 21:11:59 | 000,002,857 | —- | C] () – C:\Windows\System32\atipblag.dat
[2011/01/20 21:11:57 | 000,205,156 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2010/10/21 03:07:36 | 000,098,304 | —- | C] () – C:\Windows\System32\DTS.exe
[2010/10/21 03:07:32 | 000,106,496 | —- | C] () – C:\Windows\System32\ADMonitor.exe
[2010/08/04 20:54:22 | 000,303,104 | —- | C] () – C:\Windows\System32\glew32.dll
[2010/04/13 22:28:42 | 000,007,602 | —- | C] () – C:\Users\Travis\AppData\Local\Resmon.ResmonCfg
[2010/03/23 15:08:42 | 000,000,600 | —- | C] () – C:\Users\Travis\AppData\Local\PUTTY.RND
[2010/03/22 23:45:16 | 000,000,600 | —- | C] () – C:\Users\Travis\AppData\Roaming\winscp.rnd
[2009/12/25 11:16:06 | 000,013,312 | —- | C] () – C:\Users\Travis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/09 01:15:53 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/12/08 03:25:22 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2009/12/07 23:43:05 | 000,134,592 | —- | C] () – C:\Windows\System32\igfcg500.bin
[2009/08/04 23:44:54 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/08/04 23:05:08 | 000,056,056 | —- | C] () – C:\Windows\System32\DLAAPI_W.DLL
[2009/08/04 23:05:08 | 000,000,120 | —- | C] () – C:\Windows\wininit.ini
[2009/08/04 23:02:52 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2009/08/04 23:02:52 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2009/08/04 23:02:52 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2009/08/04 23:02:52 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2009/08/04 23:02:52 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2009/08/04 23:02:52 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2009/08/04 22:50:02 | 001,754,368 | —- | C] () – C:\Windows\System32\drivers\snp2uvc.sys
[2009/08/04 22:50:02 | 000,028,800 | —- | C] () – C:\Windows\System32\drivers\sncduvc.sys
[2009/08/04 22:50:02 | 000,015,497 | —- | C] () – C:\Windows\snp2uvc.ini
[2009/08/04 22:37:18 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2009/08/04 22:14:22 | 000,016,896 | —- | C] () – C:\Windows\Eventclr.exe
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/14 00:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,465,288 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,665,084 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,122,820 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/06/04 16:51:10 | 000,000,542 | —- | C] () – C:\Windows\System32\atipblup.dat

========== LOP Check ==========

[2010/12/09 17:59:33 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\Arduino
[2010/08/09 20:56:04 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\Audacity
[2010/05/03 12:55:27 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\avidemux
[2009/12/08 04:59:28 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\Bao_Nguyen
[2011/02/04 00:41:29 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\Blender Foundation
[2010/03/25 12:03:09 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\Blue Cat Audio
[2010/02/09 16:24:51 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\Bundysoft
[2011/03/16 20:53:35 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\CachedFiles
[2010/11/06 10:21:15 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\CVS
[2010/08/15 21:31:25 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\DAEMON Tools Lite
[2010/11/12 19:20:57 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\DAZ 3D
[2011/05/15 10:14:54 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\Dropbox
[2011/01/12 00:49:18 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\gtk-2.0
[2010/03/25 12:03:22 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\HighAndes
[2011/03/02 22:32:43 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\inkscape
[2009/12/08 05:54:36 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\InterVideo
[2010/08/26 19:35:20 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\Lenovo
[2009/12/31 16:31:14 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\MilkShape 3D 1.x.x
[2010/03/25 11:27:21 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\Nvu
[2011/02/28 21:06:39 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\PwrMgr
[2010/06/04 11:26:21 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\TechWizard
[2010/10/20 17:23:56 | 000,000,000 | —D | M] – C:\Users\Travis\AppData\Roaming\WinPatrol
[2011/05/12 22:35:59 | 000,000,528 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2010/08/09 18:32:59 | 000,032,624 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/05/15 10:03:34 | 000,000,382 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2011/05/14 17:01:29 | 000,020,487 | —- | M] () – C:\ComboFix.txt
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/05/15 10:13:43 | 1981,816,832 | -HS- | M] () – C:\hiberfil.sys
[2011/01/10 21:18:22 | 000,000,450 | —- | M] () – C:\INSTALL.LOG
[2010/08/15 21:31:45 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/15 21:31:45 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/06/04 11:55:54 | 000,000,549 | —- | M] () – C:\NTDClient.log
[2011/05/15 10:13:50 | 2642,423,808 | -HS- | M] () – C:\pagefile.sys
[2009/12/19 10:40:31 | 000,000,188 | —- | M] () – C:\setup.log
[2009/12/08 05:51:36 | 000,001,188 | —- | M] () – C:\sysiclog.txt
[2011/05/12 19:07:03 | 000,081,250 | —- | M] () – C:\TDSSKiller.2.5.0.0_12.05.2011_19.06.03_log.txt
[2011/05/12 22:49:38 | 000,081,250 | —- | M] () – C:\TDSSKiller.2.5.0.0_12.05.2011_22.41.35_log.txt
[2011/05/14 14:56:05 | 000,002,168 | —- | M] () – C:\TDSSKiller.2.5.0.0_14.05.2011_14.55.21_log.txt
[2011/05/14 16:48:23 | 000,083,300 | —- | M] () – C:\TDSSKiller.2.5.1.0_14.05.2011_14.56.40_log.txt
[2011/03/20 13:13:12 | 000,001,732 | —- | M] () – C:\tvtpktfilter.dat

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/06/22 19:58:20 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 22:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 08:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/08 03:58:16 | 000,000,221 | -HS- | M] () – C:\Users\Travis\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/03/28 17:28:29 | 000,000,221 | -HS- | M] () – C:\Users\Travis\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/05/13 21:27:11 | 000,589,632 | —- | M] (AVAST Software) – C:\Users\Travis\Desktop\aswMBR.exe
[2011/05/14 16:43:48 | 004,347,991 | R— | M] () – C:\Users\Travis\Desktop\ComboFix.exe
[2011/05/14 19:06:23 | 000,050,477 | —- | M] () – C:\Users\Travis\Desktop\Defogger.exe
[2011/05/14 20:08:36 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Travis\Desktop\mbam-setup-1.50.1.1100.exe
[2011/05/14 19:06:41 | 000,080,384 | —- | M] () – C:\Users\Travis\Desktop\MBRCheck.exe
[2011/05/13 16:28:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Travis\Desktop\OTL.exe
[2011/05/14 14:56:26 | 001,407,280 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Travis\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2006/05/19 14:53:02 | 000,013,022 | —- | M] () – C:\Windows\snp2uvc.src
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-13 02:53:13

< End of report >


My computer definately seems to be running so much better.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI