This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My computer start up is really slow

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello I'm David Nelson. Just about a month ago I turned on my computer and a screen popped up. something to do with my hard drive and that i need to back up my files immediatly. AFter i backed it all up I rebooted my whole computer and still, that screen when i turn on my computer pops up. I downloaded hijack this and wanted to see if that would help at all with fixing this. overall everything on my computer works fine… just the start up is so so so slow and sometimes programs do not repsond always…. i don't know if I need to get a new hard drive or if it just might be a dumb virus. So if you can at all help i would truely be thankful!!!

Here is my hijack log….

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:51:40 AM, on 6/8/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\David\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: EgisPBIE - {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisPBIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2380.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2380.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2380.0\npwinext.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [VitaKeyTSR] C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe /run
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: CinemaNow Service - CinemaNow, Inc. - C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Red Bend Device Management Service (DMAgent) - Red Bend Ltd. - C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\SwSetup\HPQWMM\QuickWeb\QW.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EgisTec Service - Egis Technology Inc. - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HPWMISVC - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - iolo technologies, LLC - C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - iolo technologies, LLC - C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Intel® PROSet/Wireless WiMAX Service (WiMAXAppSrv) - Intel® Corporation - C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

–
End of file - 12339 bytes
Hello drnelson and welcome to the WTT forum.


My username is Astabi and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:

Please do not install/uninstall any programs unless asked to.
Please do not run any scans other than those requested
Please follow all instructions in the order posted
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
If you don't understand something, please don't hesitate to ask for clarification before proceeding
The fixes are specific to your problem and should only be used for this issue on this machine.
Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!


Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.


Thanks,
Astabi
Hello drnelson,

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions.  If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • WiNlOgOn.exe
  • uSeRiNiT.exe

Do not reboot your computer after running rkill as the malware programs will start again.

Then,

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan results.

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Next,

Download aswMBR.exe( 511KB ) to your desktop.

Double click the aswMBR.exe to run it
[external image: Posted Image]
Click the "Scan" button to start scan
[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply.

In your next post provide:
  • DDS Log
  • Attach.txt (attached)
  • aswMBR log

Thanks,
Astabi
I'm sorry but the DSS link you gave me wont work… this is what shows up We're sorry, but your last request produced the following error: An internal error occurred. Please contact an administrator Thank you.
Hello, Lets try it differently,

Put this in place of the dds instructions earlier.

Download and run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • dds.scr
    • dds.com
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results soon.
  • Follow the instructions that pop up for posting the results and then click Ok.
  • The black and message box window shall then disappear.
  • Please save both log files on your desktop and post the DDS.txt and zip up and attach Attach.txt as instructed.

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

Thanks,

Astabi
here is the dss log… —————————————————————————————————————- DDS (Ver_2011-06-11.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 18:30:27 on 2011-06-10 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3894.1709 [GMT -7:00] . AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\IDT\WDM\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\vcsFPService.exe C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\IDT\WDM\AESTSr64.exe C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe C:\SwSetup\HPQWMM\QuickWeb\QW.SYS\config\DVMExportService.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.AutoUpdate.exe C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe C:\Program Files (x86)\iolo\System Mechanic Professional\SMSystemAnalyzer.exe C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe C:\Program Files (x86)\Windows Media Player\wmplayer.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe C:\Windows\system32\WUDFHost.exe C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Transcoder.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\wuauclt.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . mWinlogon: Userinit=userinit.exe BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO: Window Shopper: {74f475fa-6c75-43bd-aab9-ecda6184f600} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll BHO: EgisPBIE Class: {7b51ccbe-4af9-44a6-bdab-d7f7e4c4e6f9} - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisPBIE.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2380.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2380.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2380.0\npwinext.dll TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll uRun: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d mRun: [VitaKeyTSR] C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe /run mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot mRun: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun: [] mRunOnce: [SMRequiresRestart] mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{58D9788E-958C-44A8-BD92-C5037ED6FE8F} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{58D9788E-958C-44A8-BD92-C5037ED6FE8F}\14E67656C67237 : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{58D9788E-958C-44A8-BD92-C5037ED6FE8F}\25F62696E637F6E6F5145747F6 : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{58D9788E-958C-44A8-BD92-C5037ED6FE8F}\9484343475C414E4 : DhcpNameServer = 192.168.193.108 192.168.193.109 TCP: Interfaces\{58D9788E-958C-44A8-BD92-C5037ED6FE8F}\E4544574541425 : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{E3F8C82C-4C4A-4018-83B5-189C939BCFF1} : NameServer = 166.181.191.17 166.181.127.17 Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll LSA: Notification Packages = EgisPwdFilter EgisDSPwdFilter BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO-X64: 0x1 - No File BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll BHO-X64: Symantec NCO BHO - No File BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL BHO-X64: Symantec Intrusion Prevention - No File BHO-X64: StartNow Toolbar Helper: {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll BHO-X64: StartNowToolbarHelper - No File BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO-X64: Search Helper - No File BHO-X64: Window Shopper: {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll BHO-X64: WindowShopper - No File BHO-X64: EgisPBIE Class: {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisPBIE.dll BHO-X64: EgisPBIE - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2380.0\npwinext.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll TB-X64: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2380.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2380.0\npwinext.dll TB-X64: StartNow Toolbar: {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun-x64: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" mRun-x64: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d mRun-x64: [VitaKeyTSR] C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe /run mRun-x64: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe mRun-x64: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe mRun-x64: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot mRun-x64: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun-x64: [(Default)] mRunOnce-x64: [SMRequiresRestart] . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS –> C:\Windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS [?] R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS –> C:\Windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [?] R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\Definitions\BASHDefs\20110518.001\BHDrvx64.sys [2011-5-18 1127032] R1 DVMIO;DeviceVM IO Service;C:\Windows\system32\DRIVERS\dvmio.sys –> C:\Windows\system32\DRIVERS\dvmio.sys [?] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\Definitions\IPSDefs\20110604.001\IDSviA64.sys [2011-6-2 488056] R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS –> C:\Windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS [?] R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\NISx64\1206000.01D\SYMNETS.SYS –> C:\Windows\system32\Drivers\NISx64\1206000.01D\SYMNETS.SYS [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2010-12-8 89600] R2 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2010-6-12 400368] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664] R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2010-6-7 408576] R2 DvmMDES;DeviceVM Meta Data Export Service;C:\SwSetup\HPQWMM\QuickWeb\QW.SYS\config\DVMExportService.exe [2010-6-25 338168] R2 EgisTec Service;EgisTec Service;C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe [2010-6-8 697712] R2 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2010-6-8 646000] R2 HP Wireless Assistant Service;HP Wireless Assistant Service;C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-6-18 103992] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-6-25 92216] R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-6-29 27192] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-12-8 13336] R2 ioloFileInfoList;iolo FileInfoList Service;C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2011-5-21 724152] R2 ioloSystemService;iolo System Service;C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2011-5-21 724152] R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe [2011-5-19 130008] R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-4-24 483688] R3 bpenum;bpenum;C:\Windows\system32\DRIVERS\bpenum.sys –> C:\Windows\system32\DRIVERS\bpenum.sys [?] R3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\Windows\system32\DRIVERS\bpmp.sys –> C:\Windows\system32\DRIVERS\bpmp.sys [?] R3 bpusb;bpusb;C:\Windows\system32\Drivers\bpusb.sys –> C:\Windows\system32\Drivers\bpusb.sys [?] R3 clwvd;HP Webcam Splitter;C:\Windows\system32\DRIVERS\clwvd.sys –> C:\Windows\system32\DRIVERS\clwvd.sys [?] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-6-8 136824] R3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?] R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys –> C:\Windows\system32\DRIVERS\Impcd.sys [?] R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys –> C:\Windows\system32\DRIVERS\IntcDAud.sys [?] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-3-5 340240] R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETw5s64.sys –> C:\Windows\system32\DRIVERS\NETw5s64.sys [?] R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys –> C:\Windows\system32\DRIVERS\Sftfslh.sys [?] R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys –> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?] R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys –> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?] R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys –> C:\Windows\system32\DRIVERS\Sftvollh.sys [?] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-4-24 209768] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys –> C:\Windows\system32\DRIVERS\vwifimp.sys [?] R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys –> C:\Windows\system32\DRIVERS\WDKMD.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 AmUStor;AM USB Stroage Driver;C:\Windows\system32\drivers\AmUStor.SYS –> C:\Windows\system32\drivers\AmUStor.SYS [?] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys –> C:\Windows\system32\DRIVERS\netw5v64.sys [?] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS –> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?] S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS –> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS –> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys –> C:\Windows\system32\DRIVERS\yk62x64.sys [?] S4 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe –> C:\Windows\system32\Hpservice.exe [?] . =============== File Associations =============== . JSEFile=NOTEPAD.EXE %1neI?e? regfile=NOTEPAD.EXE %1neI?e? scrfile=NOTEPAD.EXE %1neI?e? VBEFile=NOTEPAD.EXE %1neI?e? VBSFile=NOTEPAD.EXE %1neI?e? . =============== Created Last 30 ================ . 2011-06-11 01:25:35 8718160 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{33F44265-794B-4BB7-872A-82B04CB46A68}\mpengine.dll 2011-06-11 01:25:24 ——– d—–w- C:\6cf8fc2d9341c318562a9fb203 2011-06-10 15:32:29 ——– d—–w- C:\Program Files (x86)\StartNow Toolbar 2011-06-10 15:23:02 ——– d—–w- C:\Program Files (x86)\Superfish 2011-06-06 00:34:45 ——– d-sh–w- C:\found.000 2011-06-02 02:57:46 ——– d—–w- C:\Users\David\AppData\Local\{CAEC8FF3-D5A7-478D-81D1-CD7A24CB2B35} 2011-06-01 04:58:34 ——– d—–w- C:\Users\David\AppData\Local\{358426CE-79A3-4F01-A752-491F7F19A942} 2011-05-30 22:34:26 ——– d—–w- C:\Users\David\AppData\Local\{D90CB075-D4A2-450E-BBF8-DD5ABC6537BF} 2011-05-30 22:01:30 ——– d—–w- C:\ProgramData\Spotmau 2011-05-30 22:01:14 ——– d—–w- C:\Users\David\AppData\Roaming\spotmau 2011-05-30 22:01:13 ——– d—–w- C:\ProgramData\pc health check 2011-05-30 22:00:46 ——– d—–w- C:\ProgramData\TuneUp360 2011-05-30 22:00:28 380224 —-a-w- C:\Windows\SysWow64\TuneUp360.ocx 2011-05-30 22:00:24 ——– d—–w- C:\Program Files (x86)\TuneUp360 2011-05-30 01:01:18 ——– d—–w- C:\Program Files (x86)\Call of Duty Game of the Year Edition 2011-05-28 03:50:28 ——– d—–w- C:\Program Files (x86)\MacGAMUT 2003 2011-05-28 03:50:04 57344 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll 2011-05-28 03:50:04 5632 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe 2011-05-28 03:50:04 237568 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll 2011-05-28 03:50:04 155648 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll 2011-05-28 03:50:03 692224 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll 2011-05-28 03:49:57 163972 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll 2011-05-28 03:49:56 282756 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll 2011-05-27 14:32:44 ——– d—–w- C:\Users\David\AppData\Local\{F89CED9D-CC33-4603-9DEA-E676D11BCAE7} 2011-05-27 14:32:44 ——– d—–w- C:\Users\David\AppData\Local\{E85E4382-4E66-4AF1-934C-E2647F0600B6} 2011-05-27 14:06:31 27008 —-a-w- C:\Windows\System32\drivers\Diskdump.sys 2011-05-26 20:55:37 ——– d—–w- C:\Program Files (x86)\Coupons 2011-05-26 20:54:17 ——– d—–w- C:\Users\David\AppData\Roaming\HpUpdate 2011-05-26 20:52:55 361320 ——w- C:\Windows\System32\HPDiscoPM9311.dll 2011-05-26 20:51:30 ——– d—–w- C:\Program Files (x86)\HP 2011-05-26 20:50:23 ——– d—–w- C:\Program Files\HP 2011-05-26 20:49:34 ——– d—–w- C:\Users\David\AppData\Local\HP 2011-05-26 17:10:44 1135104 —-a-w- C:\Windows\System32\FntCache.dll 2011-05-26 17:10:43 1540608 —-a-w- C:\Windows\System32\DWrite.dll 2011-05-26 17:10:43 1074176 —-a-w- C:\Windows\SysWow64\DWrite.dll 2011-05-26 17:10:42 902656 —-a-w- C:\Windows\System32\d2d1.dll 2011-05-26 17:10:42 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll 2011-05-25 02:50:19 ——– d—–w- C:\Program Files (x86)\Infogrames 2011-05-25 02:43:11 4711 —-a-w- C:\Windows\System32\dmouse.vxd 2011-05-25 02:43:07 ——– d—–w- C:\Program Files\Ultimate Doom for Windows 95 2011-05-25 02:24:00 ——– d—–w- C:\Users\David\AppData\Local\Microsoft Games 2011-05-24 21:23:45 ——– d—–w- C:\Users\David\AppData\Local\Microsoft Help 2011-05-24 01:41:16 306688 —-a-w- C:\Windows\IsUninst.exe 2011-05-23 03:16:17 77656 —-a-w- C:\Windows\System32\XAPOFX1_5.dll 2011-05-23 03:16:17 74072 —-a-w- C:\Windows\SysWow64\XAPOFX1_5.dll 2011-05-23 03:16:17 527192 —-a-w- C:\Windows\SysWow64\XAudio2_7.dll 2011-05-23 03:16:17 518488 —-a-w- C:\Windows\System32\XAudio2_7.dll 2011-05-23 03:14:40 238936 —-a-w- C:\Windows\SysWow64\xactengine3_6.dll 2011-05-23 03:14:40 176984 —-a-w- C:\Windows\System32\xactengine3_6.dll 2011-05-23 03:14:32 24920 —-a-w- C:\Windows\System32\X3DAudio1_7.dll 2011-05-23 03:14:32 22360 —-a-w- C:\Windows\SysWow64\X3DAudio1_7.dll 2011-05-23 03:14:21 517960 —-a-w- C:\Windows\System32\XAudio2_5.dll 2011-05-23 03:14:08 238936 —-a-w- C:\Windows\SysWow64\xactengine3_5.dll 2011-05-23 03:14:08 176968 —-a-w- C:\Windows\System32\xactengine3_5.dll 2011-05-23 03:14:01 2582888 —-a-w- C:\Windows\System32\D3DCompiler_42.dll 2011-05-23 03:14:01 1974616 —-a-w- C:\Windows\SysWow64\D3DCompiler_42.dll 2011-05-23 03:13:51 5554512 —-a-w- C:\Windows\System32\d3dcsx_42.dll 2011-05-23 03:13:51 5501792 —-a-w- C:\Windows\SysWow64\d3dcsx_42.dll 2011-05-23 03:13:46 285024 —-a-w- C:\Windows\System32\d3dx11_42.dll 2011-05-23 03:13:46 235344 —-a-w- C:\Windows\SysWow64\d3dx11_42.dll 2011-05-23 03:13:27 2475352 —-a-w- C:\Windows\System32\D3DX9_42.dll 2011-05-23 03:13:27 1892184 —-a-w- C:\Windows\SysWow64\D3DX9_42.dll 2011-05-23 03:13:10 520544 —-a-w- C:\Windows\System32\d3dx10_41.dll 2011-05-23 03:13:10 2430312 —-a-w- C:\Windows\System32\D3DCompiler_41.dll 2011-05-23 03:13:03 5425496 —-a-w- C:\Windows\System32\D3DX9_41.dll 2011-05-23 03:13:03 4178264 —-a-w- C:\Windows\SysWow64\D3DX9_41.dll 2011-05-23 03:11:55 74576 —-a-w- C:\Windows\System32\XAPOFX1_2.dll 2011-05-23 03:11:55 70992 —-a-w- C:\Windows\SysWow64\XAPOFX1_2.dll 2011-05-23 03:11:55 518480 —-a-w- C:\Windows\System32\XAudio2_3.dll 2011-05-23 03:11:55 514384 —-a-w- C:\Windows\SysWow64\XAudio2_3.dll 2011-05-23 03:11:37 235856 —-a-w- C:\Windows\SysWow64\xactengine3_3.dll 2011-05-23 03:11:37 175440 —-a-w- C:\Windows\System32\xactengine3_3.dll 2011-05-23 03:11:36 25936 —-a-w- C:\Windows\System32\X3DAudio1_5.dll 2011-05-23 03:11:36 23376 —-a-w- C:\Windows\SysWow64\X3DAudio1_5.dll 2011-05-23 03:11:13 72200 —-a-w- C:\Windows\System32\XAPOFX1_1.dll 2011-05-23 03:11:13 68616 —-a-w- C:\Windows\SysWow64\XAPOFX1_1.dll 2011-05-23 03:11:13 513544 —-a-w- C:\Windows\System32\XAudio2_2.dll 2011-05-23 03:11:13 509448 —-a-w- C:\Windows\SysWow64\XAudio2_2.dll 2011-05-23 03:09:57 238088 —-a-w- C:\Windows\SysWow64\xactengine3_1.dll 2011-05-23 03:08:47 529424 —-a-w- C:\Windows\System32\d3dx10_37.dll 2011-05-23 03:08:47 462864 —-a-w- C:\Windows\SysWow64\d3dx10_37.dll 2011-05-23 03:08:47 1860120 —-a-w- C:\Windows\System32\D3DCompiler_37.dll 2011-05-23 03:08:47 1420824 —-a-w- C:\Windows\SysWow64\D3DCompiler_37.dll 2011-05-23 03:08:39 4910088 —-a-w- C:\Windows\System32\D3DX9_37.dll 2011-05-23 03:08:39 3786760 —-a-w- C:\Windows\SysWow64\D3DX9_37.dll 2011-05-23 03:08:23 411656 —-a-w- C:\Windows\System32\xactengine2_10.dll 2011-05-23 03:08:23 267272 —-a-w- C:\Windows\SysWow64\xactengine2_10.dll 2011-05-23 03:08:09 508264 —-a-w- C:\Windows\System32\d3dx10_36.dll 2011-05-23 03:08:09 444776 —-a-w- C:\Windows\SysWow64\d3dx10_36.dll 2011-05-23 03:08:09 2006552 —-a-w- C:\Windows\System32\D3DCompiler_36.dll 2011-05-23 03:08:09 1374232 —-a-w- C:\Windows\SysWow64\D3DCompiler_36.dll 2011-05-23 03:06:58 506728 —-a-w- C:\Windows\System32\d3dx10_34.dll 2011-05-23 03:05:48 393576 —-a-w- C:\Windows\System32\xactengine2_6.dll 2011-05-23 03:05:29 255848 —-a-w- C:\Windows\SysWow64\xactengine2_6.dll 2011-05-23 03:05:10 390424 —-a-w- C:\Windows\System32\xactengine2_5.dll 2011-05-23 03:05:10 251672 —-a-w- C:\Windows\SysWow64\xactengine2_5.dll 2011-05-23 03:05:04 469264 —-a-w- C:\Windows\System32\d3dx10.dll 2011-05-23 03:05:04 440080 —-a-w- C:\Windows\SysWow64\d3dx10.dll 2011-05-23 03:03:53 364824 —-a-w- C:\Windows\System32\xactengine2_4.dll 2011-05-23 03:03:53 237848 —-a-w- C:\Windows\SysWow64\xactengine2_4.dll 2011-05-23 03:03:53 17688 —-a-w- C:\Windows\System32\x3daudio1_1.dll 2011-05-23 03:03:53 15128 —-a-w- C:\Windows\SysWow64\x3daudio1_1.dll 2011-05-23 03:03:39 3977496 —-a-w- C:\Windows\System32\d3dx9_31.dll 2011-05-23 03:03:39 2414360 —-a-w- C:\Windows\SysWow64\d3dx9_31.dll 2011-05-23 03:03:17 363288 —-a-w- C:\Windows\System32\xactengine2_3.dll 2011-05-23 03:02:54 236824 —-a-w- C:\Windows\SysWow64\xactengine2_3.dll 2011-05-23 03:02:43 83736 —-a-w- C:\Windows\System32\xinput1_2.dll 2011-05-23 03:02:43 62744 —-a-w- C:\Windows\SysWow64\xinput1_2.dll 2011-05-23 02:57:43 3767504 —-a-w- C:\Windows\System32\d3dx9_26.dll 2011-05-23 02:57:43 2297552 —-a-w- C:\Windows\SysWow64\d3dx9_26.dll 2011-05-23 02:20:20 ——– d—–w- C:\Program Files (x86)\Amnesia - The Dark Descent 2011-05-22 05:35:26 ——– d—–w- C:\Users\David\AppData\Local\CyberLink 2011-05-22 05:35:23 ——– d—–w- C:\Users\David\AppData\Local\PowerCinema 2011-05-22 04:02:53 97928 —-a-w- C:\Windows\System32\IncContxMenu.dll 2011-05-22 04:02:49 69000 —-a-w- C:\Windows\System32\offreg.dll 2011-05-22 04:02:49 56200 —-a-w- C:\Windows\SysWow64\offreg.dll 2011-05-22 04:02:49 45568 —-a-w- C:\Windows\System32\iolobtdfg.exe 2011-05-22 04:02:49 14848 —-a-w- C:\Windows\System32\smrgdf.exe 2011-05-22 04:02:49 ——– d—–w- C:\Program Files (x86)\iolo 2011-05-22 03:46:40 8718160 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2011-05-21 18:19:55 ——– d—–w- C:\Users\David\AppData\Local\ElevatedDiagnostics 2011-05-20 14:34:48 367104 —-a-w- C:\Windows\System32\wcncsvc.dll 2011-05-20 14:34:48 276992 —-a-w- C:\Windows\SysWow64\wcncsvc.dll 2011-05-20 14:28:47 ——– d—–w- C:\Program Files (x86)\MSXML 4.0 2011-05-20 14:25:27 ——– d—–w- C:\Windows\SysWow64\Wat 2011-05-20 14:25:25 ——– d—–w- C:\Windows\System32\Wat 2011-05-20 03:07:40 ——– d—–w- C:\Users\David\Tracing 2011-05-20 03:02:38 ——– d—–w- C:\Users\David\AppData\Roaming\Windows Live Writer 2011-05-20 03:02:38 ——– d—–w- C:\Users\David\AppData\Local\Windows Live Writer 2011-05-20 01:25:50 ——– d—–w- C:\Windows\en 2011-05-20 01:17:53 69464 —-a-w- C:\Windows\SysWow64\XAPOFX1_3.dll 2011-05-20 01:17:53 523088 —-a-w- C:\Windows\System32\d3dx10_42.dll 2011-05-20 01:17:53 515416 —-a-w- C:\Windows\SysWow64\XAudio2_5.dll 2011-05-20 01:17:53 453456 —-a-w- C:\Windows\SysWow64\d3dx10_42.dll 2011-05-20 00:56:22 142336 —-a-w- C:\Windows\System32\poqexec.exe 2011-05-20 00:56:22 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe 2011-05-20 00:53:34 15712 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\583c7ab81cc168822\MeshBetaRemover.exe 2011-05-20 00:53:10 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\49d7e1a41cc16881a\DSETUP.dll 2011-05-20 00:53:10 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\49d7e1a41cc16881a\DXSETUP.exe 2011-05-20 00:53:10 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\49d7e1a41cc16881a\dsetup32.dll 2011-05-20 00:53:09 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\48991b691cc168819\DSETUP.dll 2011-05-20 00:53:09 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\48991b691cc168819\DXSETUP.exe 2011-05-20 00:53:09 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\48991b691cc168819\dsetup32.dll 2011-05-20 00:51:55 ——– d—–w- C:\Users\David\AppData\Local\Windows Live 2011-05-20 00:45:30 99176 —-a-w- C:\Windows\SysWow64\PresentationHostProxy.dll 2011-05-20 00:45:30 49472 —-a-w- C:\Windows\SysWow64\netfxperf.dll 2011-05-20 00:45:30 48960 —-a-w- C:\Windows\System32\netfxperf.dll 2011-05-20 00:45:30 444752 —-a-w- C:\Windows\System32\mscoree.dll 2011-05-20 00:45:30 320352 —-a-w- C:\Windows\System32\PresentationHost.exe 2011-05-20 00:45:30 297808 —-a-w- C:\Windows\SysWow64\mscoree.dll 2011-05-20 00:45:30 295264 —-a-w- C:\Windows\SysWow64\PresentationHost.exe 2011-05-20 00:45:30 1942856 —-a-w- C:\Windows\System32\dfshim.dll 2011-05-20 00:45:30 1130824 —-a-w- C:\Windows\SysWow64\dfshim.dll 2011-05-20 00:45:30 109912 —-a-w- C:\Windows\System32\PresentationHostProxy.dll 2011-05-20 00:27:41 ——– d—–w- C:\ProgramData\VirtualizedApplications 2011-05-20 00:26:12 ——– d—–w- C:\Program Files (x86)\MSN Toolbar 2011-05-20 00:18:36 243712 —-a-w- C:\Windows\System32\drivers\ks.sys 2011-05-20 00:18:36 184832 —-a-w- C:\Windows\System32\drivers\usbvideo.sys 2011-05-20 00:14:37 31232 —-a-w- C:\Windows\SysWow64\prevhost.exe 2011-05-20 00:14:37 31232 —-a-w- C:\Windows\System32\prevhost.exe 2011-05-19 23:09:15 ——– d—–w- C:\Users\David\AppData\Roaming\Blackberry Desktop 2011-05-19 22:57:00 5509504 —-a-w- C:\Windows\System32\ntoskrnl.exe 2011-05-19 22:56:58 3957632 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2011-05-19 22:56:58 3901824 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2011-05-19 22:54:59 442880 —-a-w- C:\Windows\System32\winhttp.dll 2011-05-19 22:52:00 1739176 —-a-w- C:\Windows\System32\ntdll.dll 2011-05-19 22:52:00 1293120 —-a-w- C:\Windows\SysWow64\ntdll.dll 2011-05-19 22:51:32 2870272 —-a-w- C:\Windows\explorer.exe 2011-05-19 22:51:32 2614784 —-a-w- C:\Windows\SysWow64\explorer.exe 2011-05-19 22:49:32 476160 —-a-w- C:\Windows\System32\XpsGdiConverter.dll 2011-05-19 22:49:32 288256 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2011-05-19 22:47:55 461312 —-a-w- C:\Windows\System32\drivers\srv.sys 2011-05-19 22:47:55 401920 —-a-w- C:\Windows\System32\drivers\srv2.sys 2011-05-19 22:47:54 161792 —-a-w- C:\Windows\System32\drivers\srvnet.sys 2011-05-19 22:45:18 1359872 —-a-w- C:\Windows\System32\mfc42u.dll 2011-05-19 22:45:17 1395712 —-a-w- C:\Windows\System32\mfc42.dll 2011-05-19 22:45:17 1137664 —-a-w- C:\Windows\SysWow64\mfc42.dll 2011-05-19 22:45:16 1164288 —-a-w- C:\Windows\SysWow64\mfc42u.dll 2011-05-19 22:44:55 4582912 —-a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe 2011-05-19 22:44:54 4247040 —-a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe 2011-05-19 22:44:54 2085376 —-a-w- C:\Windows\System32\ole32.dll 2011-05-19 22:44:53 1413632 —-a-w- C:\Windows\SysWow64\ole32.dll 2011-05-19 22:44:16 558592 —-a-w- C:\Windows\System32\spoolsv.exe 2011-05-19 22:44:11 714752 —-a-w- C:\Windows\System32\kerberos.dll 2011-05-19 22:44:11 541184 —-a-w- C:\Windows\SysWow64\kerberos.dll 2011-05-19 22:43:40 148992 —-a-w- C:\Windows\System32\t2embed.dll 2011-05-19 22:43:40 109056 —-a-w- C:\Windows\SysWow64\t2embed.dll 2011-05-19 22:43:33 46080 —-a-w- C:\Windows\System32\atmlib.dll 2011-05-19 22:43:33 367104 —-a-w- C:\Windows\System32\atmfd.dll 2011-05-19 22:43:33 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2011-05-19 22:43:33 294912 —-a-w- C:\Windows\SysWow64\atmfd.dll 2011-05-19 22:43:02 954752 —-a-w- C:\Windows\SysWow64\mfc40.dll 2011-05-19 22:43:02 954288 —-a-w- C:\Windows\SysWow64\mfc40u.dll 2011-05-19 22:42:30 483840 —-a-w- C:\Windows\System32\StructuredQuery.dll 2011-05-19 22:42:30 363520 —-a-w- C:\Windows\SysWow64\StructuredQuery.dll 2011-05-19 22:42:20 633856 —-a-w- C:\Windows\System32\comctl32.dll 2011-05-19 22:42:20 530432 —-a-w- C:\Windows\SysWow64\comctl32.dll 2011-05-19 22:42:10 2080256 —-a-w- C:\Program Files\Windows Mail\msoe.dll 2011-05-19 22:42:10 1619968 —-a-w- C:\Program Files (x86)\Windows Mail\msoe.dll 2011-05-19 22:42:01 3133440 —-a-w- C:\Windows\System32\win32k.sys 2011-05-19 22:41:54 516096 —-a-w- C:\Program Files\Windows Mail\wab.exe 2011-05-19 22:41:54 516096 —-a-w- C:\Program Files (x86)\Windows Mail\wab.exe 2011-05-19 22:41:54 35328 —-a-w- C:\Program Files\Windows Mail\wabfind.dll 2011-05-19 22:40:57 340992 —-a-w- C:\Windows\System32\schannel.dll 2011-05-19 22:40:57 224256 —-a-w- C:\Windows\SysWow64\schannel.dll 2011-05-19 22:38:41 3138048 —-a-w- C:\Windows\System32\mstscax.dll 2011-05-19 22:38:40 2690560 —-a-w- C:\Windows\SysWow64\mstscax.dll 2011-05-19 22:38:40 1097216 —-a-w- C:\Windows\System32\mstsc.exe 2011-05-19 22:38:40 1034240 —-a-w- C:\Windows\SysWow64\mstsc.exe 2011-05-19 22:38:34 976896 —-a-w- C:\Windows\System32\inetcomm.dll 2011-05-19 22:38:34 740864 —-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-05-19 22:36:30 90624 —-a-w- C:\Windows\System32\drivers\bowser.sys 2011-05-19 22:36:30 286720 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-05-19 22:36:30 157696 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-05-19 22:36:30 126464 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-05-19 22:36:20 267776 —-a-w- C:\Windows\System32\FXSCOVER.exe 2011-05-19 22:36:11 112000 —-a-w- C:\Windows\System32\consent.exe 2011-05-19 22:23:54 395776 —-a-w- C:\Windows\System32\webio.dll 2011-05-19 22:23:54 314368 —-a-w- C:\Windows\SysWow64\webio.dll 2011-05-19 22:23:38 30208 —-a-w- C:\Windows\System32\dnscacheugc.exe 2011-05-19 22:23:38 28672 —-a-w- C:\Windows\SysWow64\dnscacheugc.exe 2011-05-19 22:23:38 182272 —-a-w- C:\Windows\System32\dnsrslvr.dll 2011-05-19 22:16:23 ——– d—–w- C:\Users\David\AppData\Local\SoftGrid Client 2011-05-19 22:16:20 ——– d—–w- C:\Users\David\AppData\Roaming\SoftGrid Client 2011-05-19 22:14:49 ——– d—–w- C:\Users\David\AppData\Local\Adobe 2011-05-19 22:12:29 ——– d—–w- C:\Program Files (x86)\Microsoft Application Virtualization Client 2011-05-19 22:11:31 ——– d—–w- C:\Users\David\AppData\Roaming\TP 2011-05-19 20:39:33 912504 —-a-w- C:\Windows\System32\drivers\NISx64\1206000.01D\symefa64.sys 2011-05-19 20:39:33 744568 —-a-w- C:\Windows\System32\drivers\NISx64\1206000.01D\srtsp64.sys 2011-05-19 20:39:33 450680 —-a-w- C:\Windows\System32\drivers\NISx64\1206000.01D\symds64.sys 2011-05-19 20:39:33 40568 —-a-w- C:\Windows\System32\drivers\NISx64\1206000.01D\srtspx64.sys 2011-05-19 20:39:33 382584 —-a-w- C:\Windows\System32\drivers\NISx64\1206000.01D\symnets.sys 2011-05-19 20:39:33 171128 —-a-w- C:\Windows\System32\drivers\NISx64\1206000.01D\ironx64.sys 2011-05-19 20:39:17 ——– d—–w- C:\Windows\System32\drivers\NISx64\1206000.01D 2011-05-19 16:50:09 9728 —-a-w- C:\Windows\SysWow64\sscore.dll 2011-05-19 16:50:09 236032 —-a-w- C:\Windows\System32\srvsvc.dll 2011-05-18 23:03:29 ——– d—–w- C:\Users\David\AppData\Local\Diagnostics 2011-05-18 23:00:11 ——– d—–w- C:\Users\David\AppData\Local\Research In Motion 2011-05-18 23:00:05 ——– d—–w- C:\Users\David\AppData\Roaming\Research In Motion 2011-05-18 21:23:35 31744 —-a-w- C:\Windows\System32\drivers\RimSerial_AMD64.sys 2011-05-18 21:20:32 ——– d—–w- C:\ProgramData\Research In Motion 2011-05-18 21:19:48 ——– d—–w- C:\Program Files (x86)\Research In Motion 2011-05-18 21:19:48 ——– d—–w- C:\Program Files (x86)\Common Files\Research In Motion 2011-05-18 19:37:36 ——– d—–w- C:\Program Files (x86)\Common Files\Symantec Shared 2011-05-18 19:27:56 ——– d—–w- C:\Users\David\AppData\Local\CrashDumps 2011-05-18 19:08:29 ——– d—–w- C:\ProgramData\Recovery 2011-05-18 18:58:33 ——– d—–w- C:\Program Files (x86)\uTorrent 2011-05-18 18:58:02 ——– d—–w- C:\Users\David\AppData\Roaming\uTorrent 2011-05-18 18:53:19 ——– d—–w- C:\Program Files (x86)\Common Files\xing shared 2011-05-18 18:40:04 ——– d—–r- C:\Program Files (x86)\Skype 2011-05-18 18:01:27 511328 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\CAPICOM\CAPICOM.DLL 2011-05-18 17:48:09 74703 —-a-w- C:\Windows\SysWow64\mfc45.dll 2011-05-18 17:44:45 ——– d—–w- C:\Users\David\AppData\Roaming\iolo 2011-05-18 17:44:45 ——– d—–w- C:\ProgramData\iolo 2011-05-18 17:34:27 ——– d—–w- C:\Users\David\AppData\Local\Yahoo 2011-05-18 17:33:05 ——– d—–w- C:\Users\David\AppData\Local\Yahoo! 2011-05-18 17:23:37 ——– d—–w- C:\Program Files (x86)\Yahoo! 2011-05-18 17:20:42 174200 —-a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS 2011-05-18 17:20:41 ——– d—–w- C:\Program Files\Symantec 2011-05-18 17:20:41 ——– d—–w- C:\Program Files\Common Files\Symantec Shared 2011-05-18 17:02:40 270720 ——w- C:\Windows\System32\MpSigStub.exe 2011-05-18 16:59:20 ——– d—–w- C:\Users\David\AppData\Local\EgisTec 2011-05-18 16:58:41 ——– d—–w- C:\Users\David\AppData\Roaming\hpqLog 2011-05-18 16:57:33 ——– d—–w- C:\Users\David\AppData\Roaming\Intel 2011-05-18 16:57:33 ——– d—–w- C:\Users\David\AppData\Local\EgisTec IPS 2011-05-18 16:57:05 ——– d—–w- C:\Users\David\AppData\Roaming\Intel Corporation 2011-05-18 16:50:57 ——– d—–w- C:\Users\David\AppData\Local\Hewlett-Packard 2011-05-18 16:27:39 ——– d—–w- C:\Users\David\AppData\Local\VirtualStore . ==================== Find3M ==================== . 2011-05-18 19:29:52 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-05-18 19:22:30 982912 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2011-05-18 18:51:39 348160 —-a-w- C:\Windows\SysWow64\msvcr71.dll 2011-05-18 18:51:38 499712 —-a-w- C:\Windows\SysWow64\msvcp71.dll 2011-04-14 12:07:59 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-04-12 20:31:32 507904 —-a-r- C:\Windows\SysWow64\btwapi.dll . ============= FINISH: 18:33:14.74 =============== aswMBR LOG——————————————— This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish. Rkill was run on 06/10/2011 at 8:10:46. Operating System: Windows 7 Home Premium Processes terminated by Rkill or while it was running: Rkill completed on 06/10/2011 at 8:11:00.

Attachments:

Hello,

Can you please re-post the aswMBR log from your desktop, it doesn't look like a complete log posted. If that in fact was the complete log, please do the following:

  • Run rkill as posted earlier. Remember, after running rkill do NOT reboot your computer.
    Then,
  • Run aswMBR as posted earlier, post the log so it can be reviewed.

Thanks!
Astabi
ahhh I posted the wrong thing! Sorry :D aswMBR log —————————————————————- aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-06-11 05:57:55 —————————– 05:57:55.775 OS Version: Windows x64 6.1.7600 05:57:55.775 Number of processors: 4 586 0x2505 05:57:55.776 ComputerName: DAVID-HP UserName: David 05:58:02.003 Initialize success 05:58:21.725 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 05:58:21.729 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 610480MB BusType: 3 05:58:21.746 Disk 0 MBR read successfully 05:58:21.750 Disk 0 MBR scan 05:58:21.753 Disk 0 unknown MBR code 05:58:21.757 Service scanning 05:58:23.040 Disk 0 trace - called modules: 05:58:23.046 05:58:23.053 Scan finished successfully 05:58:35.214 Disk 0 MBR has been saved successfully to "C:\Users\David\Desktop\MBR.dat" 05:58:35.215 The log file has been saved successfully to "C:\Users\David\Desktop\aswMBR.txt"
Hi

I am very sorry for the wait,

Please do the following:

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
Oh its okay, I had to work all weekend anyways so i didn't really get a chance to check it out… I just figured you were on your weekemd. Here is the log ComboFix 11-06-13.01 - David 06/13/2011 13:59:12.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3894.1958 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe . . ((((((((((((((((((((((((( Files Created from 2011-05-13 to 2011-06-13 ))))))))))))))))))))))))))))))) . . 2011-06-13 21:13 . 2011-06-13 21:13 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-12 01:20 . 2011-06-12 01:20 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2011-06-12 01:19 . 2011-06-12 01:19 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-06-12 01:16 . 2011-06-12 01:16 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-06-12 01:15 . 2011-06-12 01:15 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2011-06-11 01:25 . 2011-05-09 22:00 8718160 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{33F44265-794B-4BB7-872A-82B04CB46A68}\mpengine.dll 2011-06-10 15:32 . 2011-06-10 15:32 ——– d—–w- c:\program files (x86)\StartNow Toolbar 2011-06-10 15:23 . 2011-06-10 15:23 ——– d—–w- c:\program files (x86)\Superfish 2011-06-06 00:34 . 2011-06-06 12:30 ——– d—–w- C:\found.000 2011-05-30 22:01 . 2011-05-30 22:01 ——– d—–w- c:\programdata\Spotmau 2011-05-30 22:01 . 2011-05-30 22:01 ——– d—–w- c:\programdata\pc health check 2011-05-30 22:00 . 2011-05-30 22:00 ——– d—–w- c:\programdata\TuneUp360 2011-05-30 22:00 . 2010-11-23 23:44 380224 —-a-w- c:\windows\SysWow64\TuneUp360.ocx 2011-05-30 22:00 . 2011-05-30 23:15 ——– d—–w- c:\program files (x86)\TuneUp360 2011-05-30 01:01 . 2011-06-12 03:56 ——– d—–w- c:\program files (x86)\Call of Duty Game of the Year Edition 2011-05-28 03:50 . 2011-05-28 03:57 ——– d—–w- c:\program files (x86)\MacGAMUT 2003 2011-05-28 03:50 . 2002-12-05 21:10 155648 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll 2011-05-28 03:50 . 2002-12-02 22:22 5632 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe 2011-05-28 03:50 . 2002-12-02 20:33 57344 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll 2011-05-28 03:50 . 2002-12-02 20:33 237568 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll 2011-05-28 03:50 . 2002-12-05 21:12 692224 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll 2011-05-28 03:49 . 2011-05-28 03:49 163972 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll 2011-05-28 03:49 . 2011-05-28 03:49 282756 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll 2011-05-27 14:06 . 2011-04-22 20:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-26 20:55 . 2011-05-26 20:55 ——– d—–w- c:\program files (x86)\Coupons 2011-05-26 20:52 . 2010-06-14 23:24 361320 ——w- c:\windows\system32\HPDiscoPM9311.dll 2011-05-26 20:51 . 2011-05-26 20:56 ——– d—–w- c:\programdata\HP 2011-05-26 20:51 . 2011-05-26 20:54 ——– d—–w- c:\program files (x86)\HP 2011-05-26 20:50 . 2011-05-26 20:50 ——– d—–w- c:\program files\HP 2011-05-26 17:10 . 2011-02-19 06:37 1135104 —-a-w- c:\windows\system32\FntCache.dll 2011-05-26 17:10 . 2011-02-19 06:37 1540608 —-a-w- c:\windows\system32\DWrite.dll 2011-05-26 17:10 . 2011-02-19 05:32 1074176 —-a-w- c:\windows\SysWow64\DWrite.dll 2011-05-26 17:10 . 2011-02-19 06:36 902656 —-a-w- c:\windows\system32\d2d1.dll 2011-05-26 17:10 . 2011-02-19 05:32 739840 —-a-w- c:\windows\SysWow64\d2d1.dll 2011-05-25 02:50 . 2011-05-25 02:50 ——– d—–w- c:\program files (x86)\Infogrames 2011-05-25 02:43 . 1996-06-12 20:44 4711 —-a-w- c:\windows\system32\dmouse.vxd 2011-05-25 02:43 . 2011-05-25 02:49 ——– d—–w- c:\program files\Ultimate Doom for Windows 95 2011-05-24 21:23 . 2011-05-24 21:24 ——– d—–w- c:\programdata\Microsoft Help 2011-05-24 20:03 . 2011-05-24 20:03 ——– d—–w- c:\program files (x86)\Microsoft.NET 2011-05-24 01:41 . 1998-10-29 23:45 306688 —-a-w- c:\windows\IsUninst.exe 2011-05-23 03:16 . 2010-06-02 11:55 77656 —-a-w- c:\windows\system32\XAPOFX1_5.dll 2011-05-23 03:16 . 2010-06-02 11:55 74072 —-a-w- c:\windows\SysWow64\XAPOFX1_5.dll 2011-05-23 03:16 . 2010-06-02 11:55 527192 —-a-w- c:\windows\SysWow64\XAudio2_7.dll 2011-05-23 03:16 . 2010-06-02 11:55 518488 —-a-w- c:\windows\system32\XAudio2_7.dll 2011-05-23 03:14 . 2010-02-04 17:01 238936 —-a-w- c:\windows\SysWow64\xactengine3_6.dll 2011-05-23 03:14 . 2010-02-04 17:01 176984 —-a-w- c:\windows\system32\xactengine3_6.dll 2011-05-23 03:14 . 2010-02-04 17:01 24920 —-a-w- c:\windows\system32\X3DAudio1_7.dll 2011-05-23 03:14 . 2010-02-04 17:01 22360 —-a-w- c:\windows\SysWow64\X3DAudio1_7.dll 2011-05-23 03:14 . 2009-09-05 00:44 517960 —-a-w- c:\windows\system32\XAudio2_5.dll 2011-05-23 03:14 . 2009-09-05 00:44 238936 —-a-w- c:\windows\SysWow64\xactengine3_5.dll 2011-05-23 03:14 . 2009-09-05 00:44 176968 —-a-w- c:\windows\system32\xactengine3_5.dll 2011-05-23 03:14 . 2009-09-05 00:29 1974616 —-a-w- c:\windows\SysWow64\D3DCompiler_42.dll 2011-05-23 03:14 . 2009-09-05 00:29 2582888 —-a-w- c:\windows\system32\D3DCompiler_42.dll 2011-05-23 03:13 . 2009-09-05 00:29 5501792 —-a-w- c:\windows\SysWow64\d3dcsx_42.dll 2011-05-23 03:13 . 2009-09-05 00:29 5554512 —-a-w- c:\windows\system32\d3dcsx_42.dll 2011-05-23 03:13 . 2009-09-05 00:29 235344 —-a-w- c:\windows\SysWow64\d3dx11_42.dll 2011-05-23 03:13 . 2009-09-05 00:29 285024 —-a-w- c:\windows\system32\d3dx11_42.dll 2011-05-23 03:13 . 2009-09-05 00:29 1892184 —-a-w- c:\windows\SysWow64\D3DX9_42.dll 2011-05-23 03:13 . 2009-09-05 00:29 2475352 —-a-w- c:\windows\system32\D3DX9_42.dll 2011-05-23 03:13 . 2009-03-09 22:27 520544 —-a-w- c:\windows\system32\d3dx10_41.dll 2011-05-23 03:13 . 2009-03-09 22:27 2430312 —-a-w- c:\windows\system32\D3DCompiler_41.dll 2011-05-23 03:13 . 2009-03-09 22:27 5425496 —-a-w- c:\windows\system32\D3DX9_41.dll 2011-05-23 03:13 . 2009-03-09 22:27 4178264 —-a-w- c:\windows\SysWow64\D3DX9_41.dll 2011-05-23 03:11 . 2008-10-27 17:04 518480 —-a-w- c:\windows\system32\XAudio2_3.dll 2011-05-23 03:11 . 2008-10-27 17:04 514384 —-a-w- c:\windows\SysWow64\XAudio2_3.dll 2011-05-23 03:11 . 2008-10-27 17:04 74576 —-a-w- c:\windows\system32\XAPOFX1_2.dll 2011-05-23 03:11 . 2008-10-27 17:04 70992 —-a-w- c:\windows\SysWow64\XAPOFX1_2.dll 2011-05-23 03:11 . 2008-10-27 17:04 235856 —-a-w- c:\windows\SysWow64\xactengine3_3.dll 2011-05-23 03:11 . 2008-10-27 17:04 175440 —-a-w- c:\windows\system32\xactengine3_3.dll 2011-05-23 03:11 . 2008-10-27 17:04 25936 —-a-w- c:\windows\system32\X3DAudio1_5.dll 2011-05-23 03:11 . 2008-10-27 17:04 23376 —-a-w- c:\windows\SysWow64\X3DAudio1_5.dll 2011-05-23 03:11 . 2008-07-31 17:41 72200 —-a-w- c:\windows\system32\XAPOFX1_1.dll 2011-05-23 03:11 . 2008-07-31 17:41 68616 —-a-w- c:\windows\SysWow64\XAPOFX1_1.dll 2011-05-23 03:11 . 2008-07-31 17:40 513544 —-a-w- c:\windows\system32\XAudio2_2.dll 2011-05-23 03:11 . 2008-07-31 17:40 509448 —-a-w- c:\windows\SysWow64\XAudio2_2.dll 2011-05-23 03:09 . 2008-05-30 21:18 238088 —-a-w- c:\windows\SysWow64\xactengine3_1.dll 2011-05-23 03:08 . 2008-03-05 22:56 1860120 —-a-w- c:\windows\system32\D3DCompiler_37.dll 2011-05-23 03:08 . 2008-03-05 22:56 1420824 —-a-w- c:\windows\SysWow64\D3DCompiler_37.dll 2011-05-23 03:08 . 2008-02-06 06:07 462864 —-a-w- c:\windows\SysWow64\d3dx10_37.dll 2011-05-23 03:08 . 2008-02-06 06:07 529424 —-a-w- c:\windows\system32\d3dx10_37.dll 2011-05-23 03:08 . 2008-03-05 22:56 4910088 —-a-w- c:\windows\system32\D3DX9_37.dll 2011-05-23 03:08 . 2008-03-05 22:56 3786760 —-a-w- c:\windows\SysWow64\D3DX9_37.dll 2011-05-23 03:08 . 2007-10-22 10:40 411656 —-a-w- c:\windows\system32\xactengine2_10.dll 2011-05-23 03:08 . 2007-10-22 10:39 267272 —-a-w- c:\windows\SysWow64\xactengine2_10.dll 2011-05-23 03:08 . 2007-10-12 22:14 2006552 —-a-w- c:\windows\system32\D3DCompiler_36.dll 2011-05-23 03:08 . 2007-10-12 22:14 1374232 —-a-w- c:\windows\SysWow64\D3DCompiler_36.dll 2011-05-23 03:08 . 2007-10-02 16:56 444776 —-a-w- c:\windows\SysWow64\d3dx10_36.dll 2011-05-23 03:08 . 2007-10-02 16:56 508264 —-a-w- c:\windows\system32\d3dx10_36.dll 2011-05-23 03:06 . 2007-05-16 23:45 506728 —-a-w- c:\windows\system32\d3dx10_34.dll 2011-05-23 03:05 . 2007-01-24 22:27 393576 —-a-w- c:\windows\system32\xactengine2_6.dll 2011-05-23 03:05 . 2007-01-24 22:27 255848 —-a-w- c:\windows\SysWow64\xactengine2_6.dll 2011-05-23 03:05 . 2006-12-08 19:02 251672 —-a-w- c:\windows\SysWow64\xactengine2_5.dll 2011-05-23 03:05 . 2006-12-08 19:00 390424 —-a-w- c:\windows\system32\xactengine2_5.dll 2011-05-23 03:05 . 2006-11-29 20:06 469264 —-a-w- c:\windows\system32\d3dx10.dll 2011-05-23 03:05 . 2006-11-29 20:06 440080 —-a-w- c:\windows\SysWow64\d3dx10.dll 2011-05-23 03:03 . 2007-03-05 19:42 15128 —-a-w- c:\windows\SysWow64\x3daudio1_1.dll 2011-05-23 03:03 . 2007-03-05 19:42 17688 —-a-w- c:\windows\system32\x3daudio1_1.dll 2011-05-23 03:03 . 2006-09-28 23:05 237848 —-a-w- c:\windows\SysWow64\xactengine2_4.dll 2011-05-23 03:03 . 2006-09-28 23:04 364824 —-a-w- c:\windows\system32\xactengine2_4.dll 2011-05-23 03:03 . 2006-09-28 23:05 3977496 —-a-w- c:\windows\system32\d3dx9_31.dll 2011-05-23 03:03 . 2006-09-28 23:05 2414360 —-a-w- c:\windows\SysWow64\d3dx9_31.dll 2011-05-23 03:03 . 2006-07-28 16:30 363288 —-a-w- c:\windows\system32\xactengine2_3.dll 2011-05-23 03:02 . 2006-07-28 16:30 236824 —-a-w- c:\windows\SysWow64\xactengine2_3.dll 2011-05-23 03:02 . 2006-07-28 16:31 83736 —-a-w- c:\windows\system32\xinput1_2.dll 2011-05-23 03:02 . 2006-07-28 16:30 62744 —-a-w- c:\windows\SysWow64\xinput1_2.dll 2011-05-23 02:57 . 2005-05-26 22:34 3767504 —-a-w- c:\windows\system32\d3dx9_26.dll 2011-05-23 02:57 . 2005-05-26 22:34 2297552 —-a-w- c:\windows\SysWow64\d3dx9_26.dll 2011-05-23 02:20 . 2011-05-23 02:20 ——– d—–w- c:\program files (x86)\Amnesia - The Dark Descent 2011-05-22 04:02 . 2011-03-15 22:24 97928 —-a-w- c:\windows\system32\IncContxMenu.dll 2011-05-22 04:02 . 2011-05-22 04:02 ——– d—–w- c:\program files (x86)\iolo 2011-05-22 04:02 . 2011-03-15 22:23 14848 —-a-w- c:\windows\system32\smrgdf.exe 2011-05-22 04:02 . 2011-03-15 22:23 45568 —-a-w- c:\windows\system32\iolobtdfg.exe 2011-05-22 04:02 . 2010-02-09 06:36 69000 —-a-w- c:\windows\system32\offreg.dll 2011-05-22 04:02 . 2010-02-09 05:59 56200 —-a-w- c:\windows\SysWow64\offreg.dll 2011-05-20 14:34 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll 2011-05-20 14:34 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll 2011-05-20 14:28 . 2011-05-20 14:28 ——– d—–w- c:\program files (x86)\MSXML 4.0 2011-05-20 14:25 . 2011-05-20 14:25 ——– d—–w- c:\windows\SysWow64\Wat 2011-05-20 14:25 . 2011-05-20 14:25 ——– d—–w- c:\windows\system32\Wat 2011-05-20 01:25 . 2011-05-20 01:25 ——– d—–w- c:\windows\en 2011-05-20 01:19 . 2011-05-20 01:19 ——– d—–w- c:\program files\Windows Live 2011-05-20 01:17 . 2009-09-05 00:44 69464 —-a-w- c:\windows\SysWow64\XAPOFX1_3.dll 2011-05-20 01:17 . 2009-09-05 00:44 515416 —-a-w- c:\windows\SysWow64\XAudio2_5.dll 2011-05-20 01:17 . 2009-09-05 00:29 453456 —-a-w- c:\windows\SysWow64\d3dx10_42.dll 2011-05-20 01:17 . 2009-09-05 00:29 523088 —-a-w- c:\windows\system32\d3dx10_42.dll . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-20 01:21 . 2010-06-24 18:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-05-18 18:51 . 2003-02-21 11:42 348160 —-a-w- c:\windows\SysWow64\msvcr71.dll 2011-05-18 18:51 . 2003-03-19 03:14 499712 —-a-w- c:\windows\SysWow64\msvcp71.dll 2011-04-14 12:07 . 2010-10-26 19:32 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-04-12 20:31 . 2011-04-12 20:31 507904 —-a-r- c:\windows\SysWow64\btwapi.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 .[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HPAdvisorDock"="c:\program files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe" [2010-02-10 1712184] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2010-05-07 26211624] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696] "EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2009-12-25 401192] "EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2009-12-25 201512] "VitaKeyTSR"="c:\program files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe" [2010-06-09 380272] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-06-30 602168] "Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928] "TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" [2011-05-18 273544] "RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-03-05 340240] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x] R4 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\Definitions\BASHDefs\20110518.001\BHDrvx64.sys [2011-05-18 1127032] S1 DVMIO;DeviceVM IO Service;c:\windows\system32\DRIVERS\dvmio.sys [x] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\Definitions\IPSDefs\20110604.001\IDSvia64.sys [2011-06-03 488056] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1206000.01D\SYMNETS.SYS [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600] S2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2010-06-13 400368] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664] S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2010-06-07 408576] S2 DvmMDES;DeviceVM Meta Data Export Service;c:\swsetup\HPQWMM\QuickWeb\QW.SYS\config\DVMExportService.exe [2010-06-25 338168] S2 EgisTec Service;EgisTec Service;c:\program files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe [2010-06-09 697712] S2 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2010-06-09 646000] S2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-06-25 92216] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-06-30 27192] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336] S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2011-03-15 724152] S2 ioloSystemService;iolo System Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2011-03-15 724152] S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe [2011-04-17 130008] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688] S2 Toolbar Updater Service;Toolbar Updater Service;c:\program files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [2011-03-24 199904] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-04-15 2533400] S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2010-02-23 2192176] S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-06-07 911872] S3 bpenum;bpenum;c:\windows\system32\DRIVERS\bpenum.sys [x] S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [x] S3 bpusb;bpusb;c:\windows\system32\Drivers\bpusb.sys [x] S3 clwvd;HP Webcam Splitter;c:\windows\system32\DRIVERS\clwvd.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-23 136824] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-05-18 c:\windows\Tasks\HPCeeScheduleForDavid.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 10:53] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "combofix"="c:\combofix\CF30641.cfxxe" [X] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-06-26 324096] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-06-18 487424] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 1928976] "IntelWirelessWiMAX"="c:\program files\Intel\WiMAX\Bin\WiMAXCU.exe" [2010-06-08 1441792] "SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-01-21 611896] "HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-06-18 8192] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll TCP: DhcpNameServer = 192.168.1.1 . . ——- File Associations ——- . JSEFile=NOTEPAD.EXE %1p\bin\???Þ . - - - - ORPHANS REMOVED - - - - . HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS] "ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000001 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe c:\windows\SysWOW64\WerFault.exe . ************************************************************************** . Completion time: 2011-06-13 14:50:06 - machine was rebooted ComboFix-quarantined-files.txt 2011-06-13 21:50 . Pre-Run: 551,222,460,416 bytes free Post-Run: 551,056,666,624 bytes free . - - End Of File - - B39D2AF822E3614955135F1E2B553A63
Hi

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
When I tried to use the eset online scanner the window would pop up where I tick yes i agree to the therms. I then click ok and there is a little tiny picture at the top left hand side and that is all… nothing else loads. But I have the malwarebytes log right here. Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 6851 Windows 6.1.7600 Internet Explorer 9.0.8112.16421 6/13/2011 7:39:27 PM mbam-log-2011-06-13 (19-39-27).txt Scan type: Quick scan Objects scanned: 165366 Time elapsed: 3 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi

Try this scanner instead:

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC Now button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    Post the contents of the ActiveScan report

NEXT


Please do the following:

Download TFC to your desktop
Mirror
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

NEXT

Download and run Puran Disk Defragmenter



How is the computer running? Are there any outstanding issues
I noticed that the start up is faster… But i'm still getting a messeage when i first start my computer saying smart hard disk error and that i need to back up my computer asap. I looked into that message and it said that when i recieve that message its basically giving me warning of a hard drive failure.
Do you have your data backed up?

If you do, then run chkdsk, it may be able to repair any errors it finds,

if not, then you will probably need to replace the hard drive before it crashes completely.

Run chkdsk in a Elevated Command Prompt - Vista
Open an elevated command prompt.
Open the Start Menu.

Click on All Programs and Accessories

Right click on Command Prompt and click Run as administrator.

Click on Continue in the UAC prompt.
A command window will open
At the command prompt, type chkdsk /r then press Enter.
Close the command prompt.

Restart the computer and chkdsk will begin running at startup.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI