This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

internet explorer acting crazy

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello, My interent explorer has been acting crazy for the past few days. every time i type something into the search bar and hit enter, internet explorer takes me somewhere completely different. my norton antivirus shows messages while i'm on the internet that say an intrusion attempt was blocked. However i have ran full scans using malwarebytes and norton and nothing significant has been reported. any help would be appreciated greatly. thank you!
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post







  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply








  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Thank you so much for your help,
After running the aswMBR, below is the report it conducted

aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-01 22:56:21
—————————–
22:56:21.741 OS Version: Windows x64 6.1.7600
22:56:21.742 Number of processors: 4 586 0x2505
22:56:21.742 ComputerName: OWNER-PC UserName: owner
22:56:23.634 Initialize success
22:56:26.531 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:56:26.534 Disk 0 Vendor: ST950032 0001 Size: 476940MB BusType: 3
22:56:26.553 Disk 0 MBR read successfully
22:56:26.556 Disk 0 MBR scan
22:56:26.558 Disk 0 unknown MBR code
22:56:26.561 Service scanning
22:56:27.481 Disk 0 trace - called modules:
22:56:27.489 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys
22:56:27.493 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c1e790]
22:56:27.499 3 CLASSPNP.SYS[fffff880013ca43f] -> nt!IofCallDriver -> [0xfffffa8004967300]
22:56:27.502 5 ACPI.sys[fffff88000f5e781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800496d050]
22:56:27.506 Scan finished successfully
22:57:02.606 Disk 0 MBR has been saved successfully to "C:\Users\owner\Desktop\MBR.dat"
22:57:02.607 The log file has been saved successfully to "C:\Users\owner\Desktop\aswMBR.txt"

After running the OLT reports below are the results

OTL.txt

OTL logfile created on: 6/1/2011 10:59:27 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\owner\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.15 Gb Available Physical Memory | 56.61% Memory free
7.61 Gb Paging File | 5.82 Gb Available in Paging File | 76.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 432.81 Gb Total Space | 376.31 Gb Free Space | 86.95% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\owner\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.189\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
PRC - C:\Program Files (x86)\Toshiba\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Windows\SysWOW64\regsvr32.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Modules (SafeList) ==========

MOD - C:\Users\owner\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (N360) – C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (Application Updater) – C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.189\McCHSvc.exe (McAfee, Inc.)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (cfWiMAXService) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION)
SRV - (TMachInfo) – C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ConfigFree Service) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RTL8192Ce) – C:\Windows\SysNative\drivers\rtl8192ce.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (FwLnk) – C:\Windows\SysNative\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110601.021\EX64.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110601.021\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110518.001\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110531.001\IDSviA64.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.ca/welcome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.ca/welcome

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.ca/welcome
IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.3\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2011/05/20 12:15:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn\ [2011/05/20 12:14:09 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (brincome browser plug-in) - {38BA8B8B-651F-7E28-0D9B-EE755739F882} - C:\Windows\SysWOW64\.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.3\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.3\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [messenger.exe] File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [vuqzcrshbnd] C:\windows\SysWow64\.dll ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/05/25 15:51:04 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\CrashDumps
[2011/05/24 19:05:29 | 000,000,000 | —D | C] – C:\Users\owner\Desktop\Payroll
[2011/05/24 14:21:41 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\Diskdump.sys
[2011/05/23 17:18:13 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/05/23 17:16:55 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Apps
[2011/05/23 17:16:54 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Deployment
[2011/05/20 20:01:04 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Diagnostics
[2011/05/20 12:16:17 | 000,000,000 | —D | C] – C:\Users\owner\Documents\Symantec
[2011/05/20 12:14:45 | 000,174,200 | —- | C] (Symantec Corporation) – C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/20 12:14:45 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\windows\SysNative\drivers\GEARAspiWDM.sys
[2011/05/20 12:14:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/05/20 12:14:45 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/05/20 12:14:21 | 000,912,504 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.sys
[2011/05/20 12:14:21 | 000,744,568 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.sys
[2011/05/20 12:14:21 | 000,450,680 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.sys
[2011/05/20 12:14:21 | 000,382,584 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\symnets.sys
[2011/05/20 12:14:21 | 000,171,128 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\Ironx64.sys
[2011/05/20 12:14:21 | 000,040,568 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.sys
[2011/05/20 12:14:11 | 000,000,000 | —D | C] – C:\windows\SysNative\drivers\N360x64
[2011/05/20 12:14:11 | 000,000,000 | —D | C] – C:\windows\SysNative\drivers\N360x64\0501000.01D
[2011/05/20 12:14:09 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition
[2011/05/20 12:14:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton 360 Premier Edition
[2011/05/20 12:12:12 | 000,000,000 | —D | C] – C:\ProgramData\PCSettings
[2011/05/20 12:09:42 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2011/05/18 19:14:21 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\poqexec.exe
[2011/05/18 19:14:21 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\poqexec.exe
[2011/05/11 16:41:56 | 005,509,504 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2011/05/11 16:41:55 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2011/05/11 16:41:55 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2011/05/11 16:41:53 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\usbport.sys
[2011/05/11 16:41:53 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\usbd.sys
[2011/05/08 14:16:35 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Apple Computer
[2011/05/08 14:16:35 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Apple Computer
[2011/05/08 14:16:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/08 14:16:11 | 000,125,872 | —- | C] (GEAR Software Inc.) – C:\windows\SysNative\GEARAspi64.dll
[2011/05/08 14:16:11 | 000,106,928 | —- | C] (GEAR Software Inc.) – C:\windows\SysWow64\GEARAspi.dll
[2011/05/08 14:16:11 | 000,000,000 | —D | C] – C:\windows\SysNative\DRVSTORE
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/05/08 14:15:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/08 14:15:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/05/08 14:15:00 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/05/08 14:14:49 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Apple
[2011/05/08 14:14:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/05/08 14:14:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/05/08 14:14:30 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/08 14:14:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/05/08 14:14:17 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/05/08 14:14:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/08 14:12:07 | 081,790,248 | —- | C] (Apple Inc.) – C:\Users\owner\Documents\iTunes64Setup.exe

========== Files - Modified Within 30 Days ==========

[2011/06/01 22:57:02 | 000,000,512 | —- | M] () – C:\Users\owner\Desktop\MBR.dat
[2011/06/01 22:40:18 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/01 22:40:18 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/01 22:32:49 | 000,000,314 | -HS- | M] () – C:\windows\tasks\XSPYO.job
[2011/06/01 22:32:46 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/06/01 22:32:39 | 3063,029,760 | -HS- | M] () – C:\hiberfil.sys
[2011/05/31 23:22:00 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000UA.job
[2011/05/31 10:48:13 | 000,727,182 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/05/31 10:48:13 | 000,624,622 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/05/31 10:48:13 | 000,106,708 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/05/29 20:22:45 | 000,002,413 | —- | M] () – C:\Users\owner\Desktop\Google Chrome.lnk
[2011/05/24 14:21:16 | 001,314,858 | —- | M] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\Cat.DB
[2011/05/23 17:22:00 | 000,000,856 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000Core.job
[2011/05/20 12:14:45 | 000,174,200 | —- | M] (Symantec Corporation) – C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/20 12:14:45 | 000,007,488 | —- | M] () – C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/20 12:14:45 | 000,000,855 | —- | M] () – C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/20 12:14:32 | 000,002,651 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/05/20 12:14:04 | 000,001,324 | —- | M] () – C:\Users\owner\Desktop\Norton Installation Files.lnk
[2011/05/20 11:19:25 | 000,050,320 | —- | M] () – C:\windows\SysWow64\wtwmdelvyeht.exe
[2011/05/20 11:19:23 | 000,468,054 | —- | M] () – C:\Program Files (x86)\Drivers_pack_v4.55.63_fix.exe
[2011/05/20 11:19:22 | 000,106,496 | RHS- | M] () – C:\windows\SysWow64\iprtprio9.dll
[2011/05/17 06:30:14 | 000,767,488 | —- | M] () – C:\windows\SysWow64\.dll
[2011/05/09 11:35:31 | 000,000,000 | -H– | M] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/08 14:16:28 | 000,001,794 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/05/08 14:15:05 | 000,001,856 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/08 14:12:53 | 081,790,248 | —- | M] (Apple Inc.) – C:\Users\owner\Documents\iTunes64Setup.exe

========== Files Created - No Company Name ==========

[2011/06/01 22:57:02 | 000,000,512 | —- | C] () – C:\Users\owner\Desktop\MBR.dat
[2011/05/23 17:18:15 | 000,002,413 | —- | C] () – C:\Users\owner\Desktop\Google Chrome.lnk
[2011/05/23 17:17:34 | 000,000,908 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000UA.job
[2011/05/23 17:17:34 | 000,000,856 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000Core.job
[2011/05/20 12:14:52 | 001,314,858 | —- | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\Cat.DB
[2011/05/20 12:14:45 | 000,007,488 | —- | C] () – C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/20 12:14:45 | 000,000,855 | —- | C] () – C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/20 12:14:32 | 000,002,651 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/05/20 12:14:21 | 000,000,000 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.cat
[2011/05/20 12:14:12 | 000,003,373 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymEFA.inf
[2011/05/20 12:14:12 | 000,002,792 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymDS.inf
[2011/05/20 12:14:12 | 000,001,446 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymNet.inf
[2011/05/20 12:14:12 | 000,001,438 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.inf
[2011/05/20 12:14:12 | 000,001,422 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.inf
[2011/05/20 12:14:12 | 000,000,772 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\Iron.inf
[2011/05/20 12:14:11 | 000,007,492 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\iron.cat
[2011/05/20 12:14:11 | 000,007,462 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.cat
[2011/05/20 12:14:11 | 000,007,460 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.cat
[2011/05/20 12:14:11 | 000,007,458 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\symnet64.cat
[2011/05/20 12:14:11 | 000,007,458 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.cat
[2011/05/20 12:14:11 | 000,000,172 | —- | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\isolate.ini
[2011/05/20 12:09:42 | 000,001,324 | —- | C] () – C:\Users\owner\Desktop\Norton Installation Files.lnk
[2011/05/20 11:19:25 | 000,050,320 | —- | C] () – C:\windows\SysWow64\wtwmdelvyeht.exe
[2011/05/20 11:19:23 | 000,468,054 | —- | C] () – C:\Program Files (x86)\Drivers_pack_v4.55.63_fix.exe
[2011/05/20 11:19:22 | 000,106,496 | RHS- | C] () – C:\windows\SysWow64\iprtprio9.dll
[2011/05/20 11:19:22 | 000,000,314 | -HS- | C] () – C:\windows\tasks\XSPYO.job
[2011/05/17 06:30:14 | 000,767,488 | —- | C] () – C:\windows\SysWow64\.dll
[2011/05/09 11:35:31 | 000,000,000 | -H– | C] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/08 14:16:28 | 000,001,794 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/05/08 14:15:05 | 000,001,856 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/08 14:14:49 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/04/15 19:19:57 | 000,743,534 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/02/25 12:22:27 | 000,000,000 | —- | C] () – C:\windows\NDSTray.INI
[2011/02/25 12:06:11 | 000,451,072 | —- | C] () – C:\windows\SysWow64\ISSRemoveSP.exe
[2010/07/06 22:06:46 | 000,000,000 | —- | C] () – C:\windows\ativpsrm.bin
[2010/02/22 22:15:02 | 000,001,105 | —- | C] () – C:\windows\SysWow64\atipblag.dat
[2010/02/20 12:22:24 | 000,870,560 | —- | C] () – C:\windows\SysWow64\igkrng575.bin
[2010/02/20 12:22:24 | 000,127,868 | —- | C] () – C:\windows\SysWow64\igcompkrng575.bin
[2010/02/20 12:22:24 | 000,104,636 | —- | C] () – C:\windows\SysWow64\igfcg575m.bin
[2010/02/20 11:27:36 | 000,208,896 | —- | C] () – C:\windows\SysWow64\iglhsip32.dll
[2010/02/20 11:27:36 | 000,143,360 | —- | C] () – C:\windows\SysWow64\iglhcp32.dll
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/05/31 23:55:57 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\SoftGrid Client
[2011/05/15 15:57:26 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\Toshiba
[2011/04/15 19:21:06 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\TP
[2011/05/30 19:09:42 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/06/01 22:32:49 | 000,000,314 | -HS- | M] () – C:\Windows\Tasks\XSPYO.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/07/06 22:09:10 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/06/01 22:32:39 | 3063,029,760 | -HS- | M] () – C:\hiberfil.sys
[2011/06/01 22:32:45 | 4084,039,680 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/17 04:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2011/05/20 11:19:23 | 000,468,054 | —- | M] () – C:\Program Files (x86)\Drivers_pack_v4.55.63_fix.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/15 11:15:16 | 000,000,221 | -HS- | M] () – C:\Users\owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | —- | M] () – C:\Windows\addins\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/04/15 10:41:37 | 000,000,402 | -HS- | M] () – C:\Users\owner\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Thank you so much for your help,
After running the aswMBR, below is the report it conducted

aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-01 22:56:21
—————————–
22:56:21.741 OS Version: Windows x64 6.1.7600
22:56:21.742 Number of processors: 4 586 0x2505
22:56:21.742 ComputerName: OWNER-PC UserName: owner
22:56:23.634 Initialize success
22:56:26.531 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:56:26.534 Disk 0 Vendor: ST950032 0001 Size: 476940MB BusType: 3
22:56:26.553 Disk 0 MBR read successfully
22:56:26.556 Disk 0 MBR scan
22:56:26.558 Disk 0 unknown MBR code
22:56:26.561 Service scanning
22:56:27.481 Disk 0 trace - called modules:
22:56:27.489 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys
22:56:27.493 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c1e790]
22:56:27.499 3 CLASSPNP.SYS[fffff880013ca43f] -> nt!IofCallDriver -> [0xfffffa8004967300]
22:56:27.502 5 ACPI.sys[fffff88000f5e781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800496d050]
22:56:27.506 Scan finished successfully
22:57:02.606 Disk 0 MBR has been saved successfully to "C:\Users\owner\Desktop\MBR.dat"
22:57:02.607 The log file has been saved successfully to "C:\Users\owner\Desktop\aswMBR.txt"

After running the OLT reports below are the results

OTL.txt

OTL logfile created on: 6/1/2011 10:59:27 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\owner\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.15 Gb Available Physical Memory | 56.61% Memory free
7.61 Gb Paging File | 5.82 Gb Available in Paging File | 76.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 432.81 Gb Total Space | 376.31 Gb Free Space | 86.95% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\owner\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.189\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
PRC - C:\Program Files (x86)\Toshiba\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Windows\SysWOW64\regsvr32.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Modules (SafeList) ==========

MOD - C:\Users\owner\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (N360) – C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (Application Updater) – C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.189\McCHSvc.exe (McAfee, Inc.)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (cfWiMAXService) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION)
SRV - (TMachInfo) – C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ConfigFree Service) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RTL8192Ce) – C:\Windows\SysNative\drivers\rtl8192ce.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (FwLnk) – C:\Windows\SysNative\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110601.021\EX64.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110601.021\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110518.001\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110531.001\IDSviA64.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.ca/welcome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.ca/welcome

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.ca/welcome
IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.3\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2011/05/20 12:15:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn\ [2011/05/20 12:14:09 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (brincome browser plug-in) - {38BA8B8B-651F-7E28-0D9B-EE755739F882} - C:\Windows\SysWOW64\.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.3\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.3\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [messenger.exe] File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [vuqzcrshbnd] C:\windows\SysWow64\.dll ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/05/25 15:51:04 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\CrashDumps
[2011/05/24 19:05:29 | 000,000,000 | —D | C] – C:\Users\owner\Desktop\Payroll
[2011/05/24 14:21:41 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\Diskdump.sys
[2011/05/23 17:18:13 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/05/23 17:16:55 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Apps
[2011/05/23 17:16:54 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Deployment
[2011/05/20 20:01:04 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Diagnostics
[2011/05/20 12:16:17 | 000,000,000 | —D | C] – C:\Users\owner\Documents\Symantec
[2011/05/20 12:14:45 | 000,174,200 | —- | C] (Symantec Corporation) – C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/20 12:14:45 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\windows\SysNative\drivers\GEARAspiWDM.sys
[2011/05/20 12:14:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/05/20 12:14:45 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/05/20 12:14:21 | 000,912,504 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.sys
[2011/05/20 12:14:21 | 000,744,568 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.sys
[2011/05/20 12:14:21 | 000,450,680 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.sys
[2011/05/20 12:14:21 | 000,382,584 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\symnets.sys
[2011/05/20 12:14:21 | 000,171,128 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\Ironx64.sys
[2011/05/20 12:14:21 | 000,040,568 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.sys
[2011/05/20 12:14:11 | 000,000,000 | —D | C] – C:\windows\SysNative\drivers\N360x64
[2011/05/20 12:14:11 | 000,000,000 | —D | C] – C:\windows\SysNative\drivers\N360x64\0501000.01D
[2011/05/20 12:14:09 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition
[2011/05/20 12:14:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton 360 Premier Edition
[2011/05/20 12:12:12 | 000,000,000 | —D | C] – C:\ProgramData\PCSettings
[2011/05/20 12:09:42 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2011/05/18 19:14:21 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\poqexec.exe
[2011/05/18 19:14:21 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\poqexec.exe
[2011/05/11 16:41:56 | 005,509,504 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2011/05/11 16:41:55 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2011/05/11 16:41:55 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2011/05/11 16:41:53 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\usbport.sys
[2011/05/11 16:41:53 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\usbd.sys
[2011/05/08 14:16:35 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Apple Computer
[2011/05/08 14:16:35 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Apple Computer
[2011/05/08 14:16:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/08 14:16:11 | 000,125,872 | —- | C] (GEAR Software Inc.) – C:\windows\SysNative\GEARAspi64.dll
[2011/05/08 14:16:11 | 000,106,928 | —- | C] (GEAR Software Inc.) – C:\windows\SysWow64\GEARAspi.dll
[2011/05/08 14:16:11 | 000,000,000 | —D | C] – C:\windows\SysNative\DRVSTORE
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/05/08 14:15:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/08 14:15:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/05/08 14:15:00 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/05/08 14:14:49 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Apple
[2011/05/08 14:14:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/05/08 14:14:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/05/08 14:14:30 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/08 14:14:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/05/08 14:14:17 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/05/08 14:14:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/08 14:12:07 | 081,790,248 | —- | C] (Apple Inc.) – C:\Users\owner\Documents\iTunes64Setup.exe

========== Files - Modified Within 30 Days ==========

[2011/06/01 22:57:02 | 000,000,512 | —- | M] () – C:\Users\owner\Desktop\MBR.dat
[2011/06/01 22:40:18 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/01 22:40:18 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/01 22:32:49 | 000,000,314 | -HS- | M] () – C:\windows\tasks\XSPYO.job
[2011/06/01 22:32:46 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/06/01 22:32:39 | 3063,029,760 | -HS- | M] () – C:\hiberfil.sys
[2011/05/31 23:22:00 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000UA.job
[2011/05/31 10:48:13 | 000,727,182 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/05/31 10:48:13 | 000,624,622 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/05/31 10:48:13 | 000,106,708 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/05/29 20:22:45 | 000,002,413 | —- | M] () – C:\Users\owner\Desktop\Google Chrome.lnk
[2011/05/24 14:21:16 | 001,314,858 | —- | M] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\Cat.DB
[2011/05/23 17:22:00 | 000,000,856 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000Core.job
[2011/05/20 12:14:45 | 000,174,200 | —- | M] (Symantec Corporation) – C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/20 12:14:45 | 000,007,488 | —- | M] () – C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/20 12:14:45 | 000,000,855 | —- | M] () – C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/20 12:14:32 | 000,002,651 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/05/20 12:14:04 | 000,001,324 | —- | M] () – C:\Users\owner\Desktop\Norton Installation Files.lnk
[2011/05/20 11:19:25 | 000,050,320 | —- | M] () – C:\windows\SysWow64\wtwmdelvyeht.exe
[2011/05/20 11:19:23 | 000,468,054 | —- | M] () – C:\Program Files (x86)\Drivers_pack_v4.55.63_fix.exe
[2011/05/20 11:19:22 | 000,106,496 | RHS- | M] () – C:\windows\SysWow64\iprtprio9.dll
[2011/05/17 06:30:14 | 000,767,488 | —- | M] () – C:\windows\SysWow64\.dll
[2011/05/09 11:35:31 | 000,000,000 | -H– | M] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/08 14:16:28 | 000,001,794 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/05/08 14:15:05 | 000,001,856 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/08 14:12:53 | 081,790,248 | —- | M] (Apple Inc.) – C:\Users\owner\Documents\iTunes64Setup.exe

========== Files Created - No Company Name ==========

[2011/06/01 22:57:02 | 000,000,512 | —- | C] () – C:\Users\owner\Desktop\MBR.dat
[2011/05/23 17:18:15 | 000,002,413 | —- | C] () – C:\Users\owner\Desktop\Google Chrome.lnk
[2011/05/23 17:17:34 | 000,000,908 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000UA.job
[2011/05/23 17:17:34 | 000,000,856 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000Core.job
[2011/05/20 12:14:52 | 001,314,858 | —- | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\Cat.DB
[2011/05/20 12:14:45 | 000,007,488 | —- | C] () – C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/20 12:14:45 | 000,000,855 | —- | C] () – C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/20 12:14:32 | 000,002,651 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/05/20 12:14:21 | 000,000,000 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.cat
[2011/05/20 12:14:12 | 000,003,373 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymEFA.inf
[2011/05/20 12:14:12 | 000,002,792 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymDS.inf
[2011/05/20 12:14:12 | 000,001,446 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymNet.inf
[2011/05/20 12:14:12 | 000,001,438 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.inf
[2011/05/20 12:14:12 | 000,001,422 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.inf
[2011/05/20 12:14:12 | 000,000,772 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\Iron.inf
[2011/05/20 12:14:11 | 000,007,492 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\iron.cat
[2011/05/20 12:14:11 | 000,007,462 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.cat
[2011/05/20 12:14:11 | 000,007,460 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.cat
[2011/05/20 12:14:11 | 000,007,458 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\symnet64.cat
[2011/05/20 12:14:11 | 000,007,458 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.cat
[2011/05/20 12:14:11 | 000,000,172 | —- | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\isolate.ini
[2011/05/20 12:09:42 | 000,001,324 | —- | C] () – C:\Users\owner\Desktop\Norton Installation Files.lnk
[2011/05/20 11:19:25 | 000,050,320 | —- | C] () – C:\windows\SysWow64\wtwmdelvyeht.exe
[2011/05/20 11:19:23 | 000,468,054 | —- | C] () – C:\Program Files (x86)\Drivers_pack_v4.55.63_fix.exe
[2011/05/20 11:19:22 | 000,106,496 | RHS- | C] () – C:\windows\SysWow64\iprtprio9.dll
[2011/05/20 11:19:22 | 000,000,314 | -HS- | C] () – C:\windows\tasks\XSPYO.job
[2011/05/17 06:30:14 | 000,767,488 | —- | C] () – C:\windows\SysWow64\.dll
[2011/05/09 11:35:31 | 000,000,000 | -H– | C] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/08 14:16:28 | 000,001,794 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/05/08 14:15:05 | 000,001,856 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/08 14:14:49 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/04/15 19:19:57 | 000,743,534 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/02/25 12:22:27 | 000,000,000 | —- | C] () – C:\windows\NDSTray.INI
[2011/02/25 12:06:11 | 000,451,072 | —- | C] () – C:\windows\SysWow64\ISSRemoveSP.exe
[2010/07/06 22:06:46 | 000,000,000 | —- | C] () – C:\windows\ativpsrm.bin
[2010/02/22 22:15:02 | 000,001,105 | —- | C] () – C:\windows\SysWow64\atipblag.dat
[2010/02/20 12:22:24 | 000,870,560 | —- | C] () – C:\windows\SysWow64\igkrng575.bin
[2010/02/20 12:22:24 | 000,127,868 | —- | C] () – C:\windows\SysWow64\igcompkrng575.bin
[2010/02/20 12:22:24 | 000,104,636 | —- | C] () – C:\windows\SysWow64\igfcg575m.bin
[2010/02/20 11:27:36 | 000,208,896 | —- | C] () – C:\windows\SysWow64\iglhsip32.dll
[2010/02/20 11:27:36 | 000,143,360 | —- | C] () – C:\windows\SysWow64\iglhcp32.dll
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/05/31 23:55:57 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\SoftGrid Client
[2011/05/15 15:57:26 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\Toshiba
[2011/04/15 19:21:06 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\TP
[2011/05/30 19:09:42 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/06/01 22:32:49 | 000,000,314 | -HS- | M] () – C:\Windows\Tasks\XSPYO.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/07/06 22:09:10 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/06/01 22:32:39 | 3063,029,760 | -HS- | M] () – C:\hiberfil.sys
[2011/06/01 22:32:45 | 4084,039,680 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/17 04:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2011/05/20 11:19:23 | 000,468,054 | —- | M] () – C:\Program Files (x86)\Drivers_pack_v4.55.63_fix.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/15 11:15:16 | 000,000,221 | -HS- | M] () – C:\Users\owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | —- | M] () – C:\Windows\addins\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/04/15 10:41:37 | 000,000,402 | -HS- | M] () – C:\Users\owner\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Extra.txt


OTL Extras logfile created on: 6/1/2011 10:59:27 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\owner\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.15 Gb Available Physical Memory | 56.61% Memory free
7.61 Gb Paging File | 5.82 Gb Available in Paging File | 76.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 432.81 Gb Total Space | 376.31 Gb Free Space | 86.95% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{18155797-EF2E-4699-9A16-FE787C4C10DB}" = iTunes
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{A0E99122-25C1-4CA4-9063-499A2A814EB6}" = TOSHIBA ReelTime
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"CNXT_AUDIO_HDA" = Conexant HD Audio
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{073B89C3-BA88-41B5-965F-B35A88EAE838}" = TOSHIBA Supervisor Password
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.6.5
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = TOSHIBA Assist
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{607BE7BF-7C28-4ADB-A4A0-385962B901C3}" = TOSHIBA ConfigFree
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8E9CEA3B-EBD1-439C-A01D-830CB39613C6}" = TOSHIBA Hardware Setup
"{90140011-0062-0409-0000-0000000FF1CE}" = Microsoft Office Home and Business 2010 - English
"{92881120-6DA5-44A3-8BAB-2429A01D022E}" = YouTube Downloader Toolbar v4.3
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}" = TOSHIBA Media Controller
"{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}" = TOSHIBA Media Controller Plug-in
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Amazon Kindle For PC" = Amazon Kindle For PC v1.1
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{A0E99122-25C1-4CA4-9063-499A2A814EB6}" = TOSHIBA ReelTime
"InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"McAfee Security Scan" = McAfee Security Scan Plus
"N360" = Norton 360 Premier Edition
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"TOSHIBA Game Console" = WildTangent ORB Game Console
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WT088682" = Bejeweled 2 Deluxe
"WT088696" = Chuzzle Deluxe
"WT088702" = Plants vs. Zombies
"WT088703" = Build-a-lot 2
"WT088710" = Zuma's Revenge
"WT088739" = FATE
"WT088750" = Jewel Quest - Heritage
"WT088759" = Polar Bowler
"WT088760" = Virtual Villagers 4 - The Tree of Life
"WT088761" = Wheel of Fortune 2
"wtwmdelvyeht" = Performance Solution Brincome.

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/24/2011 10:29:34 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: WS2_32.dll, version: 6.1.7600.16385,
time stamp: 0x4a5bdb4a Exception code: 0xc0000005 Fault offset: 0x0000ba60 Faulting
process id: 0x1954 Faulting application start time: 0x01cc1a8381c32971 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\syswow64\WS2_32.dll Report Id: d352b1a6-8676-11e0-b3cc-00266caee642

Error - 5/25/2011 3:47:25 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab86 Exception code: 0xc0000374 Fault offset: 0x000cea27 Faulting
process id: 0x910 Faulting application start time: 0x01cc1b147ec6f60a Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\SysWOW64\ntdll.dll Report Id: d01b443b-8707-11e0-b5e3-00266caee642

Error - 5/25/2011 3:50:57 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab86 Exception code: 0xc0000374 Fault offset: 0x000cea27 Faulting
process id: 0x498 Faulting application start time: 0x01cc1b1495a60746 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\SysWOW64\ntdll.dll Report Id: 4e5aa376-8708-11e0-b5e3-00266caee642

Error - 5/25/2011 3:51:02 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: WININET.dll, version: 9.0.8112.16421,
time stamp: 0x4d7625c8 Exception code: 0xc0000005 Fault offset: 0x0001bdfd Faulting
process id: 0x688 Faulting application start time: 0x01cc1b1512948c04 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\syswow64\WININET.dll Report Id: 5180ab88-8708-11e0-b5e3-00266caee642

Error - 5/25/2011 4:07:01 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: MSHTML.dll, version: 9.0.8112.16421,
time stamp: 0x4d76266c Exception code: 0xc0000005 Fault offset: 0x00263003 Faulting
process id: 0x19f4 Faulting application start time: 0x01cc1b173df2477c Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\system32\MSHTML.dll Report Id: 8cef6ab5-870a-11e0-b5e3-00266caee642

Error - 5/25/2011 4:07:22 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: MSHTML.dll, version: 9.0.8112.16421,
time stamp: 0x4d76266c Exception code: 0xc0000005 Fault offset: 0x002c95d9 Faulting
process id: 0x1bcc Faulting application start time: 0x01cc1b17517fef29 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\system32\MSHTML.dll Report Id: 99a3271b-870a-11e0-b5e3-00266caee642

Error - 5/25/2011 4:09:43 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab86 Exception code: 0xc0000374 Fault offset: 0x000cea27 Faulting
process id: 0x1a18 Faulting application start time: 0x01cc1b175dcd6fa6 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\SysWOW64\ntdll.dll Report Id: ed831a23-870a-11e0-b5e3-00266caee642

Error - 5/25/2011 4:10:02 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab86 Exception code: 0xc0000005 Fault offset: 0x0002e3be Faulting
process id: 0x13e0 Faulting application start time: 0x01cc1b17b2eac4cb Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\SysWOW64\ntdll.dll Report Id: f91a2e14-870a-11e0-b5e3-00266caee642

Error - 5/25/2011 4:19:03 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab86 Exception code: 0xc0000374 Fault offset: 0x000cea27 Faulting
process id: 0x1ad0 Faulting application start time: 0x01cc1b17bcea6fb6 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\SysWOW64\ntdll.dll Report Id: 3b4b2cb9-870c-11e0-b5e3-00266caee642

Error - 5/25/2011 5:05:35 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab86 Exception code: 0xc0000005 Fault offset: 0x0002e3be Faulting
process id: 0xfc0 Faulting application start time: 0x01cc1b1f7751e866 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\SysWOW64\ntdll.dll Report Id: bb76083d-8712-11e0-b5e3-00266caee642

[ System Events ]
Error - 4/23/2011 10:39:00 AM | Computer Name = owner-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 4/23/2011 10:39:00 AM | Computer Name = owner-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 4/27/2011 3:54:15 PM | Computer Name = owner-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x800b0100: Update for Windows 7 for x64-based Systems (KB982018).

Error - 5/1/2011 11:46:49 AM | Computer Name = owner-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:28:54 PM on ?4/?30/?2011 was unexpected.

Error - 5/14/2011 2:19:51 PM | Computer Name = owner-PC | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 5/18/2011 7:41:24 PM | Computer Name = owner-PC | Source = DCOM | ID = 10010
Description =

Error - 5/24/2011 7:02:48 PM | Computer Name = owner-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{966AF2B6-705C-4ED4-AD73-0798AB686F3D}
because another computer on the network has the same name. The server could not
start.

Error - 5/24/2011 7:02:48 PM | Computer Name = owner-PC | Source = NetBT | ID = 4321
Description = The name "OWNER-PC :0" could not be registered on the interface
with IP address 10.24.18.27. The computer with the IP address 10.40.1.5 did not
allow the name to be claimed by this computer.

Error - 5/24/2011 7:02:48 PM | Computer Name = owner-PC | Source = NetBT | ID = 4321
Description = The name "OWNER-PC :20" could not be registered on the interface
with IP address 10.24.18.27. The computer with the IP address 10.40.1.5 did not
allow the name to be claimed by this computer.

Error - 5/25/2011 3:41:22 PM | Computer Name = owner-PC | Source = Microsoft-Windows-WHEA-Logger | ID = 18
Description = A fatal hardware error has occurred. Reported by component: Processor
Core Error Source: 3 Error Type: 5 Processor ID: 0 The details view of this entry contains
further information.


< End of report >
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Look in C:\ComboFix.txt for the log




Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
ComboFix Log ComboFix 11-06-04.02 - owner 06/04/2011 19:22:19.4.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3895.2592 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Norton Internet Security *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\YouTube Downloader Toolbar\IE\4.3\yoUTubedownloadertoolbarie.dll c:\windows\system32\Thumbs.db c:\windows\SysWow64\.dll . . ((((((((((((((((((((((((( Files Created from 2011-05-04 to 2011-06-04 ))))))))))))))))))))))))))))))) . . 2011-06-04 23:26 . 2011-06-04 23:26 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-05-25 19:51 . 2011-05-30 14:52 ——– d—–w- c:\users\owner\AppData\Local\CrashDumps 2011-05-24 18:21 . 2011-04-22 20:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-23 21:16 . 2011-05-23 21:16 ——– d—–w- c:\users\owner\AppData\Local\Apps 2011-05-23 21:16 . 2011-05-23 21:17 ——– d—–w- c:\users\owner\AppData\Local\Deployment 2011-05-21 00:01 . 2011-05-21 00:01 ——– d—–w- c:\users\owner\AppData\Local\Diagnostics 2011-05-20 16:14 . 2011-05-20 16:14 174200 —-a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\program files\Symantec 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\program files\Common Files\Symantec Shared 2011-05-20 16:14 . 2010-08-21 03:59 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\windows\system32\drivers\N360x64 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\program files (x86)\Norton 360 Premier Edition 2011-05-20 16:12 . 2011-05-20 16:12 ——– d—–w- c:\programdata\PCSettings 2011-05-20 15:19 . 2011-05-20 15:19 50320 —-a-w- c:\windows\SysWow64\wtwmdelvyeht.exe 2011-05-20 15:19 . 2011-05-20 15:19 468054 —-a-w- c:\program files (x86)\Drivers_pack_v4.55.63_fix.exe 2011-05-20 15:19 . 2011-05-20 15:19 106496 –sha-r- c:\windows\SysWow64\iprtprio9.dll 2011-05-18 23:14 . 2011-04-18 13:15 8802128 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6083372B-52BF-4B6F-8AC8-6A2C437795EC}\mpengine.dll 2011-05-18 23:14 . 2011-04-09 06:58 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-05-18 23:14 . 2011-04-09 05:56 123904 —-a-w- c:\windows\SysWow64\poqexec.exe 2011-05-16 23:31 . 2011-02-02 22:11 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-05-11 20:41 . 2011-04-09 06:45 5509504 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-05-11 20:41 . 2011-04-09 06:13 3957632 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-05-11 20:41 . 2011-04-09 06:13 3901824 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-05-11 20:41 . 2011-03-29 03:32 52224 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-11 20:41 . 2011-03-29 03:32 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-11 20:41 . 2011-03-29 03:32 99328 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-11 20:41 . 2011-03-29 03:32 324608 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-05-11 20:41 . 2011-03-29 03:32 25600 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-05-11 20:41 . 2011-03-29 03:32 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-11 20:41 . 2011-03-29 03:32 7936 —-a-w- c:\windows\system32\drivers\usbd.sys 2011-05-08 18:16 . 2011-05-15 02:05 ——– d—–w- c:\users\owner\AppData\Local\Apple Computer 2011-05-08 18:16 . 2011-05-09 15:56 ——– d—–w- c:\users\owner\AppData\Roaming\Apple Computer 2011-05-08 18:16 . 2011-05-20 16:14 ——– dc—-w- c:\windows\system32\DRVSTORE 2011-05-08 18:16 . 2010-08-21 03:59 125872 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-05-08 18:16 . 2010-08-21 03:59 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\users\owner\AppData\Local\Apple 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files\Common Files\Apple 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files\Bonjour 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files (x86)\Bonjour 2011-05-08 18:14 . 2011-05-09 15:34 ——– d—–w- c:\programdata\Apple 2011-05-08 18:14 . 2011-05-08 18:15 ——– d—–w- c:\program files (x86)\Common Files\Apple . .TDSSKiller log: 2011/06/04 19:18:00.0343 1072 TDSS rootkit removing tool 2.5.3.0 May 25 2011 07:09:24 2011/06/04 19:18:01.0273 1072 ================================================================================ 2011/06/04 19:18:01.0273 1072 SystemInfo: 2011/06/04 19:18:01.0273 1072 2011/06/04 19:18:01.0273 1072 OS Version: 6.1.7600 ServicePack: 0.0 2011/06/04 19:18:01.0273 1072 Product type: Workstation 2011/06/04 19:18:01.0273 1072 ComputerName: OWNER-PC 2011/06/04 19:18:01.0273 1072 UserName: owner 2011/06/04 19:18:01.0273 1072 Windows directory: C:\windows 2011/06/04 19:18:01.0273 1072 System windows directory: C:\windows 2011/06/04 19:18:01.0273 1072 Running under WOW64 2011/06/04 19:18:01.0273 1072 Processor architecture: Intel x64 2011/06/04 19:18:01.0273 1072 Number of processors: 4 2011/06/04 19:18:01.0273 1072 Page size: 0x1000 2011/06/04 19:18:01.0273 1072 Boot type: Normal boot 2011/06/04 19:18:01.0273 1072 ================================================================================ 2011/06/04 19:18:03.0221 1072 Initialize success 2011/06/04 19:18:05.0998 5864 ================================================================================ 2011/06/04 19:18:05.0998 5864 Scan started 2011/06/04 19:18:05.0998 5864 Mode: Manual; 2011/06/04 19:18:05.0998 5864 ================================================================================ 2011/06/04 19:18:09.0726 5864 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\windows\system32\DRIVERS\1394ohci.sys 2011/06/04 19:18:09.0789 5864 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\windows\system32\DRIVERS\ACPI.sys 2011/06/04 19:18:09.0820 5864 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\windows\system32\DRIVERS\acpipmi.sys 2011/06/04 19:18:09.0867 5864 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys 2011/06/04 19:18:09.0898 5864 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys 2011/06/04 19:18:09.0945 5864 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys 2011/06/04 19:18:10.0007 5864 AFD (b9384e03479d2506bc924c16a3db87bc) C:\windows\system32\drivers\afd.sys 2011/06/04 19:18:10.0085 5864 AgereSoftModem (98022774d9930ecbb292e70db7601df6) C:\windows\system32\DRIVERS\agrsm64.sys 2011/06/04 19:18:10.0225 5864 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\DRIVERS\agp440.sys 2011/06/04 19:18:10.0288 5864 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\DRIVERS\aliide.sys 2011/06/04 19:18:10.0319 5864 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\DRIVERS\amdide.sys 2011/06/04 19:18:10.0366 5864 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys 2011/06/04 19:18:10.0600 5864 amdkmdag (aefaf27f1b7e52c705df4fb6c96732f6) C:\windows\system32\DRIVERS\atipmdag.sys 2011/06/04 19:18:10.0787 5864 amdkmdap (8149db73be27950ec72767a1193153a6) C:\windows\system32\DRIVERS\atikmpag.sys 2011/06/04 19:18:10.0849 5864 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys 2011/06/04 19:18:10.0912 5864 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\windows\system32\drivers\amdsata.sys 2011/06/04 19:18:10.0959 5864 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys 2011/06/04 19:18:10.0990 5864 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\windows\system32\drivers\amdxata.sys 2011/06/04 19:18:11.0052 5864 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\windows\system32\drivers\appid.sys 2011/06/04 19:18:11.0208 5864 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys 2011/06/04 19:18:11.0255 5864 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys 2011/06/04 19:18:11.0286 5864 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys 2011/06/04 19:18:11.0395 5864 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\DRIVERS\atapi.sys 2011/06/04 19:18:11.0551 5864 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys 2011/06/04 19:18:11.0614 5864 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys 2011/06/04 19:18:11.0661 5864 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys 2011/06/04 19:18:11.0895 5864 BHDrvx64 (3b9b31981894123f78c4ef0d97184319) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110518.001\BHDrvx64.sys 2011/06/04 19:18:12.0004 5864 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys 2011/06/04 19:18:12.0097 5864 bowser (19d20159708e152267e53b66677a4995) C:\windows\system32\DRIVERS\bowser.sys 2011/06/04 19:18:12.0207 5864 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys 2011/06/04 19:18:12.0253 5864 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys 2011/06/04 19:18:12.0300 5864 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys 2011/06/04 19:18:12.0347 5864 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys 2011/06/04 19:18:12.0378 5864 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys 2011/06/04 19:18:12.0409 5864 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys 2011/06/04 19:18:12.0472 5864 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys 2011/06/04 19:18:12.0534 5864 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys 2011/06/04 19:18:12.0597 5864 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\windows\system32\DRIVERS\cdrom.sys 2011/06/04 19:18:12.0706 5864 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys 2011/06/04 19:18:12.0768 5864 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys 2011/06/04 19:18:12.0924 5864 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys 2011/06/04 19:18:12.0955 5864 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\DRIVERS\cmdide.sys 2011/06/04 19:18:13.0018 5864 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\windows\system32\Drivers\cng.sys 2011/06/04 19:18:13.0111 5864 CnxtHdAudService (25c58ee97be0416a373e3e4f855206b5) C:\windows\system32\drivers\CHDRT64.sys 2011/06/04 19:18:13.0174 5864 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys 2011/06/04 19:18:13.0252 5864 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\windows\system32\DRIVERS\CompositeBus.sys 2011/06/04 19:18:13.0345 5864 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys 2011/06/04 19:18:13.0439 5864 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\windows\system32\Drivers\dfsc.sys 2011/06/04 19:18:13.0455 5864 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys 2011/06/04 19:18:13.0486 5864 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys 2011/06/04 19:18:13.0564 5864 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys 2011/06/04 19:18:13.0626 5864 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\windows\System32\drivers\dxgkrnl.sys 2011/06/04 19:18:13.0751 5864 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys 2011/06/04 19:18:14.0157 5864 eeCtrl (eb0883462ac43829e47929d705d40933) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 2011/06/04 19:18:14.0281 5864 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys 2011/06/04 19:18:14.0422 5864 EraserUtilRebootDrv (86fc0d272f6bb43e7214d4ba955a41e7) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2011/06/04 19:18:14.0515 5864 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\DRIVERS\errdev.sys 2011/06/04 19:18:14.0609 5864 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys 2011/06/04 19:18:14.0671 5864 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys 2011/06/04 19:18:14.0734 5864 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys 2011/06/04 19:18:14.0827 5864 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys 2011/06/04 19:18:14.0859 5864 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys 2011/06/04 19:18:14.0905 5864 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys 2011/06/04 19:18:14.0937 5864 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\windows\system32\drivers\fltmgr.sys 2011/06/04 19:18:14.0968 5864 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys 2011/06/04 19:18:14.0983 5864 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys 2011/06/04 19:18:15.0061 5864 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\windows\system32\DRIVERS\fvevol.sys 2011/06/04 19:18:15.0137 5864 FwLnk (60acb128e64c35c2b4e4aab1b0a5c293) C:\windows\system32\DRIVERS\FwLnk.sys 2011/06/04 19:18:15.0177 5864 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys 2011/06/04 19:18:15.0237 5864 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys 2011/06/04 19:18:15.0277 5864 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys 2011/06/04 19:18:15.0307 5864 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\windows\system32\drivers\HdAudio.sys 2011/06/04 19:18:15.0367 5864 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\windows\system32\DRIVERS\HDAudBus.sys 2011/06/04 19:18:15.0427 5864 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\windows\system32\DRIVERS\HECIx64.sys 2011/06/04 19:18:15.0477 5864 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys 2011/06/04 19:18:15.0497 5864 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys 2011/06/04 19:18:15.0527 5864 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys 2011/06/04 19:18:15.0577 5864 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\windows\system32\DRIVERS\hidusb.sys 2011/06/04 19:18:15.0627 5864 HpSAMD (0886d440058f203eba0e1825e4355914) C:\windows\system32\DRIVERS\HpSAMD.sys 2011/06/04 19:18:15.0667 5864 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\windows\system32\drivers\HTTP.sys 2011/06/04 19:18:15.0707 5864 hwpolicy (f17766a19145f111856378df337a5d79) C:\windows\system32\drivers\hwpolicy.sys 2011/06/04 19:18:15.0737 5864 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys 2011/06/04 19:18:15.0777 5864 iaStor (85977cd13fc16069ce0af7943a811775) C:\windows\system32\DRIVERS\iaStor.sys 2011/06/04 19:18:15.0837 5864 iaStorV (b75e45c564e944a2657167d197ab29da) C:\windows\system32\drivers\iaStorV.sys 2011/06/04 19:18:16.0037 5864 IDSVia64 (8f9faa4583e634a1505bad8d0c04c5c9) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110602.001\IDSvia64.sys 2011/06/04 19:18:16.0337 5864 igfx (898ab5bfed7040d7ab07af01885eb944) C:\windows\system32\DRIVERS\igdkmd64.sys 2011/06/04 19:18:16.0567 5864 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys 2011/06/04 19:18:16.0617 5864 Impcd (4b6363cd4610bb848531bb260b15dfcc) C:\windows\system32\DRIVERS\Impcd.sys 2011/06/04 19:18:16.0677 5864 IntcDAud (58cf58dee26c909bd6f977b61d246295) C:\windows\system32\DRIVERS\IntcDAud.sys 2011/06/04 19:18:16.0717 5864 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\DRIVERS\intelide.sys 2011/06/04 19:18:16.0757 5864 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys 2011/06/04 19:18:16.0787 5864 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\windows\system32\DRIVERS\ipfltdrv.sys 2011/06/04 19:18:16.0837 5864 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\windows\system32\DRIVERS\IPMIDrv.sys 2011/06/04 19:18:16.0857 5864 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys 2011/06/04 19:18:16.0907 5864 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys 2011/06/04 19:18:16.0927 5864 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\DRIVERS\isapnp.sys 2011/06/04 19:18:16.0967 5864 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\windows\system32\DRIVERS\msiscsi.sys 2011/06/04 19:18:17.0007 5864 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys 2011/06/04 19:18:17.0077 5864 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\windows\system32\DRIVERS\kbdhid.sys 2011/06/04 19:18:17.0158 5864 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\windows\system32\Drivers\ksecdd.sys 2011/06/04 19:18:17.0189 5864 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\windows\system32\Drivers\ksecpkg.sys 2011/06/04 19:18:17.0221 5864 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys 2011/06/04 19:18:17.0283 5864 L1C (55480b9c63f3f91a8ebbadcbf28fe581) C:\windows\system32\DRIVERS\L1C62x64.sys 2011/06/04 19:18:17.0345 5864 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys 2011/06/04 19:18:17.0392 5864 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys 2011/06/04 19:18:17.0423 5864 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys 2011/06/04 19:18:17.0439 5864 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys 2011/06/04 19:18:17.0486 5864 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys 2011/06/04 19:18:17.0501 5864 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys 2011/06/04 19:18:17.0548 5864 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys 2011/06/04 19:18:17.0564 5864 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys 2011/06/04 19:18:17.0611 5864 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys 2011/06/04 19:18:17.0642 5864 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys 2011/06/04 19:18:17.0704 5864 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys 2011/06/04 19:18:17.0767 5864 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys 2011/06/04 19:18:17.0813 5864 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\windows\system32\drivers\mountmgr.sys 2011/06/04 19:18:17.0829 5864 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\windows\system32\DRIVERS\mpio.sys 2011/06/04 19:18:17.0860 5864 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys 2011/06/04 19:18:17.0891 5864 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\windows\system32\drivers\mrxdav.sys 2011/06/04 19:18:17.0938 5864 mrxsmb (b7f3d2c40bdf8ffb73ebfb19c77734e2) C:\windows\system32\DRIVERS\mrxsmb.sys 2011/06/04 19:18:17.0969 5864 mrxsmb10 (86c6f88b5168ce21cf8d69d0b3ff5d19) C:\windows\system32\DRIVERS\mrxsmb10.sys 2011/06/04 19:18:18.0001 5864 mrxsmb20 (b081069251c8e9f42cb8769d07148f9c) C:\windows\system32\DRIVERS\mrxsmb20.sys 2011/06/04 19:18:18.0032 5864 msahci (5c37497276e3b3a5488b23a326a754b7) C:\windows\system32\DRIVERS\msahci.sys 2011/06/04 19:18:18.0063 5864 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\windows\system32\DRIVERS\msdsm.sys 2011/06/04 19:18:18.0094 5864 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys 2011/06/04 19:18:18.0188 5864 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys 2011/06/04 19:18:18.0235 5864 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\DRIVERS\msisadrv.sys 2011/06/04 19:18:18.0344 5864 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys 2011/06/04 19:18:18.0375 5864 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys 2011/06/04 19:18:18.0422 5864 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys 2011/06/04 19:18:18.0469 5864 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\windows\system32\drivers\MsRPC.sys 2011/06/04 19:18:18.0515 5864 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys 2011/06/04 19:18:18.0562 5864 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys 2011/06/04 19:18:18.0593 5864 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys 2011/06/04 19:18:18.0625 5864 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys 2011/06/04 19:18:18.0734 5864 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys 2011/06/04 19:18:18.0921 5864 NAVENG (f594e1acbbb3ba48586b5dd69b3a6bc2) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110603.002\ENG64.SYS 2011/06/04 19:18:19.0121 5864 NAVEX15 (cfe00b55488acf0cd9f62b0401297864) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110603.002\EX64.SYS 2011/06/04 19:18:19.0251 5864 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\windows\system32\drivers\ndis.sys 2011/06/04 19:18:19.0321 5864 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys 2011/06/04 19:18:19.0361 5864 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys 2011/06/04 19:18:19.0381 5864 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\windows\system32\DRIVERS\ndisuio.sys 2011/06/04 19:18:19.0431 5864 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\windows\system32\DRIVERS\ndiswan.sys 2011/06/04 19:18:19.0451 5864 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\windows\system32\drivers\NDProxy.sys 2011/06/04 19:18:19.0471 5864 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys 2011/06/04 19:18:19.0521 5864 NetBT (9162b273a44ab9dce5b44362731d062a) C:\windows\system32\DRIVERS\netbt.sys 2011/06/04 19:18:19.0591 5864 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys 2011/06/04 19:18:19.0621 5864 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys 2011/06/04 19:18:19.0651 5864 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys 2011/06/04 19:18:19.0741 5864 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\windows\system32\drivers\Ntfs.sys 2011/06/04 19:18:19.0841 5864 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys 2011/06/04 19:18:19.0891 5864 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\windows\system32\drivers\nvraid.sys 2011/06/04 19:18:19.0921 5864 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\windows\system32\drivers\nvstor.sys 2011/06/04 19:18:19.0971 5864 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\DRIVERS\nv_agp.sys 2011/06/04 19:18:20.0001 5864 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\DRIVERS\ohci1394.sys 2011/06/04 19:18:20.0061 5864 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys 2011/06/04 19:18:20.0091 5864 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\windows\system32\drivers\partmgr.sys 2011/06/04 19:18:20.0121 5864 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\windows\system32\DRIVERS\pci.sys 2011/06/04 19:18:20.0151 5864 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys 2011/06/04 19:18:20.0181 5864 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys 2011/06/04 19:18:20.0221 5864 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys 2011/06/04 19:18:20.0251 5864 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys 2011/06/04 19:18:20.0351 5864 PGEffect (663962900e7fea522126ba287715bb4a) C:\windows\system32\DRIVERS\pgeffect.sys 2011/06/04 19:18:20.0481 5864 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\windows\system32\DRIVERS\raspptp.sys 2011/06/04 19:18:20.0521 5864 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys 2011/06/04 19:18:20.0591 5864 Psched (ee992183bd8eaefd9973f352e587a299) C:\windows\system32\DRIVERS\pacer.sys 2011/06/04 19:18:20.0651 5864 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys 2011/06/04 19:18:20.0701 5864 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys 2011/06/04 19:18:20.0741 5864 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys 2011/06/04 19:18:20.0751 5864 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys 2011/06/04 19:18:20.0801 5864 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys 2011/06/04 19:18:20.0851 5864 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\windows\system32\DRIVERS\rasl2tp.sys 2011/06/04 19:18:20.0881 5864 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys 2011/06/04 19:18:20.0911 5864 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys 2011/06/04 19:18:20.0941 5864 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\windows\system32\DRIVERS\rdbss.sys 2011/06/04 19:18:20.0971 5864 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys 2011/06/04 19:18:21.0002 5864 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys 2011/06/04 19:18:21.0033 5864 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys 2011/06/04 19:18:21.0049 5864 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys 2011/06/04 19:18:21.0080 5864 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\windows\system32\drivers\RDPWD.sys 2011/06/04 19:18:21.0127 5864 rdyboost (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\windows\system32\drivers\rdyboost.sys 2011/06/04 19:18:21.0252 5864 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys 2011/06/04 19:18:21.0330 5864 RSUSBSTOR (907c4464381b5ebdfdc60f6c7d0dedfc) C:\windows\system32\Drivers\RtsUStor.sys 2011/06/04 19:18:21.0408 5864 RTL8192Ce (ffc748d848740d1bc8f330a8879c2674) C:\windows\system32\DRIVERS\rtl8192Ce.sys 2011/06/04 19:18:21.0470 5864 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\windows\system32\DRIVERS\sbp2port.sys 2011/06/04 19:18:21.0501 5864 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\windows\system32\DRIVERS\scfilter.sys 2011/06/04 19:18:21.0548 5864 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys 2011/06/04 19:18:21.0579 5864 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys 2011/06/04 19:18:21.0611 5864 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys 2011/06/04 19:18:21.0626 5864 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys 2011/06/04 19:18:21.0657 5864 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\DRIVERS\sffdisk.sys 2011/06/04 19:18:21.0689 5864 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\DRIVERS\sffp_mmc.sys 2011/06/04 19:18:21.0704 5864 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\windows\system32\DRIVERS\sffp_sd.sys 2011/06/04 19:18:21.0735 5864 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys 2011/06/04 19:18:21.0798 5864 Sftfs (72cd52403efc137290cb5a328510ebca) C:\windows\system32\DRIVERS\Sftfslh.sys 2011/06/04 19:18:21.0845 5864 Sftplay (31a36ef71af36eabcc4b4f8ab8f76465) C:\windows\system32\DRIVERS\Sftplaylh.sys 2011/06/04 19:18:21.0876 5864 Sftredir (2d969194fcc8eb41ed1d52863bfe7f52) C:\windows\system32\DRIVERS\Sftredirlh.sys 2011/06/04 19:18:21.0907 5864 Sftvol (08b36d2f63af3ca2248458a4280c0c50) C:\windows\system32\DRIVERS\Sftvollh.sys 2011/06/04 19:18:21.0954 5864 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys 2011/06/04 19:18:21.0969 5864 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys 2011/06/04 19:18:22.0016 5864 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys 2011/06/04 19:18:22.0063 5864 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys 2011/06/04 19:18:22.0172 5864 SRTSP (90ef30c3867bcde4579c01a6d6e75a7a) C:\windows\system32\drivers\N360x64\0501000.01D\SRTSP64.SYS 2011/06/04 19:18:22.0250 5864 SRTSPX (c513e8a5e7978da49077f5484344ee1b) C:\windows\system32\drivers\N360x64\0501000.01D\SRTSPX64.SYS 2011/06/04 19:18:22.0313 5864 srv (148d50904d2a0df29a19778715eb35bb) C:\windows\system32\DRIVERS\srv.sys 2011/06/04 19:18:22.0391 5864 srv2 (ce2189fe31d36678ac9eb7ddee08ec96) C:\windows\system32\DRIVERS\srv2.sys 2011/06/04 19:18:22.0437 5864 srvnet (cb69edeb069a49577592835659cd0e46) C:\windows\system32\DRIVERS\srvnet.sys 2011/06/04 19:18:22.0500 5864 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys 2011/06/04 19:18:22.0531 5864 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys 2011/06/04 19:18:22.0609 5864 SymDS (6160145c7a87fc7672e8e3b886888176) C:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS 2011/06/04 19:18:22.0687 5864 SymEFA (96aeed40d4d3521568b42027687e69e0) C:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS 2011/06/04 19:18:22.0812 5864 SymEvent (21a1c2d694c3cf962d31f5e873ab3d6f) C:\windows\system32\Drivers\SYMEVENT64x86.SYS 2011/06/04 19:18:22.0874 5864 SymIRON (bd0d711d8cbfcaa19ca123306eaf53a5) C:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS 2011/06/04 19:18:22.0921 5864 SymNetS (81d134628a98a22b6e054e971af525dc) C:\windows\system32\drivers\N360x64\0501000.01D\SYMNETS.SYS 2011/06/04 19:18:22.0968 5864 SynTP (470c47daba9ca3966f0ab3f835d7d135) C:\windows\system32\DRIVERS\SynTP.sys 2011/06/04 19:18:23.0061 5864 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\windows\system32\drivers\tcpip.sys 2011/06/04 19:18:23.0186 5864 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\windows\system32\DRIVERS\tcpip.sys 2011/06/04 19:18:23.0249 5864 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\windows\system32\drivers\tcpipreg.sys 2011/06/04 19:18:23.0311 5864 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\windows\system32\DRIVERS\tdcmdpst.sys 2011/06/04 19:18:23.0342 5864 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys 2011/06/04 19:18:23.0358 5864 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys 2011/06/04 19:18:23.0405 5864 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\windows\system32\DRIVERS\tdx.sys 2011/06/04 19:18:23.0420 5864 TermDD (c448651339196c0e869a355171875522) C:\windows\system32\DRIVERS\termdd.sys 2011/06/04 19:18:23.0607 5864 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\windows\system32\DRIVERS\tssecsrv.sys 2011/06/04 19:18:23.0670 5864 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\windows\system32\DRIVERS\tunnel.sys 2011/06/04 19:18:23.0732 5864 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\windows\system32\DRIVERS\TVALZ_O.SYS 2011/06/04 19:18:23.0810 5864 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\windows\system32\DRIVERS\TVALZFL.sys 2011/06/04 19:18:23.0857 5864 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys 2011/06/04 19:18:23.0919 5864 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\windows\system32\DRIVERS\udfs.sys 2011/06/04 19:18:23.0966 5864 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\DRIVERS\uliagpkx.sys 2011/06/04 19:18:23.0997 5864 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\windows\system32\DRIVERS\umbus.sys 2011/06/04 19:18:24.0044 5864 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys 2011/06/04 19:18:24.0107 5864 USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\windows\system32\Drivers\usbaapl64.sys 2011/06/04 19:18:24.0169 5864 usbccgp (537a4e03d7103c12d42dfd8ffdb5bdc9) C:\windows\system32\DRIVERS\usbccgp.sys 2011/06/04 19:18:24.0216 5864 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\DRIVERS\usbcir.sys 2011/06/04 19:18:24.0231 5864 usbehci (fbb21ebe49f6d560db37ac25fbc68e66) C:\windows\system32\drivers\usbehci.sys 2011/06/04 19:18:24.0278 5864 usbhub (6b7a8a99c4a459e73c286a6763ea24cc) C:\windows\system32\DRIVERS\usbhub.sys 2011/06/04 19:18:24.0309 5864 usbohci (8c88aa7617b4cbc2e4bed61d26b33a27) C:\windows\system32\drivers\usbohci.sys 2011/06/04 19:18:24.0356 5864 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys 2011/06/04 19:18:24.0387 5864 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys 2011/06/04 19:18:24.0434 5864 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\windows\system32\DRIVERS\USBSTOR.SYS 2011/06/04 19:18:24.0481 5864 usbuhci (0b5b3b2df3fd1709618acfa50b8392b0) C:\windows\system32\drivers\usbuhci.sys 2011/06/04 19:18:24.0543 5864 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\windows\System32\Drivers\usbvideo.sys 2011/06/04 19:18:24.0606 5864 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\DRIVERS\vdrvroot.sys 2011/06/04 19:18:24.0637 5864 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys 2011/06/04 19:18:24.0668 5864 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys 2011/06/04 19:18:24.0699 5864 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\windows\system32\DRIVERS\vhdmp.sys 2011/06/04 19:18:24.0715 5864 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\DRIVERS\viaide.sys 2011/06/04 19:18:24.0777 5864 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\windows\system32\DRIVERS\volmgr.sys 2011/06/04 19:18:24.0809 5864 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\windows\system32\drivers\volmgrx.sys 2011/06/04 19:18:24.0855 5864 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\windows\system32\DRIVERS\volsnap.sys 2011/06/04 19:18:24.0902 5864 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys 2011/06/04 19:18:24.0949 5864 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys 2011/06/04 19:18:24.0965 5864 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys 2011/06/04 19:18:25.0011 5864 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\windows\system32\DRIVERS\vwifimp.sys 2011/06/04 19:18:25.0027 5864 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys 2011/06/04 19:18:25.0121 5864 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys 2011/06/04 19:18:25.0167 5864 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys 2011/06/04 19:18:25.0308 5864 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys 2011/06/04 19:18:25.0370 5864 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys 2011/06/04 19:18:25.0542 5864 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys 2011/06/04 19:18:25.0573 5864 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys 2011/06/04 19:18:25.0698 5864 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\windows\system32\DRIVERS\WinUsb.sys 2011/06/04 19:18:25.0745 5864 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys 2011/06/04 19:18:25.0807 5864 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys 2011/06/04 19:18:25.0854 5864 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\windows\system32\drivers\WudfPf.sys 2011/06/04 19:18:25.0901 5864 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\windows\system32\DRIVERS\WUDFRd.sys 2011/06/04 19:18:25.0963 5864 MBR (0x1B8) (5b5e648d12fcadc244c1ec30318e1eb9) \Device\Harddisk0\DR0 2011/06/04 19:18:25.0963 5864 ================================================================================ 2011/06/04 19:18:25.0963 5864 Scan finished 2011/06/04 19:18:25.0963 5864 ================================================================================ 2011/06/04 19:18:25.0979 3392 Detected object count: 0 2011/06/04 19:18:25.0979 3392 Actual detected object count: 0 2011/06/04 19:20:04.0098 6720 ================================================================================ 2011/06/04 19:20:04.0098 6720 Scan started 2011/06/04 19:20:04.0098 6720 Mode: Manual; 2011/06/04 19:20:04.0098 6720 ================================================================================ 2011/06/04 19:20:04.0707 6720 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\windows\system32\DRIVERS\1394ohci.sys 2011/06/04 19:20:04.0738 6720 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\windows\system32\DRIVERS\ACPI.sys 2011/06/04 19:20:04.0785 6720 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\windows\system32\DRIVERS\acpipmi.sys 2011/06/04 19:20:04.0832 6720 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys 2011/06/04 19:20:04.0878 6720 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys 2011/06/04 19:20:04.0910 6720 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys 2011/06/04 19:20:05.0019 6720 AFD (b9384e03479d2506bc924c16a3db87bc) C:\windows\system32\drivers\afd.sys 2011/06/04 19:20:05.0081 6720 AgereSoftModem (98022774d9930ecbb292e70db7601df6) C:\windows\system32\DRIVERS\agrsm64.sys 2011/06/04 19:20:05.0144 6720 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\DRIVERS\agp440.sys 2011/06/04 19:20:05.0159 6720 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\DRIVERS\aliide.sys 2011/06/04 19:20:05.0175 6720 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\DRIVERS\amdide.sys 2011/06/04 19:20:05.0206 6720 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys 2011/06/04 19:20:05.0378 6720 amdkmdag (aefaf27f1b7e52c705df4fb6c96732f6) C:\windows\system32\DRIVERS\atipmdag.sys 2011/06/04 19:20:05.0440 6720 amdkmdap (8149db73be27950ec72767a1193153a6) C:\windows\system32\DRIVERS\atikmpag.sys 2011/06/04 19:20:05.0471 6720 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys 2011/06/04 19:20:05.0518 6720 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\windows\system32\drivers\amdsata.sys 2011/06/04 19:20:05.0549 6720 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys 2011/06/04 19:20:05.0580 6720 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\windows\system32\drivers\amdxata.sys 2011/06/04 19:20:05.0596 6720 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\windows\system32\drivers\appid.sys 2011/06/04 19:20:05.0637 6720 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys 2011/06/04 19:20:05.0657 6720 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys 2011/06/04 19:20:05.0667 6720 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys 2011/06/04 19:20:05.0707 6720 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\DRIVERS\atapi.sys 2011/06/04 19:20:05.0757 6720 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys 2011/06/04 19:20:05.0797 6720 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys 2011/06/04 19:20:05.0837 6720 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys 2011/06/04 19:20:06.0007 6720 BHDrvx64 (3b9b31981894123f78c4ef0d97184319) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110518.001\BHDrvx64.sys 2011/06/04 19:20:06.0117 6720 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys 2011/06/04 19:20:06.0177 6720 bowser (19d20159708e152267e53b66677a4995) C:\windows\system32\DRIVERS\bowser.sys 2011/06/04 19:20:06.0227 6720 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys 2011/06/04 19:20:06.0247 6720 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys 2011/06/04 19:20:06.0267 6720 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys 2011/06/04 19:20:06.0287 6720 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys 2011/06/04 19:20:06.0307 6720 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys 2011/06/04 19:20:06.0317 6720 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys 2011/06/04 19:20:06.0337 6720 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys 2011/06/04 19:20:06.0387 6720 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys 2011/06/04 19:20:06.0417 6720 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\windows\system32\DRIVERS\cdrom.sys 2011/06/04 19:20:06.0447 6720 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys 2011/06/04 19:20:06.0487 6720 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys 2011/06/04 19:20:06.0557 6720 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys 2011/06/04 19:20:06.0587 6720 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\DRIVERS\cmdide.sys 2011/06/04 19:20:06.0607 6720 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\windows\system32\Drivers\cng.sys 2011/06/04 19:20:06.0727 6720 CnxtHdAudService (25c58ee97be0416a373e3e4f855206b5) C:\windows\system32\drivers\CHDRT64.sys 2011/06/04 19:20:06.0767 6720 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys 2011/06/04 19:20:06.0787 6720 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\windows\system32\DRIVERS\CompositeBus.sys 2011/06/04 19:20:06.0817 6720 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys 2011/06/04 19:20:06.0867 6720 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\windows\system32\Drivers\dfsc.sys 2011/06/04 19:20:06.0887 6720 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys 2011/06/04 19:20:06.0907 6720 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys 2011/06/04 19:20:06.0937 6720 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys 2011/06/04 19:20:07.0027 6720 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\windows\System32\drivers\dxgkrnl.sys 2011/06/04 19:20:07.0137 6720 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys 2011/06/04 19:20:07.0227 6720 eeCtrl (eb0883462ac43829e47929d705d40933) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 2011/06/04 19:20:07.0357 6720 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys 2011/06/04 19:20:07.0437 6720 EraserUtilRebootDrv (86fc0d272f6bb43e7214d4ba955a41e7) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2011/06/04 19:20:07.0547 6720 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\DRIVERS\errdev.sys 2011/06/04 19:20:07.0617 6720 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys 2011/06/04 19:20:07.0657 6720 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys 2011/06/04 19:20:07.0707 6720 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys 2011/06/04 19:20:07.0777 6720 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys 2011/06/04 19:20:07.0787 6720 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys 2011/06/04 19:20:07.0827 6720 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys 2011/06/04 19:20:07.0847 6720 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\windows\system32\drivers\fltmgr.sys 2011/06/04 19:20:07.0867 6720 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys 2011/06/04 19:20:07.0887 6720 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys 2011/06/04 19:20:07.0927 6720 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\windows\system32\DRIVERS\fvevol.sys 2011/06/04 19:20:07.0957 6720 FwLnk (60acb128e64c35c2b4e4aab1b0a5c293) C:\windows\system32\DRIVERS\FwLnk.sys 2011/06/04 19:20:07.0987 6720 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys 2011/06/04 19:20:08.0027 6720 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys 2011/06/04 19:20:08.0057 6720 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys 2011/06/04 19:20:08.0077 6720 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\windows\system32\drivers\HdAudio.sys 2011/06/04 19:20:08.0107 6720 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\windows\system32\DRIVERS\HDAudBus.sys 2011/06/04 19:20:08.0137 6720 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\windows\system32\DRIVERS\HECIx64.sys 2011/06/04 19:20:08.0167 6720 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys 2011/06/04 19:20:08.0187 6720 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys 2011/06/04 19:20:08.0207 6720 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys 2011/06/04 19:20:08.0237 6720 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\windows\system32\DRIVERS\hidusb.sys 2011/06/04 19:20:08.0267 6720 HpSAMD (0886d440058f203eba0e1825e4355914) C:\windows\system32\DRIVERS\HpSAMD.sys 2011/06/04 19:20:08.0287 6720 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\windows\system32\drivers\HTTP.sys 2011/06/04 19:20:08.0307 6720 hwpolicy (f17766a19145f111856378df337a5d79) C:\windows\system32\drivers\hwpolicy.sys 2011/06/04 19:20:08.0327 6720 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys 2011/06/04 19:20:08.0367 6720 iaStor (85977cd13fc16069ce0af7943a811775) C:\windows\system32\DRIVERS\iaStor.sys 2011/06/04 19:20:08.0417 6720 iaStorV (b75e45c564e944a2657167d197ab29da) C:\windows\system32\drivers\iaStorV.sys 2011/06/04 19:20:08.0567 6720 IDSVia64 (8f9faa4583e634a1505bad8d0c04c5c9) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110602.001\IDSvia64.sys 2011/06/04 19:20:08.0877 6720 igfx (898ab5bfed7040d7ab07af01885eb944) C:\windows\system32\DRIVERS\igdkmd64.sys 2011/06/04 19:20:08.0977 6720 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys 2011/06/04 19:20:09.0027 6720 Impcd (4b6363cd4610bb848531bb260b15dfcc) C:\windows\system32\DRIVERS\Impcd.sys 2011/06/04 19:20:09.0057 6720 IntcDAud (58cf58dee26c909bd6f977b61d246295) C:\windows\system32\DRIVERS\IntcDAud.sys 2011/06/04 19:20:09.0097 6720 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\DRIVERS\intelide.sys 2011/06/04 19:20:09.0117 6720 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys 2011/06/04 19:20:09.0137 6720 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\windows\system32\DRIVERS\ipfltdrv.sys 2011/06/04 19:20:09.0157 6720 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\windows\system32\DRIVERS\IPMIDrv.sys 2011/06/04 19:20:09.0177 6720 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys 2011/06/04 19:20:09.0197 6720 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys 2011/06/04 19:20:09.0217 6720 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\DRIVERS\isapnp.sys 2011/06/04 19:20:09.0257 6720 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\windows\system32\DRIVERS\msiscsi.sys 2011/06/04 19:20:09.0287 6720 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys 2011/06/04 19:20:09.0307 6720 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\windows\system32\DRIVERS\kbdhid.sys 2011/06/04 19:20:09.0387 6720 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\windows\system32\Drivers\ksecdd.sys 2011/06/04 19:20:09.0437 6720 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\windows\system32\Drivers\ksecpkg.sys 2011/06/04 19:20:09.0467 6720 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys 2011/06/04 19:20:09.0537 6720 L1C (55480b9c63f3f91a8ebbadcbf28fe581) C:\windows\system32\DRIVERS\L1C62x64.sys 2011/06/04 19:20:09.0587 6720 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys 2011/06/04 19:20:09.0637 6720 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys 2011/06/04 19:20:09.0647 6720 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys 2011/06/04 19:20:09.0667 6720 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys 2011/06/04 19:20:09.0677 6720 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys 2011/06/04 19:20:09.0708 6720 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys 2011/06/04 19:20:09.0724 6720 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys 2011/06/04 19:20:09.0755 6720 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys 2011/06/04 19:20:09.0771 6720 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys 2011/06/04 19:20:09.0818 6720 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys 2011/06/04 19:20:09.0833 6720 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys 2011/06/04 19:20:09.0849 6720 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys 2011/06/04 19:20:09.0864 6720 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\windows\system32\drivers\mountmgr.sys 2011/06/04 19:20:09.0911 6720 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\windows\system32\DRIVERS\mpio.sys 2011/06/04 19:20:09.0927 6720 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys 2011/06/04 19:20:09.0958 6720 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\windows\system32\drivers\mrxdav.sys 2011/06/04 19:20:09.0994 6720 mrxsmb (b7f3d2c40bdf8ffb73ebfb19c77734e2) C:\windows\system32\DRIVERS\mrxsmb.sys 2011/06/04 19:20:10.0024 6720 mrxsmb10 (86c6f88b5168ce21cf8d69d0b3ff5d19) C:\windows\system32\DRIVERS\mrxsmb10.sys 2011/06/04 19:20:10.0054 6720 mrxsmb20 (b081069251c8e9f42cb8769d07148f9c) C:\windows\system32\DRIVERS\mrxsmb20.sys 2011/06/04 19:20:10.0084 6720 msahci (5c37497276e3b3a5488b23a326a754b7) C:\windows\system32\DRIVERS\msahci.sys 2011/06/04 19:20:10.0114 6720 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\windows\system32\DRIVERS\msdsm.sys 2011/06/04 19:20:10.0144 6720 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys 2011/06/04 19:20:10.0164 6720 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys 2011/06/04 19:20:10.0184 6720 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\DRIVERS\msisadrv.sys 2011/06/04 19:20:10.0214 6720 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys 2011/06/04 19:20:10.0234 6720 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys 2011/06/04 19:20:10.0254 6720 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys 2011/06/04 19:20:10.0294 6720 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\windows\system32\drivers\MsRPC.sys 2011/06/04 19:20:10.0314 6720 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys 2011/06/04 19:20:10.0334 6720 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys 2011/06/04 19:20:10.0354 6720 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys 2011/06/04 19:20:10.0374 6720 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys 2011/06/04 19:20:10.0414 6720 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys 2011/06/04 19:20:10.0534 6720 NAVENG (f594e1acbbb3ba48586b5dd69b3a6bc2) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110603.002\ENG64.SYS 2011/06/04 19:20:10.0744 6720 NAVEX15 (cfe00b55488acf0cd9f62b0401297864) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110603.002\EX64.SYS 2011/06/04 19:20:10.0944 6720 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\windows\system32\drivers\ndis.sys 2011/06/04 19:20:11.0084 6720 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys 2011/06/04 19:20:11.0134 6720 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys 2011/06/04 19:20:11.0164 6720 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\windows\system32\DRIVERS\ndisuio.sys 2011/06/04 19:20:11.0204 6720 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\windows\system32\DRIVERS\ndiswan.sys 2011/06/04 19:20:11.0234 6720 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\windows\system32\drivers\NDProxy.sys 2011/06/04 19:20:11.0264 6720 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys 2011/06/04 19:20:11.0294 6720 NetBT (9162b273a44ab9dce5b44362731d062a) C:\windows\system32\DRIVERS\netbt.sys 2011/06/04 19:20:11.0374 6720 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys 2011/06/04 19:20:11.0424 6720 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys 2011/06/04 19:20:11.0464 6720 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys 2011/06/04 19:20:11.0574 6720 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\windows\system32\drivers\Ntfs.sys 2011/06/04 19:20:11.0644 6720 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys 2011/06/04 19:20:11.0674 6720 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\windows\system32\drivers\nvraid.sys 2011/06/04 19:20:11.0704 6720 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\windows\system32\drivers\nvstor.sys 2011/06/04 19:20:11.0754 6720 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\DRIVERS\nv_agp.sys 2011/06/04 19:20:11.0764 6720 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\DRIVERS\ohci1394.sys 2011/06/04 19:20:11.0804 6720 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys 2011/06/04 19:20:11.0824 6720 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\windows\system32\drivers\partmgr.sys 2011/06/04 19:20:11.0854 6720 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\windows\system32\DRIVERS\pci.sys 2011/06/04 19:20:11.0884 6720 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys 2011/06/04 19:20:11.0914 6720 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys 2011/06/04 19:20:11.0944 6720 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys 2011/06/04 19:20:11.0974 6720 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys 2011/06/04 19:20:12.0024 6720 PGEffect (663962900e7fea522126ba287715bb4a) C:\windows\system32\DRIVERS\pgeffect.sys 2011/06/04 19:20:12.0070 6720 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\windows\system32\DRIVERS\raspptp.sys 2011/06/04 19:20:12.0102 6720 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys 2011/06/04 19:20:12.0133 6720 Psched (ee992183bd8eaefd9973f352e587a299) C:\windows\system32\DRIVERS\pacer.sys 2011/06/04 19:20:12.0195 6720 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys 2011/06/04 19:20:12.0211 6720 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys 2011/06/04 19:20:12.0273 6720 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys 2011/06/04 19:20:12.0289 6720 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys 2011/06/04 19:20:12.0320 6720 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys 2011/06/04 19:20:12.0351 6720 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\windows\system32\DRIVERS\rasl2tp.sys 2011/06/04 19:20:12.0382 6720 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys 2011/06/04 19:20:12.0398 6720 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys 2011/06/04 19:20:12.0414 6720 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\windows\system32\DRIVERS\rdbss.sys 2011/06/04 19:20:12.0445 6720 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys 2011/06/04 19:20:12.0476 6720 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys 2011/06/04 19:20:12.0507 6720 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys 2011/06/04 19:20:12.0523 6720 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys 2011/06/04 19:20:12.0538 6720 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\windows\system32\drivers\RDPWD.sys 2011/06/04 19:20:12.0570 6720 rdyboost (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\windows\system32\drivers\rdyboost.sys 2011/06/04 19:20:12.0601 6720 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys 2011/06/04 19:20:12.0648 6720 RSUSBSTOR (907c4464381b5ebdfdc60f6c7d0dedfc) C:\windows\system32\Drivers\RtsUStor.sys 2011/06/04 19:20:12.0694 6720 RTL8192Ce (ffc748d848740d1bc8f330a8879c2674) C:\windows\system32\DRIVERS\rtl8192Ce.sys 2011/06/04 19:20:12.0741 6720 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\windows\system32\DRIVERS\sbp2port.sys 2011/06/04 19:20:12.0772 6720 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\windows\system32\DRIVERS\scfilter.sys 2011/06/04 19:20:12.0819 6720 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys 2011/06/04 19:20:12.0835 6720 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys 2011/06/04 19:20:12.0850 6720 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys 2011/06/04 19:20:12.0866 6720 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys 2011/06/04 19:20:12.0913 6720 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\DRIVERS\sffdisk.sys 2011/06/04 19:20:12.0928 6720 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\DRIVERS\sffp_mmc.sys 2011/06/04 19:20:12.0944 6720 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\windows\system32\DRIVERS\sffp_sd.sys 2011/06/04 19:20:12.0960 6720 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys 2011/06/04 19:20:13.0022 6720 Sftfs (72cd52403efc137290cb5a328510ebca) C:\windows\system32\DRIVERS\Sftfslh.sys 2011/06/04 19:20:13.0069 6720 Sftplay (31a36ef71af36eabcc4b4f8ab8f76465) C:\windows\system32\DRIVERS\Sftplaylh.sys 2011/06/04 19:20:13.0100 6720 Sftredir (2d969194fcc8eb41ed1d52863bfe7f52) C:\windows\system32\DRIVERS\Sftredirlh.sys 2011/06/04 19:20:13.0131 6720 Sftvol (08b36d2f63af3ca2248458a4280c0c50) C:\windows\system32\DRIVERS\Sftvollh.sys 2011/06/04 19:20:13.0178 6720 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys 2011/06/04 19:20:13.0194 6720 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys 2011/06/04 19:20:13.0209 6720 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys 2011/06/04 19:20:13.0240 6720 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys 2011/06/04 19:20:13.0303 6720 SRTSP (90ef30c3867bcde4579c01a6d6e75a7a) C:\windows\system32\drivers\N360x64\0501000.01D\SRTSP64.SYS 2011/06/04 19:20:13.0334 6720 SRTSPX (c513e8a5e7978da49077f5484344ee1b) C:\windows\system32\drivers\N360x64\0501000.01D\SRTSPX64.SYS 2011/06/04 19:20:13.0381 6720 srv (148d50904d2a0df29a19778715eb35bb) C:\windows\system32\DRIVERS\srv.sys 2011/06/04 19:20:13.0412 6720 srv2 (ce2189fe31d36678ac9eb7ddee08ec96) C:\windows\system32\DRIVERS\srv2.sys 2011/06/04 19:20:13.0443 6720 srvnet (cb69edeb069a49577592835659cd0e46) C:\windows\system32\DRIVERS\srvnet.sys 2011/06/04 19:20:13.0506 6720 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys 2011/06/04 19:20:13.0537 6720 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys 2011/06/04 19:20:13.0584 6720 SymDS (6160145c7a87fc7672e8e3b886888176) C:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS 2011/06/04 19:20:13.0646 6720 SymEFA (96aeed40d4d3521568b42027687e69e0) C:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS 2011/06/04 19:20:13.0687 6720 SymEvent (21a1c2d694c3cf962d31f5e873ab3d6f) C:\windows\system32\Drivers\SYMEVENT64x86.SYS 2011/06/04 19:20:13.0717 6720 SymIRON (bd0d711d8cbfcaa19ca123306eaf53a5) C:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS 2011/06/04 19:20:13.0787 6720 SymNetS (81d134628a98a22b6e054e971af525dc) C:\windows\system32\drivers\N360x64\0501000.01D\SYMNETS.SYS 2011/06/04 19:20:13.0987 6720 SynTP (470c47daba9ca3966f0ab3f835d7d135) C:\windows\system32\DRIVERS\SynTP.sys 2011/06/04 19:20:14.0107 6720 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\windows\system32\drivers\tcpip.sys 2011/06/04 19:20:14.0177 6720 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\windows\system32\DRIVERS\tcpip.sys 2011/06/04 19:20:14.0247 6720 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\windows\system32\drivers\tcpipreg.sys 2011/06/04 19:20:14.0287 6720 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\windows\system32\DRIVERS\tdcmdpst.sys 2011/06/04 19:20:14.0317 6720 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys 2011/06/04 19:20:14.0337 6720 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys 2011/06/04 19:20:14.0357 6720 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\windows\system32\DRIVERS\tdx.sys 2011/06/04 19:20:14.0407 6720 TermDD (c448651339196c0e869a355171875522) C:\windows\system32\DRIVERS\termdd.sys 2011/06/04 19:20:14.0487 6720 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\windows\system32\DRIVERS\tssecsrv.sys 2011/06/04 19:20:14.0517 6720 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\windows\system32\DRIVERS\tunnel.sys 2011/06/04 19:20:14.0557 6720 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\windows\system32\DRIVERS\TVALZ_O.SYS 2011/06/04 19:20:14.0587 6720 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\windows\system32\DRIVERS\TVALZFL.sys 2011/06/04 19:20:14.0637 6720 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys 2011/06/04 19:20:14.0667 6720 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\windows\system32\DRIVERS\udfs.sys 2011/06/04 19:20:14.0693 6720 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\DRIVERS\uliagpkx.sys 2011/06/04 19:20:14.0708 6720 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\windows\system32\DRIVERS\umbus.sys 2011/06/04 19:20:14.0724 6720 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys 2011/06/04 19:20:14.0786 6720 USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\windows\system32\Drivers\usbaapl64.sys 2011/06/04 19:20:14.0818 6720 usbccgp (537a4e03d7103c12d42dfd8ffdb5bdc9) C:\windows\system32\DRIVERS\usbccgp.sys 2011/06/04 19:20:14.0864 6720 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\DRIVERS\usbcir.sys 2011/06/04 19:20:14.0896 6720 usbehci (fbb21ebe49f6d560db37ac25fbc68e66) C:\windows\system32\drivers\usbehci.sys 2011/06/04 19:20:14.0927 6720 usbhub (6b7a8a99c4a459e73c286a6763ea24cc) C:\windows\system32\DRIVERS\usbhub.sys 2011/06/04 19:20:14.0958 6720 usbohci (8c88aa7617b4cbc2e4bed61d26b33a27) C:\windows\system32\drivers\usbohci.sys 2011/06/04 19:20:14.0989 6720 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys 2011/06/04 19:20:15.0020 6720 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys 2011/06/04 19:20:15.0052 6720 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\windows\system32\DRIVERS\USBSTOR.SYS 2011/06/04 19:20:15.0083 6720 usbuhci (0b5b3b2df3fd1709618acfa50b8392b0) C:\windows\system32\drivers\usbuhci.sys 2011/06/04 19:20:15.0130 6720 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\windows\System32\Drivers\usbvideo.sys 2011/06/04 19:20:15.0161 6720 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\DRIVERS\vdrvroot.sys 2011/06/04 19:20:15.0208 6720 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys 2011/06/04 19:20:15.0223 6720 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys 2011/06/04 19:20:15.0239 6720 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\windows\system32\DRIVERS\vhdmp.sys 2011/06/04 19:20:15.0254 6720 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\DRIVERS\viaide.sys 2011/06/04 19:20:15.0286 6720 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\windows\system32\DRIVERS\volmgr.sys 2011/06/04 19:20:15.0332 6720 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\windows\system32\drivers\volmgrx.sys 2011/06/04 19:20:15.0348 6720 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\windows\system32\DRIVERS\volsnap.sys 2011/06/04 19:20:15.0379 6720 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys 2011/06/04 19:20:15.0395 6720 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys 2011/06/04 19:20:15.0426 6720 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys 2011/06/04 19:20:15.0442 6720 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\windows\system32\DRIVERS\vwifimp.sys 2011/06/04 19:20:15.0504 6720 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys 2011/06/04 19:20:15.0551 6720 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys 2011/06/04 19:20:15.0582 6720 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys 2011/06/04 19:20:15.0660 6720 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys 2011/06/04 19:20:15.0676 6720 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys 2011/06/04 19:20:15.0738 6720 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys 2011/06/04 19:20:15.0769 6720 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys 2011/06/04 19:20:15.0832 6720 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\windows\system32\DRIVERS\WinUsb.sys 2011/06/04 19:20:15.0878 6720 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys 2011/06/04 19:20:15.0925 6720 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys 2011/06/04 19:20:15.0972 6720 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\windows\system32\drivers\WudfPf.sys 2011/06/04 19:20:15.0988 6720 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\windows\system32\DRIVERS\WUDFRd.sys 2011/06/04 19:20:16.0019 6720 MBR (0x1B8) (5b5e648d12fcadc244c1ec30318e1eb9) \Device\Harddisk0\DR0 2011/06/04 19:20:16.0034 6720 ================================================================================ 2011/06/04 19:20:16.0034 6720 Scan finished 2011/06/04 19:20:16.0034 6720 ================================================================================ 2011/06/04 19:20:16.0050 6796 Detected object count: 0 2011/06/04 19:20:16.0050 6796 Actual detected object count: 0 2011/06/04 19:20:29.0954 4468 Deinitialize success
Is that all the Combofix log? there seems to be half of it missing.




Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please










Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
ComboFix log ComboFix 11-06-04.02 - owner 06/04/2011 19:22:19.4.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3895.2592 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Norton Internet Security *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\YouTube Downloader Toolbar\IE\4.3\yoUTubedownloadertoolbarie.dll c:\windows\system32\Thumbs.db c:\windows\SysWow64\.dll . . ((((((((((((((((((((((((( Files Created from 2011-05-04 to 2011-06-04 ))))))))))))))))))))))))))))))) . . 2011-06-04 23:26 . 2011-06-04 23:26 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-05-25 19:51 . 2011-05-30 14:52 ——– d—–w- c:\users\owner\AppData\Local\CrashDumps 2011-05-24 18:21 . 2011-04-22 20:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-23 21:16 . 2011-05-23 21:16 ——– d—–w- c:\users\owner\AppData\Local\Apps 2011-05-23 21:16 . 2011-05-23 21:17 ——– d—–w- c:\users\owner\AppData\Local\Deployment 2011-05-21 00:01 . 2011-05-21 00:01 ——– d—–w- c:\users\owner\AppData\Local\Diagnostics 2011-05-20 16:14 . 2011-05-20 16:14 174200 —-a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\program files\Symantec 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\program files\Common Files\Symantec Shared 2011-05-20 16:14 . 2010-08-21 03:59 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\windows\system32\drivers\N360x64 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\program files (x86)\Norton 360 Premier Edition 2011-05-20 16:12 . 2011-05-20 16:12 ——– d—–w- c:\programdata\PCSettings 2011-05-20 15:19 . 2011-05-20 15:19 50320 —-a-w- c:\windows\SysWow64\wtwmdelvyeht.exe 2011-05-20 15:19 . 2011-05-20 15:19 468054 —-a-w- c:\program files (x86)\Drivers_pack_v4.55.63_fix.exe 2011-05-20 15:19 . 2011-05-20 15:19 106496 –sha-r- c:\windows\SysWow64\iprtprio9.dll 2011-05-18 23:14 . 2011-04-18 13:15 8802128 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6083372B-52BF-4B6F-8AC8-6A2C437795EC}\mpengine.dll 2011-05-18 23:14 . 2011-04-09 06:58 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-05-18 23:14 . 2011-04-09 05:56 123904 —-a-w- c:\windows\SysWow64\poqexec.exe 2011-05-16 23:31 . 2011-02-02 22:11 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-05-11 20:41 . 2011-04-09 06:45 5509504 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-05-11 20:41 . 2011-04-09 06:13 3957632 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-05-11 20:41 . 2011-04-09 06:13 3901824 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-05-11 20:41 . 2011-03-29 03:32 52224 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-11 20:41 . 2011-03-29 03:32 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-11 20:41 . 2011-03-29 03:32 99328 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-11 20:41 . 2011-03-29 03:32 324608 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-05-11 20:41 . 2011-03-29 03:32 25600 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-05-11 20:41 . 2011-03-29 03:32 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-11 20:41 . 2011-03-29 03:32 7936 —-a-w- c:\windows\system32\drivers\usbd.sys 2011-05-08 18:16 . 2011-05-15 02:05 ——– d—–w- c:\users\owner\AppData\Local\Apple Computer 2011-05-08 18:16 . 2011-05-09 15:56 ——– d—–w- c:\users\owner\AppData\Roaming\Apple Computer 2011-05-08 18:16 . 2011-05-20 16:14 ——– dc—-w- c:\windows\system32\DRVSTORE 2011-05-08 18:16 . 2010-08-21 03:59 125872 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-05-08 18:16 . 2010-08-21 03:59 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\users\owner\AppData\Local\Apple 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files\Common Files\Apple 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files\Bonjour 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files (x86)\Bonjour 2011-05-08 18:14 . 2011-05-09 15:34 ——– d—–w- c:\programdata\Apple 2011-05-08 18:14 . 2011-05-08 18:15 ——– d—–w- c:\program files (x86)\Common Files\Apple . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-15 15:11 . 2011-04-15 15:11 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2011-04-15 15:11 . 2011-04-15 15:11 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2011-04-15 15:11 . 2011-04-15 15:11 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2011-04-15 15:11 . 2011-04-15 15:11 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2011-04-15 15:11 . 2011-04-15 15:11 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2011-04-15 15:11 . 2011-04-15 15:11 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2011-04-15 15:11 . 2011-04-15 15:11 367104 —-a-w- c:\windows\SysWow64\html.iec 2011-04-15 15:11 . 2011-04-15 15:11 1797632 —-a-w- c:\windows\SysWow64\jscript9.dll 2011-04-15 15:11 . 2011-04-15 15:11 1126912 —-a-w- c:\windows\SysWow64\wininet.dll 2011-04-15 15:11 . 2011-04-15 15:11 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2011-04-15 15:11 . 2011-04-15 15:11 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2011-04-15 15:11 . 2011-04-15 15:11 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2011-04-15 15:11 . 2011-04-15 15:11 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-04-15 15:11 . 2011-04-15 15:11 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2011-04-15 15:11 . 2011-04-15 15:11 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2011-04-15 15:11 . 2011-04-15 15:11 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2011-04-15 15:11 . 2011-04-15 15:11 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2011-04-15 15:11 . 2011-04-15 15:11 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2011-04-15 15:11 . 2011-04-15 15:11 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2011-04-15 15:11 . 2011-04-15 15:11 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2011-04-15 15:11 . 2011-04-15 15:11 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-04-15 15:11 . 2011-04-15 15:11 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2011-04-15 15:11 . 2011-04-15 15:11 222208 —-a-w- c:\windows\system32\msls31.dll 2011-04-15 15:11 . 2011-04-15 15:11 1389056 —-a-w- c:\windows\system32\wininet.dll 2011-04-15 15:11 . 2011-04-15 15:11 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-04-15 15:11 . 2011-04-15 15:11 2303488 —-a-w- c:\windows\system32\jscript9.dll 2011-04-15 15:11 . 2011-04-15 15:11 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2011-04-15 15:11 . 2011-04-15 15:11 12288 —-a-w- c:\windows\system32\mshta.exe 2011-04-15 15:11 . 2011-04-15 15:11 114176 —-a-w- c:\windows\system32\admparse.dll 2011-04-15 15:11 . 2011-04-15 15:11 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-04-15 15:11 . 2011-04-15 15:11 85504 —-a-w- c:\windows\system32\iesetup.dll 2011-04-15 15:11 . 2011-04-15 15:11 76800 —-a-w- c:\windows\system32\tdc.ocx 2011-04-15 15:11 . 2011-04-15 15:11 49664 —-a-w- c:\windows\system32\imgutil.dll 2011-04-15 15:11 . 2011-04-15 15:11 48640 —-a-w- c:\windows\system32\mshtmler.dll 2011-04-15 15:11 . 2011-04-15 15:11 448512 —-a-w- c:\windows\system32\html.iec 2011-04-15 15:11 . 2011-04-15 15:11 30720 —-a-w- c:\windows\system32\licmgr10.dll 2011-04-15 15:11 . 2011-04-15 15:11 160256 —-a-w- c:\windows\system32\wextract.exe 2011-04-15 15:11 . 2011-04-15 15:11 1492992 —-a-w- c:\windows\system32\inetcpl.cpl 2011-04-15 15:11 . 2011-04-15 15:11 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2011-04-15 15:11 . 2011-04-15 15:11 111616 —-a-w- c:\windows\system32\iesysprep.dll 2011-04-15 15:11 . 2011-04-15 15:11 603648 —-a-w- c:\windows\system32\vbscript.dll 2011-04-15 15:11 . 2011-04-15 15:11 165888 —-a-w- c:\windows\system32\iexpress.exe 2011-04-06 20:26 . 2011-04-06 20:26 96544 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 20:26 . 2011-04-06 20:26 69408 —-a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 20:26 . 2011-04-06 20:26 237856 —-a-w- c:\windows\system32\dnssdX.dll 2011-04-06 20:26 . 2011-04-06 20:26 119584 —-a-w- c:\windows\system32\dns-sd.exe 2011-04-06 20:20 . 2011-04-06 20:20 91424 —-a-w- c:\windows\SysWow64\dnssd.dll 2011-04-06 20:20 . 2011-04-06 20:20 75040 —-a-w- c:\windows\SysWow64\jdns_sd.dll 2011-04-06 20:20 . 2011-04-06 20:20 197920 —-a-w- c:\windows\SysWow64\dnssdX.dll 2011-04-06 20:20 . 2011-04-06 20:20 107808 —-a-w- c:\windows\SysWow64\dns-sd.exe 2011-03-12 12:03 . 2011-04-27 14:31 662528 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-12 11:31 . 2011-04-27 14:31 442880 —-a-w- c:\windows\SysWow64\XpsPrint.dll 2011-03-11 06:23 . 2011-04-27 14:31 187264 —-a-w- c:\windows\system32\drivers\storport.sys 2011-03-11 06:23 . 2011-04-27 14:31 1657216 —-a-w- c:\windows\system32\drivers\ntfs.sys 2011-03-11 06:23 . 2011-04-27 14:31 166272 —-a-w- c:\windows\system32\drivers\nvstor.sys 2011-03-11 06:23 . 2011-04-27 14:31 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys 2011-03-11 06:23 . 2011-04-27 14:31 410496 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2011-03-11 06:22 . 2011-04-27 14:31 107904 —-a-w- c:\windows\system32\drivers\amdsata.sys 2011-03-11 06:22 . 2011-04-27 14:31 27008 —-a-w- c:\windows\system32\drivers\amdxata.sys 2011-03-11 06:19 . 2011-04-15 14:18 1395712 —-a-w- c:\windows\system32\mfc42.dll 2011-03-11 06:19 . 2011-04-15 14:18 1359872 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-11 06:18 . 2011-04-27 14:31 2566144 —-a-w- c:\windows\system32\esent.dll 2011-03-11 06:15 . 2011-04-27 14:31 96768 —-a-w- c:\windows\system32\fsutil.exe 2011-03-11 05:40 . 2011-04-15 14:18 1164288 —-a-w- c:\windows\SysWow64\mfc42u.dll 2011-03-11 05:40 . 2011-04-15 14:18 1137664 —-a-w- c:\windows\SysWow64\mfc42.dll 2011-03-11 05:39 . 2011-04-27 14:31 1686016 —-a-w- c:\windows\SysWow64\esent.dll 2011-03-11 05:37 . 2011-04-27 14:31 74240 —-a-w- c:\windows\SysWow64\fsutil.exe 2011-03-08 06:14 . 2011-04-15 14:18 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-08 05:38 . 2011-04-15 14:18 740864 —-a-w- c:\windows\SysWow64\inetcomm.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "SearchSettings"="c:\program files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe" [2011-01-28 526336] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-27 421160] "vuqzcrshbnd"="c:\windows\System32\regsvr32.exe" [2009-07-14 14848] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.189\SSScheduler.exe [2010-9-2 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x] R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.189\McCHSvc.exe [2010-09-02 227232] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110518.001\BHDrvx64.sys [2011-04-19 1127032] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110602.001\IDSvia64.sys [2011-03-15 476792] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\N360x64\0501000.01D\SYMNETS.SYS [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [2011-01-28 387072] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-29 249200] S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664] S2 N360;Norton 360;c:\program files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-18 258928] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-20 136824] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768] S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-24 835952] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 57165348 *Deregistered* - 57165348 . Contents of the 'Scheduled Tasks' folder . 2011-06-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000Core.job - c:\users\owner\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-23 21:17] . 2011-06-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000UA.job - c:\users\owner\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-23 21:17] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-02-26 166424] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-02-26 391192] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-02-26 410648] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272] "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uStart Page = hxxp://www.toshiba.ca/welcome uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://www.toshiba.ca/welcome mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.2.1 . - - - - ORPHANS REMOVED - - - - . BHO-{38BA8B8B-651F-7E28-0D9B-EE755739F882} - c:\windows\SysWow64\.dll Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-(Default) - (no file) HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe AddRemove-wtwmdelvyeht - c:\windows\system32\wtwmdelvyeht.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360] "ImagePath"="\"c:\program files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-06-04 19:28:33 ComboFix-quarantined-files.txt 2011-06-04 23:28 . Pre-Run: 403,835,908,096 bytes free Post-Run: 403,815,575,552 bytes free . - - End Of File - - 2B1850CF0BAC23394C9069FC667643AA
ComboFix log ComboFix 11-06-04.02 - owner 06/04/2011 19:22:19.4.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3895.2592 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Norton Internet Security *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\YouTube Downloader Toolbar\IE\4.3\yoUTubedownloadertoolbarie.dll c:\windows\system32\Thumbs.db c:\windows\SysWow64\.dll . . ((((((((((((((((((((((((( Files Created from 2011-05-04 to 2011-06-04 ))))))))))))))))))))))))))))))) . . 2011-06-04 23:26 . 2011-06-04 23:26 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-05-25 19:51 . 2011-05-30 14:52 ——– d—–w- c:\users\owner\AppData\Local\CrashDumps 2011-05-24 18:21 . 2011-04-22 20:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-23 21:16 . 2011-05-23 21:16 ——– d—–w- c:\users\owner\AppData\Local\Apps 2011-05-23 21:16 . 2011-05-23 21:17 ——– d—–w- c:\users\owner\AppData\Local\Deployment 2011-05-21 00:01 . 2011-05-21 00:01 ——– d—–w- c:\users\owner\AppData\Local\Diagnostics 2011-05-20 16:14 . 2011-05-20 16:14 174200 —-a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\program files\Symantec 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\program files\Common Files\Symantec Shared 2011-05-20 16:14 . 2010-08-21 03:59 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\windows\system32\drivers\N360x64 2011-05-20 16:14 . 2011-05-20 16:14 ——– d—–w- c:\program files (x86)\Norton 360 Premier Edition 2011-05-20 16:12 . 2011-05-20 16:12 ——– d—–w- c:\programdata\PCSettings 2011-05-20 15:19 . 2011-05-20 15:19 50320 —-a-w- c:\windows\SysWow64\wtwmdelvyeht.exe 2011-05-20 15:19 . 2011-05-20 15:19 468054 —-a-w- c:\program files (x86)\Drivers_pack_v4.55.63_fix.exe 2011-05-20 15:19 . 2011-05-20 15:19 106496 –sha-r- c:\windows\SysWow64\iprtprio9.dll 2011-05-18 23:14 . 2011-04-18 13:15 8802128 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6083372B-52BF-4B6F-8AC8-6A2C437795EC}\mpengine.dll 2011-05-18 23:14 . 2011-04-09 06:58 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-05-18 23:14 . 2011-04-09 05:56 123904 —-a-w- c:\windows\SysWow64\poqexec.exe 2011-05-16 23:31 . 2011-02-02 22:11 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-05-11 20:41 . 2011-04-09 06:45 5509504 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-05-11 20:41 . 2011-04-09 06:13 3957632 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-05-11 20:41 . 2011-04-09 06:13 3901824 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-05-11 20:41 . 2011-03-29 03:32 52224 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-11 20:41 . 2011-03-29 03:32 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-11 20:41 . 2011-03-29 03:32 99328 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-11 20:41 . 2011-03-29 03:32 324608 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-05-11 20:41 . 2011-03-29 03:32 25600 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-05-11 20:41 . 2011-03-29 03:32 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-11 20:41 . 2011-03-29 03:32 7936 —-a-w- c:\windows\system32\drivers\usbd.sys 2011-05-08 18:16 . 2011-05-15 02:05 ——– d—–w- c:\users\owner\AppData\Local\Apple Computer 2011-05-08 18:16 . 2011-05-09 15:56 ——– d—–w- c:\users\owner\AppData\Roaming\Apple Computer 2011-05-08 18:16 . 2011-05-20 16:14 ——– dc—-w- c:\windows\system32\DRVSTORE 2011-05-08 18:16 . 2010-08-21 03:59 125872 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-05-08 18:16 . 2010-08-21 03:59 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\users\owner\AppData\Local\Apple 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files\Common Files\Apple 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files\Bonjour 2011-05-08 18:14 . 2011-05-08 18:14 ——– d—–w- c:\program files (x86)\Bonjour 2011-05-08 18:14 . 2011-05-09 15:34 ——– d—–w- c:\programdata\Apple 2011-05-08 18:14 . 2011-05-08 18:15 ——– d—–w- c:\program files (x86)\Common Files\Apple . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-15 15:11 . 2011-04-15 15:11 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2011-04-15 15:11 . 2011-04-15 15:11 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2011-04-15 15:11 . 2011-04-15 15:11 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2011-04-15 15:11 . 2011-04-15 15:11 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2011-04-15 15:11 . 2011-04-15 15:11 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2011-04-15 15:11 . 2011-04-15 15:11 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2011-04-15 15:11 . 2011-04-15 15:11 367104 —-a-w- c:\windows\SysWow64\html.iec 2011-04-15 15:11 . 2011-04-15 15:11 1797632 —-a-w- c:\windows\SysWow64\jscript9.dll 2011-04-15 15:11 . 2011-04-15 15:11 1126912 —-a-w- c:\windows\SysWow64\wininet.dll 2011-04-15 15:11 . 2011-04-15 15:11 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2011-04-15 15:11 . 2011-04-15 15:11 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2011-04-15 15:11 . 2011-04-15 15:11 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2011-04-15 15:11 . 2011-04-15 15:11 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-04-15 15:11 . 2011-04-15 15:11 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2011-04-15 15:11 . 2011-04-15 15:11 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2011-04-15 15:11 . 2011-04-15 15:11 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2011-04-15 15:11 . 2011-04-15 15:11 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2011-04-15 15:11 . 2011-04-15 15:11 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2011-04-15 15:11 . 2011-04-15 15:11 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2011-04-15 15:11 . 2011-04-15 15:11 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2011-04-15 15:11 . 2011-04-15 15:11 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-04-15 15:11 . 2011-04-15 15:11 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2011-04-15 15:11 . 2011-04-15 15:11 222208 —-a-w- c:\windows\system32\msls31.dll 2011-04-15 15:11 . 2011-04-15 15:11 1389056 —-a-w- c:\windows\system32\wininet.dll 2011-04-15 15:11 . 2011-04-15 15:11 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-04-15 15:11 . 2011-04-15 15:11 2303488 —-a-w- c:\windows\system32\jscript9.dll 2011-04-15 15:11 . 2011-04-15 15:11 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2011-04-15 15:11 . 2011-04-15 15:11 12288 —-a-w- c:\windows\system32\mshta.exe 2011-04-15 15:11 . 2011-04-15 15:11 114176 —-a-w- c:\windows\system32\admparse.dll 2011-04-15 15:11 . 2011-04-15 15:11 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-04-15 15:11 . 2011-04-15 15:11 85504 —-a-w- c:\windows\system32\iesetup.dll 2011-04-15 15:11 . 2011-04-15 15:11 76800 —-a-w- c:\windows\system32\tdc.ocx 2011-04-15 15:11 . 2011-04-15 15:11 49664 —-a-w- c:\windows\system32\imgutil.dll 2011-04-15 15:11 . 2011-04-15 15:11 48640 —-a-w- c:\windows\system32\mshtmler.dll 2011-04-15 15:11 . 2011-04-15 15:11 448512 —-a-w- c:\windows\system32\html.iec 2011-04-15 15:11 . 2011-04-15 15:11 30720 —-a-w- c:\windows\system32\licmgr10.dll 2011-04-15 15:11 . 2011-04-15 15:11 160256 —-a-w- c:\windows\system32\wextract.exe 2011-04-15 15:11 . 2011-04-15 15:11 1492992 —-a-w- c:\windows\system32\inetcpl.cpl 2011-04-15 15:11 . 2011-04-15 15:11 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2011-04-15 15:11 . 2011-04-15 15:11 111616 —-a-w- c:\windows\system32\iesysprep.dll 2011-04-15 15:11 . 2011-04-15 15:11 603648 —-a-w- c:\windows\system32\vbscript.dll 2011-04-15 15:11 . 2011-04-15 15:11 165888 —-a-w- c:\windows\system32\iexpress.exe 2011-04-06 20:26 . 2011-04-06 20:26 96544 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 20:26 . 2011-04-06 20:26 69408 —-a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 20:26 . 2011-04-06 20:26 237856 —-a-w- c:\windows\system32\dnssdX.dll 2011-04-06 20:26 . 2011-04-06 20:26 119584 —-a-w- c:\windows\system32\dns-sd.exe 2011-04-06 20:20 . 2011-04-06 20:20 91424 —-a-w- c:\windows\SysWow64\dnssd.dll 2011-04-06 20:20 . 2011-04-06 20:20 75040 —-a-w- c:\windows\SysWow64\jdns_sd.dll 2011-04-06 20:20 . 2011-04-06 20:20 197920 —-a-w- c:\windows\SysWow64\dnssdX.dll 2011-04-06 20:20 . 2011-04-06 20:20 107808 —-a-w- c:\windows\SysWow64\dns-sd.exe 2011-03-12 12:03 . 2011-04-27 14:31 662528 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-12 11:31 . 2011-04-27 14:31 442880 —-a-w- c:\windows\SysWow64\XpsPrint.dll 2011-03-11 06:23 . 2011-04-27 14:31 187264 —-a-w- c:\windows\system32\drivers\storport.sys 2011-03-11 06:23 . 2011-04-27 14:31 1657216 —-a-w- c:\windows\system32\drivers\ntfs.sys 2011-03-11 06:23 . 2011-04-27 14:31 166272 —-a-w- c:\windows\system32\drivers\nvstor.sys 2011-03-11 06:23 . 2011-04-27 14:31 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys 2011-03-11 06:23 . 2011-04-27 14:31 410496 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2011-03-11 06:22 . 2011-04-27 14:31 107904 —-a-w- c:\windows\system32\drivers\amdsata.sys 2011-03-11 06:22 . 2011-04-27 14:31 27008 —-a-w- c:\windows\system32\drivers\amdxata.sys 2011-03-11 06:19 . 2011-04-15 14:18 1395712 —-a-w- c:\windows\system32\mfc42.dll 2011-03-11 06:19 . 2011-04-15 14:18 1359872 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-11 06:18 . 2011-04-27 14:31 2566144 —-a-w- c:\windows\system32\esent.dll 2011-03-11 06:15 . 2011-04-27 14:31 96768 —-a-w- c:\windows\system32\fsutil.exe 2011-03-11 05:40 . 2011-04-15 14:18 1164288 —-a-w- c:\windows\SysWow64\mfc42u.dll 2011-03-11 05:40 . 2011-04-15 14:18 1137664 —-a-w- c:\windows\SysWow64\mfc42.dll 2011-03-11 05:39 . 2011-04-27 14:31 1686016 —-a-w- c:\windows\SysWow64\esent.dll 2011-03-11 05:37 . 2011-04-27 14:31 74240 —-a-w- c:\windows\SysWow64\fsutil.exe 2011-03-08 06:14 . 2011-04-15 14:18 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-08 05:38 . 2011-04-15 14:18 740864 —-a-w- c:\windows\SysWow64\inetcomm.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "SearchSettings"="c:\program files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe" [2011-01-28 526336] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-27 421160] "vuqzcrshbnd"="c:\windows\System32\regsvr32.exe" [2009-07-14 14848] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.189\SSScheduler.exe [2010-9-2 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x] R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.189\McCHSvc.exe [2010-09-02 227232] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110518.001\BHDrvx64.sys [2011-04-19 1127032] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110602.001\IDSvia64.sys [2011-03-15 476792] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\N360x64\0501000.01D\SYMNETS.SYS [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [2011-01-28 387072] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-29 249200] S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664] S2 N360;Norton 360;c:\program files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-18 258928] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-20 136824] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768] S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-24 835952] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 57165348 *Deregistered* - 57165348 . Contents of the 'Scheduled Tasks' folder . 2011-06-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000Core.job - c:\users\owner\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-23 21:17] . 2011-06-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000UA.job - c:\users\owner\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-23 21:17] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-02-26 166424] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-02-26 391192] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-02-26 410648] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272] "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uStart Page = hxxp://www.toshiba.ca/welcome uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://www.toshiba.ca/welcome mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.2.1 . - - - - ORPHANS REMOVED - - - - . BHO-{38BA8B8B-651F-7E28-0D9B-EE755739F882} - c:\windows\SysWow64\.dll Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-(Default) - (no file) HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe AddRemove-wtwmdelvyeht - c:\windows\system32\wtwmdelvyeht.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360] "ImagePath"="\"c:\program files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-06-04 19:28:33 ComboFix-quarantined-files.txt 2011-06-04 23:28 . Pre-Run: 403,835,908,096 bytes free Post-Run: 403,815,575,552 bytes free . - - End Of File - - 2B1850CF0BAC23394C9069FC667643AA
When I click on the links provided for downloading Malwarebyte, it downloads Reimage and after the scan, once I click on the repair button it asks me to sign up and pay. Is there another site where I can download Malwarebyte from?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI