This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My computer is slowing down more/freezing more and more..

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yes, my computer is slower now. It takes longer for it to start up. Sometimes it takes forever to load up mozilla fox and it freezes more. But the only thing that concerns me the most is that whenever I go on google and go to search up something and then I click a link, it doesn't go to that link and it goes to some totally different site. For example, imagine I googled "answers to math regents june 2010" or something, but when I click the link, it doesn't take me to the answers to the math regents june 2010, it takes me to some random site about cooking, or yoga or it takes me to like yellowpages. Why does it do that? IS there something wrong with my computer?
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)








  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello! Thank you for helping me. This is the TDSSKiller scan. 2011/06/20 18:17:50.0911 5024 TDSS rootkit removing tool 2.5.5.0 Jun 16 2011 15:25:15 2011/06/20 18:17:52.0802 5024 ================================================================================ 2011/06/20 18:17:52.0802 5024 SystemInfo: 2011/06/20 18:17:52.0802 5024 2011/06/20 18:17:52.0802 5024 OS Version: 6.0.6000 ServicePack: 0.0 2011/06/20 18:17:52.0802 5024 Product type: Workstation 2011/06/20 18:17:52.0802 5024 ComputerName: USER-PC 2011/06/20 18:17:52.0803 5024 UserName: client 2011/06/20 18:17:52.0803 5024 Windows directory: C:\Windows 2011/06/20 18:17:52.0803 5024 System windows directory: C:\Windows 2011/06/20 18:17:52.0803 5024 Processor architecture: Intel x86 2011/06/20 18:17:52.0803 5024 Number of processors: 2 2011/06/20 18:17:52.0803 5024 Page size: 0x1000 2011/06/20 18:17:52.0803 5024 Boot type: Normal boot 2011/06/20 18:17:52.0803 5024 ================================================================================ 2011/06/20 18:17:54.0033 5024 Initialize success 2011/06/20 18:18:03.0392 2436 ================================================================================ 2011/06/20 18:18:03.0392 2436 Scan started 2011/06/20 18:18:03.0392 2436 Mode: Manual; 2011/06/20 18:18:03.0392 2436 ================================================================================ 2011/06/20 18:18:05.0037 2436 ACPI (84fc6df81212d16be5c4f441682feccc) C:\Windows\system32\drivers\acpi.sys 2011/06/20 18:18:05.0135 2436 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 2011/06/20 18:18:05.0202 2436 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 2011/06/20 18:18:05.0224 2436 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 2011/06/20 18:18:05.0260 2436 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 2011/06/20 18:18:05.0305 2436 AFD (5d24caf8efd924a875698ff28384db8b) C:\Windows\system32\drivers\afd.sys 2011/06/20 18:18:05.0341 2436 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 2011/06/20 18:18:05.0391 2436 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/06/20 18:18:05.0427 2436 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys 2011/06/20 18:18:05.0449 2436 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 2011/06/20 18:18:05.0474 2436 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys 2011/06/20 18:18:05.0500 2436 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 2011/06/20 18:18:05.0524 2436 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 2011/06/20 18:18:05.0665 2436 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 2011/06/20 18:18:05.0702 2436 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 2011/06/20 18:18:05.0732 2436 AsyncMac (e86cf7ce67d5de898f27ef884dc357d8) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/06/20 18:18:05.0768 2436 atapi (b35cfcef838382ab6490b321c87edf17) C:\Windows\system32\drivers\atapi.sys 2011/06/20 18:18:05.0818 2436 Beep (ac3dd1708b22761ebd7cbe14dcc3b5d7) C:\Windows\system32\drivers\Beep.sys 2011/06/20 18:18:05.0887 2436 bowser (913cd06fbe9105ce6077e90fd4418561) C:\Windows\system32\DRIVERS\bowser.sys 2011/06/20 18:18:05.0927 2436 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/06/20 18:18:05.0950 2436 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/06/20 18:18:06.0055 2436 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/06/20 18:18:06.0088 2436 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/06/20 18:18:06.0122 2436 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/06/20 18:18:06.0140 2436 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/06/20 18:18:06.0163 2436 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/06/20 18:18:06.0219 2436 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\Windows\system32\drivers\BVRPMPR5.SYS 2011/06/20 18:18:06.0263 2436 cdfs (6c3a437fc873c6f6a4fc620b6888cb86) C:\Windows\system32\DRIVERS\cdfs.sys 2011/06/20 18:18:06.0285 2436 cdrom (8d1866e61af096ae8b582454f5e4d303) C:\Windows\system32\DRIVERS\cdrom.sys 2011/06/20 18:18:06.0322 2436 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys 2011/06/20 18:18:06.0363 2436 CLFS (1b84fd0937d3b99af9ba38ddff3daf54) C:\Windows\system32\CLFS.sys 2011/06/20 18:18:06.0391 2436 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys 2011/06/20 18:18:06.0411 2436 Compbatt (82b8c91d327cfecf76cb58716f7d4997) C:\Windows\system32\drivers\compbatt.sys 2011/06/20 18:18:06.0438 2436 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 2011/06/20 18:18:06.0467 2436 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 2011/06/20 18:18:06.0510 2436 DfsC (a7179de59ae269ab70345527894ccd7c) C:\Windows\system32\Drivers\dfsc.sys 2011/06/20 18:18:06.0564 2436 disk (841af4c4d41d3e3b2f244e976b0f7963) C:\Windows\system32\DRIVERS\disk.sys 2011/06/20 18:18:06.0628 2436 Dot4 (57b2d433a08b95e4f1b53a919937f3e5) C:\Windows\system32\DRIVERS\Dot4.sys 2011/06/20 18:18:06.0689 2436 Dot4Print (d93fa484bb62fbe7e5ef335c5415d3cf) C:\Windows\system32\DRIVERS\Dot4Prt.sys 2011/06/20 18:18:06.0716 2436 dot4usb (599742c4260fb3e8edb3be148b8ce856) C:\Windows\system32\DRIVERS\dot4usb.sys 2011/06/20 18:18:06.0761 2436 drmkaud (ee472cd2c01f6f8e8aa1fa06ffef61b6) C:\Windows\system32\drivers\drmkaud.sys 2011/06/20 18:18:06.0825 2436 DXGKrnl (334988883de69adb27e2cf9f9715bbdb) C:\Windows\System32\drivers\dxgkrnl.sys 2011/06/20 18:18:06.0879 2436 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/06/20 18:18:06.0935 2436 Ecache (0efc7531b936ee57fdb4e837664c509f) C:\Windows\system32\drivers\ecache.sys 2011/06/20 18:18:07.0022 2436 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 2011/06/20 18:18:07.0065 2436 fastfat (84a317cb0b3954d3768cdcd018dbf670) C:\Windows\system32\drivers\fastfat.sys 2011/06/20 18:18:07.0100 2436 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 2011/06/20 18:18:07.0122 2436 FileInfo (65773d6115c037ffd7ef8280ae85eb9d) C:\Windows\system32\drivers\fileinfo.sys 2011/06/20 18:18:07.0150 2436 Filetrace (c226dd0de060745f3e042f58dcf78402) C:\Windows\system32\drivers\filetrace.sys 2011/06/20 18:18:07.0173 2436 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/06/20 18:18:07.0191 2436 FltMgr (a6a8da7ae4d53394ab22ac3ab6d3f5d3) C:\Windows\system32\drivers\fltmgr.sys 2011/06/20 18:18:07.0236 2436 Fs_Rec (66a078591208baa210c7634b11eb392c) C:\Windows\system32\drivers\Fs_Rec.sys 2011/06/20 18:18:07.0259 2436 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 2011/06/20 18:18:07.0305 2436 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2011/06/20 18:18:07.0353 2436 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 2011/06/20 18:18:07.0387 2436 HDAudBus (0db613a7e427b5663563677796fd5258) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/06/20 18:18:07.0418 2436 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/06/20 18:18:07.0438 2436 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/06/20 18:18:07.0469 2436 HidUsb (3c64042b95e583b366ba4e5d2450235e) C:\Windows\system32\DRIVERS\hidusb.sys 2011/06/20 18:18:07.0520 2436 hitmanpro35 (d7e05e0173719b66bb108f3d97e49a6a) C:\Windows\system32\drivers\hitmanpro35.sys 2011/06/20 18:18:07.0546 2436 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 2011/06/20 18:18:07.0610 2436 HTTP (3c3cba3ce1a66439a960d4531a167c39) C:\Windows\system32\drivers\HTTP.sys 2011/06/20 18:18:07.0640 2436 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 2011/06/20 18:18:07.0691 2436 i8042prt (1c9ee072baa3abb460b91d7ee9152660) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/06/20 18:18:07.0722 2436 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 2011/06/20 18:18:07.0797 2436 igfx (9378d57e2b96c0a185d844770ad49948) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/06/20 18:18:07.0854 2436 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/06/20 18:18:07.0914 2436 intelide (988981c840084f480ba9e3319cebde1b) C:\Windows\system32\drivers\intelide.sys 2011/06/20 18:18:07.0935 2436 intelppm (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys 2011/06/20 18:18:07.0967 2436 IpFilterDriver (880c6f86cc3f551b8fea2c11141268c0) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/06/20 18:18:08.0057 2436 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 2011/06/20 18:18:08.0078 2436 IPNAT (10077c35845101548037df04fd1a420b) C:\Windows\system32\DRIVERS\ipnat.sys 2011/06/20 18:18:08.0124 2436 IRENUM (a82f328f4792304184642d6d397bb1e3) C:\Windows\system32\drivers\irenum.sys 2011/06/20 18:18:08.0144 2436 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 2011/06/20 18:18:08.0173 2436 iScsiPrt (4dca456d4d5723f8fa9c6760d240b0df) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/06/20 18:18:08.0202 2436 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/06/20 18:18:08.0229 2436 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/06/20 18:18:08.0263 2436 kbdclass (b076b2ab806b3f696dab21375389101c) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/06/20 18:18:08.0321 2436 kbdhid (ed61dbc6603f612b7338283edbacbc4b) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/06/20 18:18:08.0361 2436 KSecDD (0a829977b078dea11641fc2af87ceade) C:\Windows\system32\Drivers\ksecdd.sys 2011/06/20 18:18:08.0415 2436 lltdio (fd015b4f95daa2b712f0e372a116fbad) C:\Windows\system32\DRIVERS\lltdio.sys 2011/06/20 18:18:08.0449 2436 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 2011/06/20 18:18:08.0477 2436 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 2011/06/20 18:18:08.0530 2436 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 2011/06/20 18:18:08.0566 2436 luafv (42885bb44b6e065b8575a8dd6c430c52) C:\Windows\system32\drivers\luafv.sys 2011/06/20 18:18:08.0618 2436 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 2011/06/20 18:18:08.0662 2436 Modem (21755967298a46fb6adfec9db6012211) C:\Windows\system32\drivers\modem.sys 2011/06/20 18:18:08.0703 2436 monitor (7446e104a5fe5987ca9e4983fbac4f97) C:\Windows\system32\DRIVERS\monitor.sys 2011/06/20 18:18:08.0742 2436 mouclass (5fba13c1a1841b0885d316ed3589489d) C:\Windows\system32\DRIVERS\mouclass.sys 2011/06/20 18:18:08.0793 2436 mouhid (b569b5c5d3bde545df3a6af512cccdba) C:\Windows\system32\DRIVERS\mouhid.sys 2011/06/20 18:18:08.0825 2436 MountMgr (01f1e5a3e4877c931cbb31613fec16a6) C:\Windows\system32\drivers\mountmgr.sys 2011/06/20 18:18:08.0858 2436 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 2011/06/20 18:18:08.0886 2436 mpsdrv (6e7a7f0c1193ee5648443fe2d4b789ec) C:\Windows\system32\drivers\mpsdrv.sys 2011/06/20 18:18:08.0926 2436 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/06/20 18:18:08.0953 2436 MRxDAV (1d8828b98ee309d65e006f0829e280e5) C:\Windows\system32\drivers\mrxdav.sys 2011/06/20 18:18:08.0995 2436 mrxsmb (8af705ce1bb907932157fab821170f27) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/06/20 18:18:09.0016 2436 mrxsmb10 (47e13ab23371be3279eef22bbfa2c1be) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/06/20 18:18:09.0035 2436 mrxsmb20 (90b3fc7bd6b3d7ee7635debba2187f66) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/06/20 18:18:09.0058 2436 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys 2011/06/20 18:18:09.0097 2436 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 2011/06/20 18:18:09.0132 2436 Msfs (729eafefd4e7417165f353a18dbe947d) C:\Windows\system32\drivers\Msfs.sys 2011/06/20 18:18:09.0159 2436 msisadrv (5f454a16a5146cd91a176d70f0cfa3ec) C:\Windows\system32\drivers\msisadrv.sys 2011/06/20 18:18:09.0191 2436 MSKSSRV (892cedefa7e0ffe7be8da651b651d047) C:\Windows\system32\drivers\MSKSSRV.sys 2011/06/20 18:18:09.0219 2436 MSPCLOCK (ae2cb1da69b2676b4cee2a501af5871c) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/06/20 18:18:09.0243 2436 MSPQM (f910da84fa90c44a3addb7cd874463fd) C:\Windows\system32\drivers\MSPQM.sys 2011/06/20 18:18:09.0259 2436 MsRPC (84571c0ae07647ba38d493f5f0015df7) C:\Windows\system32\drivers\MsRPC.sys 2011/06/20 18:18:09.0294 2436 mssmbios (4385c80ede885e25492d408cad91bd6f) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/06/20 18:18:09.0327 2436 MSTEE (c826dd1373f38afd9ca46ec3c436a14e) C:\Windows\system32\drivers\MSTEE.sys 2011/06/20 18:18:09.0346 2436 Mup (fa7aa70050cf5e2d15de00941e5665e5) C:\Windows\system32\Drivers\mup.sys 2011/06/20 18:18:09.0393 2436 NativeWifiP (6da4a0fc7c0e83df0cb3cfd0a514c3bc) C:\Windows\system32\DRIVERS\nwifi.sys 2011/06/20 18:18:09.0434 2436 NDIS (227c11e1e7cf6ef8afb2a238d209760c) C:\Windows\system32\drivers\ndis.sys 2011/06/20 18:18:09.0478 2436 NdisTapi (81659cdcbd0f9a9e07e6878ad8c78d3f) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/06/20 18:18:09.0498 2436 Ndisuio (5de5ee546bf40838ebe0e01cb629df64) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/06/20 18:18:09.0518 2436 NdisWan (397402adcbb8946223a1950101f6cd94) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/06/20 18:18:09.0567 2436 NDProxy (1b24fa907af283199a81b3bb37e5e526) C:\Windows\system32\drivers\NDProxy.sys 2011/06/20 18:18:09.0619 2436 NetBIOS (356dbb9f98e8dc1028dd3092fceeb877) C:\Windows\system32\DRIVERS\netbios.sys 2011/06/20 18:18:09.0657 2436 netbt (e3a168912e7eefc3bd3b814720d68b41) C:\Windows\system32\DRIVERS\netbt.sys 2011/06/20 18:18:09.0717 2436 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/06/20 18:18:09.0748 2436 Npfs (4f9832beb9fafd8ceb0e541f1323b26e) C:\Windows\system32\drivers\Npfs.sys 2011/06/20 18:18:09.0804 2436 nsiproxy (b488dfec274de1fc9d653870ef2587be) C:\Windows\system32\drivers\nsiproxy.sys 2011/06/20 18:18:09.0861 2436 Ntfs (37430aa7a66d7a63407adc2c0d05e9f6) C:\Windows\system32\drivers\Ntfs.sys 2011/06/20 18:18:09.0900 2436 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/06/20 18:18:09.0918 2436 Null (ec5efb3c60f1b624648344a328bce596) C:\Windows\system32\drivers\Null.sys 2011/06/20 18:18:09.0946 2436 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys 2011/06/20 18:18:10.0032 2436 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys 2011/06/20 18:18:10.0059 2436 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 2011/06/20 18:18:10.0125 2436 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys 2011/06/20 18:18:10.0166 2436 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/06/20 18:18:10.0196 2436 partmgr (555a5b2c8022983bc7467bc925b222ee) C:\Windows\system32\drivers\partmgr.sys 2011/06/20 18:18:10.0220 2436 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/06/20 18:18:10.0251 2436 pci (1085d75657807e0e8b32f9e19a1647c3) C:\Windows\system32\drivers\pci.sys 2011/06/20 18:18:10.0277 2436 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys 2011/06/20 18:18:10.0307 2436 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2011/06/20 18:18:10.0353 2436 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/06/20 18:18:10.0468 2436 PptpMiniport (6c359ac71d7b550a0d41f9db4563ce05) C:\Windows\system32\DRIVERS\raspptp.sys 2011/06/20 18:18:10.0505 2436 PRISM_A02 (57e95881e5f014816a8a53ad94ee0c48) C:\Windows\system32\DRIVERS\WUSB20XP.sys 2011/06/20 18:18:10.0546 2436 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 2011/06/20 18:18:10.0618 2436 PSched (2c8bae55247c4e09352e870292e4d1ab) C:\Windows\system32\DRIVERS\pacer.sys 2011/06/20 18:18:10.0676 2436 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 2011/06/20 18:18:10.0725 2436 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/06/20 18:18:10.0767 2436 QWAVEdrv (d2b3e2b7426dc23e185fbc73c8936c12) C:\Windows\system32\drivers\qwavedrv.sys 2011/06/20 18:18:10.0780 2436 RasAcd (bd7b30f55b3649506dd8b3d38f571d2a) C:\Windows\system32\DRIVERS\rasacd.sys 2011/06/20 18:18:10.0817 2436 Rasl2tp (88587dd843e2059848995b407b67f6cf) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/06/20 18:18:10.0842 2436 RasPppoe (ccf4e9c6cbbac81437f88cb2ae0b6c96) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/06/20 18:18:10.0868 2436 rdbss (54129c5d9581bbec8bd1ebd3ba813f47) C:\Windows\system32\DRIVERS\rdbss.sys 2011/06/20 18:18:10.0885 2436 RDPCDD (794585276b5d7fca9f3fc15543f9f0b9) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/06/20 18:18:10.0918 2436 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys 2011/06/20 18:18:10.0934 2436 RDPENCDD (980b56e2e273e19d3a9d72d5c420f008) C:\Windows\system32\drivers\rdpencdd.sys 2011/06/20 18:18:10.0995 2436 RDPWD (8830e790a74a96605faba74f9665bb3c) C:\Windows\system32\drivers\RDPWD.sys 2011/06/20 18:18:11.0064 2436 RimUsb (f17713d108aca124a139fde877eef68a) C:\Windows\system32\Drivers\RimUsb.sys 2011/06/20 18:18:11.0098 2436 RMCAST (8804bcb4383859f66ffd51f049a1d744) C:\Windows\system32\DRIVERS\RMCAST.sys 2011/06/20 18:18:11.0141 2436 rspndr (97e939d2128fec5d5a3e6e79b290a2f4) C:\Windows\system32\DRIVERS\rspndr.sys 2011/06/20 18:18:11.0181 2436 RTL8169 (283392af1860ecdb5e0f8ebd7f3d72df) C:\Windows\system32\DRIVERS\Rtlh86.sys 2011/06/20 18:18:11.0207 2436 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/06/20 18:18:11.0254 2436 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/06/20 18:18:11.0286 2436 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/06/20 18:18:11.0314 2436 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/06/20 18:18:11.0359 2436 sermouse (450accd77ec5cea720c1cdb9e26b953b) C:\Windows\system32\drivers\sermouse.sys 2011/06/20 18:18:11.0399 2436 sffdisk (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys 2011/06/20 18:18:11.0426 2436 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 2011/06/20 18:18:11.0448 2436 sffp_sd (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys 2011/06/20 18:18:11.0476 2436 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/06/20 18:18:11.0515 2436 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 2011/06/20 18:18:11.0542 2436 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 2011/06/20 18:18:11.0572 2436 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 2011/06/20 18:18:11.0610 2436 Smb (ac0d90738adb51a6fd12ff00874a2162) C:\Windows\system32\DRIVERS\smb.sys 2011/06/20 18:18:11.0678 2436 spldr (426f9b029aa9162ceccf65369457d046) C:\Windows\system32\drivers\spldr.sys 2011/06/20 18:18:11.0717 2436 srv (038579c35f7cad4a4bbf735dbf83277d) C:\Windows\system32\DRIVERS\srv.sys 2011/06/20 18:18:11.0748 2436 srv2 (6971a757af8cb5e2cbcbb76cc530db6c) C:\Windows\system32\DRIVERS\srv2.sys 2011/06/20 18:18:11.0777 2436 srvnet (9e1a4603b874eebce0298113951abefb) C:\Windows\system32\DRIVERS\srvnet.sys 2011/06/20 18:18:11.0801 2436 swenum (1379bdb336f8158c176a465e30759f57) C:\Windows\system32\DRIVERS\swenum.sys 2011/06/20 18:18:11.0833 2436 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/06/20 18:18:11.0857 2436 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/06/20 18:18:11.0877 2436 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/06/20 18:18:11.0936 2436 Tcpip (4a82fa8f0df67aa354580c3faaf8bde3) C:\Windows\system32\drivers\tcpip.sys 2011/06/20 18:18:11.0975 2436 Tcpip6 (4a82fa8f0df67aa354580c3faaf8bde3) C:\Windows\system32\DRIVERS\tcpip.sys 2011/06/20 18:18:11.0997 2436 tcpipreg (5ce0c4a7b12d0067dad527d72b68c726) C:\Windows\system32\drivers\tcpipreg.sys 2011/06/20 18:18:12.0021 2436 TDPIPE (964248aef49c31fa6a93201a73ffaf50) C:\Windows\system32\drivers\tdpipe.sys 2011/06/20 18:18:12.0045 2436 TDTCP (7d2c1ae1648a60fce4aa0f7982e419d3) C:\Windows\system32\drivers\tdtcp.sys 2011/06/20 18:18:12.0071 2436 tdx (ab4fde8af4a0270a46a001c08cbce1c2) C:\Windows\system32\DRIVERS\tdx.sys 2011/06/20 18:18:12.0090 2436 TermDD (2c549bd9dd091fbfaa0a2a48e82ec2fb) C:\Windows\system32\DRIVERS\termdd.sys 2011/06/20 18:18:12.0147 2436 tssecsrv (29f0eca726f0d51f7e048bdb0b372f29) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/06/20 18:18:12.0189 2436 tunmp (65e953bc0084d44498b51f59784d2a82) C:\Windows\system32\DRIVERS\tunmp.sys 2011/06/20 18:18:12.0210 2436 tunnel (4a39bda5e0fd30bdf4884f9d33ae6105) C:\Windows\system32\DRIVERS\tunnel.sys 2011/06/20 18:18:12.0234 2436 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 2011/06/20 18:18:12.0265 2436 udfs (6348da98707ceda8a0dfb05820e17732) C:\Windows\system32\DRIVERS\udfs.sys 2011/06/20 18:18:12.0313 2436 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 2011/06/20 18:18:12.0337 2436 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 2011/06/20 18:18:12.0367 2436 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/06/20 18:18:12.0393 2436 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/06/20 18:18:12.0429 2436 umbus (3fb78f1d1dd86d87bececd9dffa24dd9) C:\Windows\system32\DRIVERS\umbus.sys 2011/06/20 18:18:12.0479 2436 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\Windows\system32\Drivers\usbaapl.sys 2011/06/20 18:18:12.0540 2436 usbaudio (f6bf998ae33e3fb6c7d27f0560f1173f) C:\Windows\system32\drivers\usbaudio.sys 2011/06/20 18:18:12.0574 2436 usbccgp (b0ba9caffe9b0555ec0317f30cb79cd2) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/06/20 18:18:12.0609 2436 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/06/20 18:18:12.0639 2436 usbehci (c9fcd05b0a80ea08c2768e5a279b14de) C:\Windows\system32\DRIVERS\usbehci.sys 2011/06/20 18:18:12.0672 2436 usbhub (5e44f7d957f7560da06bfe6b84b58a35) C:\Windows\system32\DRIVERS\usbhub.sys 2011/06/20 18:18:12.0697 2436 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2011/06/20 18:18:12.0726 2436 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\DRIVERS\usbprint.sys 2011/06/20 18:18:12.0755 2436 usbscan (b1f95285c08ddfe00c0b955462637ec7) C:\Windows\system32\DRIVERS\usbscan.sys 2011/06/20 18:18:12.0773 2436 USBSTOR (7887ce56934e7f104e98c975f47353c5) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/06/20 18:18:12.0794 2436 usbuhci (d864735b0bfcb65440960a0b7cc1a38d) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/06/20 18:18:12.0852 2436 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/06/20 18:18:12.0868 2436 VgaSave (17a8f877314e4067f8c8172cc6d9101c) C:\Windows\System32\drivers\vga.sys 2011/06/20 18:18:12.0899 2436 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 2011/06/20 18:18:12.0933 2436 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 2011/06/20 18:18:12.0962 2436 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys 2011/06/20 18:18:13.0043 2436 volmgr (103e84c95832d0ed93507997cc7b54e8) C:\Windows\system32\drivers\volmgr.sys 2011/06/20 18:18:13.0069 2436 volmgrx (294da8d3f965f6a8db934a83c7b461ff) C:\Windows\system32\drivers\volmgrx.sys 2011/06/20 18:18:13.0094 2436 volsnap (80dc0c9bcb579ed9815001a4d37cbfd5) C:\Windows\system32\drivers\volsnap.sys 2011/06/20 18:18:13.0128 2436 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 2011/06/20 18:18:13.0212 2436 VX3000 (13acfed0e6adca97440169dfd127ebcf) C:\Windows\system32\DRIVERS\VX3000.sys 2011/06/20 18:18:13.0281 2436 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/06/20 18:18:13.0313 2436 Wanarp (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys 2011/06/20 18:18:13.0325 2436 Wanarpv6 (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys 2011/06/20 18:18:13.0366 2436 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 2011/06/20 18:18:13.0403 2436 Wdf01000 (7b5f66e4a2219c7d9daf9e738480e534) C:\Windows\system32\drivers\Wdf01000.sys 2011/06/20 18:18:13.0499 2436 WmiAcpi (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys 2011/06/20 18:18:13.0574 2436 WpdUsb (2d27171b16a577ef14c1273668753485) C:\Windows\system32\DRIVERS\wpdusb.sys 2011/06/20 18:18:13.0586 2436 ws2ifsl (84620aecdcfd2a7a14e6263927d8c0ed) C:\Windows\system32\drivers\ws2ifsl.sys 2011/06/20 18:18:13.0632 2436 WUDFRd (a2aafcc8a204736296d937c7c545b53f) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/06/20 18:18:13.0739 2436 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 2011/06/20 18:18:13.0746 2436 ================================================================================ 2011/06/20 18:18:13.0747 2436 Scan finished 2011/06/20 18:18:13.0747 2436 ================================================================================ 2011/06/20 18:18:13.0770 2396 Detected object count: 0 2011/06/20 18:18:13.0770 2396 Actual detected object count: 0
This is the OTL.txt

OTL logfile created on: 6/20/2011 6:21:22 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\client\Downloads
Windows Vista Home Basic Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.83 Gb Available Physical Memory | 41.61% Memory free
4.19 Gb Paging File | 2.33 Gb Available in Paging File | 55.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 127.39 Gb Free Space | 54.70% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: client | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\client\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\mspatcha32.exe (wpcubed GmbH)
PRC - C:\ProgramData\iertutil32.exe (wpcubed GmbH)
PRC - C:\Program Files\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
PRC - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AIM6\aim6.exe (AOL LLC)
PRC - C:\Program Files\AIM6\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\Windows\vVX3000.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\client\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (NMIndexingService) – File not found
SRV - (wscsvc32) – C:\Windows\System32\mspatcha32.exe (wpcubed GmbH)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (PMBDeviceInfoProvider) – C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Driver Services (SafeList) ==========

DRV - (hitmanpro35) – C:\Windows\System32\drivers\hitmanpro35.sys ()
DRV - (RMCAST) RMCAST (Pgm) – C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (BVRPMPR5) – C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (VX3000) – C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation)
DRV - (PRISM_A02) – C:\Windows\System32\drivers\WUSB20XP.sys (Cisco-Linksys, LLC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 16 41 7B 02 B9 75 A0 4F 9B DB 77 3B 1F 91 4F 07 [binary data]
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:3.2.5.2
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0.14908
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:[removed]
FF - prefs.js..keyword.URL: "http://urlseek40.vmn.net/search.php?lg=en&type=dns&tbn=oovoo2_0dn&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/07 17:03:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/29 15:35:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/03 00:22:29 | 000,000,000 | —D | M]

[2009/09/20 15:22:49 | 000,000,000 | —D | M] (No name found) – C:\Users\client\AppData\Roaming\mozilla\Extensions
[2009/09/20 15:22:49 | 000,000,000 | —D | M] (No name found) – C:\Users\client\AppData\Roaming\mozilla\Extensions\[removed]
[2011/06/16 11:19:07 | 000,000,000 | —D | M] (No name found) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions
[2009/10/12 21:17:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/16 11:19:07 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/06/14 15:00:59 | 000,000,000 | —D | M] (XUL Cache) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{ad11e981-6c6d-45f2-9eee-2ee95120b2fc}
[2011/04/03 00:23:38 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/06/08 18:09:14 | 000,000,000 | —D | M] (ShopToWin18) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{fb320179-bf62-4606-9d75-5e82785ed1bf}
[2011/04/03 00:23:44 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\[removed]
[2011/04/03 00:22:32 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/03 15:52:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/16 22:07:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/01 00:59:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/02 23:59:41 | 000,000,000 | —D | M] (The Browser Highlighter) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\USERS\CLIENT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KL6GJPCX.DEFAULT\EXTENSIONS\{6E764C17-863A-450F-BDD0-6772BD5AAA18}.XPI
[2011/04/29 15:35:34 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/09/15 05:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/03 23:55:44 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2010/12/09 06:47:06 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2010/06/01 22:54:44 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {027B4116-75B9-4FA0-9BDB-773B1F914F07} - C:\Windows\System32\AudioSes32.dll (Dmitry Streblechenko)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O2 - BHO: (Shop to Win 18) - {CA2F8E90-0E43-46AD-89C0-7634A233ED00} - C:\Program Files\Shop to Win 18\Shop to Win 18.dll (Shop To Win, LLC)
O2 - BHO: (b016d812) - {DF9F5063-9246-7558-7E36-C94CBA7D3D55} - C:\ProgramData\AudioSes32.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O4 - HKLM..\Run: [AppleSyncNotifier] File not found
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Aim6] C:\Program Files\AIM6\aim6.exe (AOL LLC)
O4 - HKCU..\Run: [OM2_Monitor] File not found
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\Windows\System32\avgrsstx.dll) - File not found
O20 - AppInit_DLLs: (C:\ProgramData\AudioSes32.dll) - C:\ProgramData\AudioSes32.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\client\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\client\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{f7a229e7-967a-11df-87e9-000f66723b95}\Shell\AutoRun\command - "" = L:\PMBP_Win.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (bootdelete) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\Windows\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/06/12 17:24:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elsword
[2011/06/12 17:20:09 | 000,000,000 | —D | C] – C:\Program Files\Kill3rCombo
[2011/06/08 18:09:13 | 000,000,000 | —D | C] – C:\Users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 18
[2011/06/08 18:09:09 | 000,000,000 | —D | C] – C:\Program Files\Shop to Win 18
[2011/06/08 18:09:08 | 000,000,000 | —D | C] – C:\Program Files\Shop To Win
[2011/05/30 11:20:05 | 000,779,776 | —- | C] (wpcubed GmbH) – C:\ProgramData\iertutil32.exe
[2011/05/30 11:20:02 | 000,779,776 | —- | C] (wpcubed GmbH) – C:\Windows\System32\mspatcha32.exe
[2011/05/30 11:20:00 | 000,356,864 | —- | C] (Dmitry Streblechenko) – C:\Windows\System32\AudioSes32.dll
[2011/05/28 21:07:41 | 000,000,000 | —D | C] – C:\Users\client\AppData\Roaming\go
[2011/05/28 21:07:37 | 000,000,000 | —D | C] – C:\ProgramData\Easybits GO
[2011/05/25 22:19:56 | 000,000,000 | —D | C] – C:\ProgramData\Nexon
[2011/05/23 15:14:28 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[1 C:\Users\client\Desktop\*.tmp files -> C:\Users\client\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/20 18:17:25 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/20 18:17:25 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/20 18:10:34 | 000,000,120 | —- | M] () – C:\ProgramData\10e58f40
[2011/06/20 17:30:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/20 17:27:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001UA.job
[2011/06/19 23:48:59 | 000,003,499 | —- | M] () – C:\Users\client\Desktop\sss.jpg
[2011/06/19 20:30:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/19 18:27:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001Core.job
[2011/06/19 13:48:04 | 000,010,273 | —- | M] () – C:\Users\client\Desktop\asfas.jpg
[2011/06/19 12:17:55 | 000,043,008 | —- | M] () – C:\Users\client\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/19 12:17:09 | 000,921,624 | —- | M] () – C:\img2-001.raw
[2011/06/18 18:52:40 | 015,326,334 | —- | M] () – C:\Users\client\Desktop\lmao.wmv
[2011/06/18 18:33:34 | 000,622,906 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/06/18 18:33:34 | 000,108,122 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/06/18 17:16:39 | 000,063,962 | —- | M] () – C:\Users\client\Desktop\Untitled.jpg
[2011/06/16 17:17:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/16 17:17:26 | 2134,736,896 | -HS- | M] () – C:\hiberfil.sys
[2011/06/14 18:23:13 | 000,002,047 | —- | M] () – C:\Users\client\Desktop\Google Chrome.lnk
[2011/06/14 18:23:13 | 000,002,009 | —- | M] () – C:\Users\client\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/06/12 17:24:09 | 000,000,936 | —- | M] () – C:\Users\Public\Desktop\Elsword.lnk
[2011/06/08 18:09:03 | 000,001,726 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[2011/05/30 11:20:05 | 000,000,086 | —- | M] () – C:\Windows\System32\986423088
[2011/05/30 11:20:04 | 000,183,808 | —- | M] () – C:\ProgramData\AudioSes32.dll
[2011/05/30 11:20:00 | 000,356,864 | —- | M] (Dmitry Streblechenko) – C:\Windows\System32\AudioSes32.dll
[2011/05/30 11:19:48 | 000,779,776 | —- | M] (wpcubed GmbH) – C:\Windows\System32\mspatcha32.exe
[2011/05/30 11:19:48 | 000,779,776 | —- | M] (wpcubed GmbH) – C:\ProgramData\iertutil32.exe
[1 C:\Users\client\Desktop\*.tmp files -> C:\Users\client\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/19 23:48:58 | 000,003,499 | —- | C] () – C:\Users\client\Desktop\sss.jpg
[2011/06/19 13:48:04 | 000,010,273 | —- | C] () – C:\Users\client\Desktop\asfas.jpg
[2011/06/18 18:51:40 | 015,326,334 | —- | C] () – C:\Users\client\Desktop\lmao.wmv
[2011/06/18 17:16:39 | 000,063,962 | —- | C] () – C:\Users\client\Desktop\Untitled.jpg
[2011/06/12 17:24:09 | 000,000,936 | —- | C] () – C:\Users\Public\Desktop\Elsword.lnk
[2011/05/31 19:30:45 | 000,000,120 | —- | C] () – C:\ProgramData\10e58f40
[2011/05/30 11:20:04 | 000,183,808 | —- | C] () – C:\ProgramData\AudioSes32.dll
[2011/05/30 11:20:02 | 000,000,086 | —- | C] () – C:\Windows\System32\986423088
[2011/05/28 21:07:42 | 000,001,585 | —- | C] () – C:\Users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play games (EasyBits GO).lnk
[2011/04/30 16:49:13 | 000,000,007 | -HS- | C] () – C:\Users\client\AppData\Roaming\date
[2011/04/30 16:49:13 | 000,000,002 | -HS- | C] () – C:\Users\client\AppData\Roaming\evf6
[2011/01/21 17:20:26 | 000,000,034 | -H– | C] () – C:\Windows\System32\Converter_sysquict.dat
[2011/01/21 17:20:15 | 000,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/01/21 17:20:14 | 000,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/01/21 17:20:14 | 000,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/01/21 17:20:13 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2011/01/21 17:20:13 | 000,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/05/29 15:44:47 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat
[2010/05/27 21:48:59 | 000,000,004 | —- | C] () – C:\Users\client\AppData\Roaming\czyiwa.dat
[2010/05/27 19:52:44 | 000,085,504 | RHS- | C] () – C:\Windows\System32\msdtw.dll
[2010/05/23 16:17:31 | 000,000,000 | —- | C] () – C:\Users\client\AppData\Local\prvlcl.dat
[2010/04/12 20:52:17 | 000,015,944 | —- | C] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2010/04/12 19:54:11 | 000,000,168 | –S- | C] () – C:\Users\client\AppData\Local\3498221558.dat
[2010/04/12 19:53:15 | 000,010,920 | -HS- | C] () – C:\Users\client\AppData\Local\4T227ly4
[2010/04/12 19:53:15 | 000,010,920 | -HS- | C] () – C:\ProgramData\4T227ly4
[2010/01/07 16:59:13 | 000,163,685 | —- | C] () – C:\Windows\hpoins36.dat.temp
[2010/01/07 16:59:13 | 000,000,652 | —- | C] () – C:\Windows\hpomdl36.dat.temp
[2010/01/07 16:48:23 | 000,062,333 | —- | C] () – C:\Windows\hpqins01.dat
[2010/01/03 23:42:48 | 000,163,747 | —- | C] () – C:\Windows\hpoins36.dat
[2010/01/03 23:42:48 | 000,000,652 | —- | C] () – C:\Windows\hpomdl36.dat
[2009/10/09 20:51:57 | 000,024,064 | —- | C] () – C:\Users\client\AppData\Roaming\UserTile.png
[2009/09/11 22:14:45 | 000,000,552 | —- | C] () – C:\Users\client\AppData\Local\d3d8caps.dat
[2009/09/11 19:06:29 | 000,040,960 | —- | C] () – C:\Windows\System32\IsUser11b.dll
[2009/09/10 02:05:04 | 000,043,008 | —- | C] () – C:\Users\client\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/08 14:22:29 | 000,001,356 | —- | C] () – C:\Users\client\AppData\Local\d3d9caps.dat
[2009/09/07 13:16:16 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/02/11 19:55:18 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1437.dll
[2008/02/11 19:34:48 | 002,215,364 | —- | C] () – C:\Windows\System32\igklg400.bin
[2008/02/11 19:34:48 | 001,971,732 | —- | C] () – C:\Windows\System32\igklg450.bin
[2008/02/11 19:34:48 | 000,029,932 | —- | C] () – C:\Windows\System32\igmedcompkrn.bin
[2007/04/10 17:46:48 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini
[2006/11/02 08:53:49 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:44:53 | 000,283,664 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 06:33:01 | 000,622,906 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,108,122 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:35:16 | 000,006,672 | —- | C] () – C:\Users\client\AppData\Local\ar-SAq.dat
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/11/02 03:22:43 | 000,099,999 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2006/11/02 03:22:43 | 000,018,271 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[1999/01/22 14:46:58 | 000,065,536 | —- | C] () – C:\Windows\System32\MSRTEDIT.DLL

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2006/11/02 05:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2009/09/07 16:31:13 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/06/16 17:17:26 | 2134,736,896 | -HS- | M] () – C:\hiberfil.sys
[2010/07/03 20:06:05 | 000,002,578 | —- | M] () – C:\ijjiFFPlugin.log
[2011/06/19 12:17:09 | 000,921,624 | —- | M] () – C:\img2-001.raw
[2009/09/15 17:17:18 | 000,921,624 | —- | M] () – C:\img2-003.raw
[2009/09/11 19:51:34 | 000,000,347 | -H– | M] () – C:\IPH.PH
[2010/06/13 23:39:45 | 000,741,721 | —- | M] () – C:\ituneslib.itl
[2010/07/30 22:13:18 | 000,129,814 | —- | M] () – C:\Maple0000.jpg
[2010/05/29 20:53:01 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/05/29 20:53:01 | 000,005,120 | -H– | M] () – C:\ntuser.dat.LOG1
[2010/05/29 20:53:00 | 000,000,000 | -H– | M] () – C:\ntuser.dat.LOG2
[2010/05/29 20:53:00 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{f117c357-6b74-11df-ada0-000f66723b95}.TM.blf
[2010/05/29 20:53:00 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{f117c357-6b74-11df-ada0-000f66723b95}.TMContainer00000000000000000001.regtrans-ms
[2010/05/29 20:53:00 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{f117c357-6b74-11df-ada0-000f66723b95}.TMContainer00000000000000000002.regtrans-ms
[2010/05/29 20:53:00 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{f117c363-6b74-11df-ada0-000f66723b95}.TM.blf
[2010/05/29 20:53:00 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{f117c363-6b74-11df-ada0-000f66723b95}.TMContainer00000000000000000001.regtrans-ms
[2010/05/29 20:53:00 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{f117c363-6b74-11df-ada0-000f66723b95}.TMContainer00000000000000000002.regtrans-ms
[2011/06/16 17:17:25 | 2448,662,528 | -HS- | M] () – C:\pagefile.sys
[2010/06/01 19:04:01 | 000,000,726 | —- | M] () – C:\rkill.log
[2011/06/20 18:20:11 | 000,057,370 | —- | M] () – C:\TDSSKiller.2.5.5.0_20.06.2011_18.17.50_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 08:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 08:35:34 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/10/06 16:37:30 | 000,315,392 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpfpp083.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/09/10 02:16:36 | 000,001,666 | -H– | M] () – C:\Users\client\AppData\Roaming\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2009/10/11 04:47:08 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 06:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/21 19:18:01 | 000,000,286 | -HS- | M] () – C:\Users\client\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2007/04/10 17:46:48 | 000,013,023 | —- | M] () – C:\Windows\VX3000.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/10/16 17:36:14 | 000,004,072 | —- | M] () – C:\Users\client\Favorites\=].jpg
[2009/09/08 14:22:41 | 000,000,402 | -HS- | M] () – C:\Users\client\Favorites\desktop.ini
[2010/10/12 20:55:41 | 004,472,941 | —- | M] () – C:\Users\client\Favorites\Girl Im Sure You Want More.mp3
[2010/11/27 11:16:58 | 000,001,854 | —- | M] () – C:\Users\client\Favorites\Safari.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2011/06/20 18:10:34 | 000,000,120 | —- | M] () – C:\ProgramData\10e58f40
[2010/04/12 20:43:37 | 000,010,920 | -HS- | M] () – C:\ProgramData\4T227ly4
[2011/05/30 11:20:04 | 000,183,808 | —- | M] () – C:\ProgramData\AudioSes32.dll
[2010/01/07 17:04:27 | 000,002,755 | —- | M] () – C:\ProgramData\hpzinstall.log
[2011/05/30 11:19:48 | 000,779,776 | —- | M] (wpcubed GmbH) – C:\ProgramData\iertutil32.exe

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-17 07:02:32

< End of report >
This is the extras.txt

OTL Extras logfile created on: 6/20/2011 6:21:22 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\client\Downloads
Windows Vista Home Basic Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.83 Gb Available Physical Memory | 41.61% Memory free
4.19 Gb Paging File | 2.33 Gb Available in Paging File | 55.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 127.39 Gb Free Space | 54.70% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: client | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – C:\PROGRA~1\MICROS~2\Office\FRONTPG.EXE
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00244425-877F-480A-8BB6-90414130F10B}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{002C9C4D-DF4A-480F-A562-6767BE934DF0}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=c:\windows\system32\dfsr.exe |
"{00DB654D-B11D-48AD-8781-EC22DB93CA54}" = rport=2178 | protocol=6 | dir=out | app=system |
"{00ECB57A-68AC-4FA5-A031-F7DCCC499824}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{091E9F76-394C-4F05-8592-744680C56741}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{0B80A26B-D705-462E-97D5-2AD08F07BBD4}" = lport=3702 | protocol=17 | dir=in | svc=bits | app=c:\windows\system32\svchost.exe |
"{0D6FBA14-08E2-4490-BA8C-BD5F9B56D181}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{18E01352-F18F-4A54-B9F3-178EC7D37A26}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{19E66891-68A4-4CA8-A6CE-B788BE5E547E}" = rport=10243 | protocol=6 | dir=out | app=system |
"{200DBF3A-D862-420F-8B7D-A50CC65E7670}" = lport=445 | protocol=6 | dir=in | app=system |
"{2292BC8B-D9E0-41E9-BEFA-53DE26322628}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{22BACC68-910E-4865-B111-B0D9FE57763D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{26FA9DD6-01C4-48D9-AB8A-6F4F179240E4}" = lport=37675 | protocol=17 | dir=in | name=oovoo udp port 37675 |
"{2BCF7D63-3D74-4DE6-B314-1AD8884297DB}" = lport=1701 | protocol=17 | dir=in | app=system |
"{3394D1D1-1B50-4F38-B16F-EF4DE7B60E56}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{35A422B3-58D3-4FDB-A652-37D2946F7785}" = lport=rpc | protocol=6 | dir=in | svc=schedule | app=c:\windows\system32\svchost.exe |
"{3692A888-09D0-4BF9-8E0E-DF08D43A5ADB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{397414C7-DD7D-40F4-ACC2-447114DC005D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3F60E279-95D3-4B38-97DF-12E1AF149FAA}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3FD9F15C-576A-4A72-87A0-66791411DE05}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=c:\windows\system32\svchost.exe |
"{401A1F76-9FDD-445F-AB85-195F7DC26F29}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{411EA277-3721-4848-AD74-365E062F83BB}" = lport=138 | protocol=17 | dir=in | app=system |
"{4301973E-C2F5-4F3E-9912-5C17072350EE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{460C9EC3-446E-4F59-9C10-583C72ECDE09}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\p2phost.exe |
"{4960DAA0-A918-4D7F-B164-52A0A0F67AEC}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{49D9AD2F-1853-44D8-B59B-AED35795CD91}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{4C4D230A-78B0-4E83-8AC3-EB2E76B99942}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{4D947441-FF3A-4EE0-B408-6C9EB7170F07}" = rport=445 | protocol=6 | dir=out | app=system |
"{5135047C-9961-461F-8A56-2724955784A2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{56B2BE5A-001C-462A-A34D-48AD5041FCE7}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=c:\windows\system32\dfsr.exe |
"{5DD621A2-379D-4D24-AE5D-B853126BC67D}" = lport=37674 | protocol=6 | dir=in | name=oovoo tcp port 37674 |
"{628A409C-BEBC-496F-AF26-DCEA1EDAE0C4}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{68B5F981-ACE6-4974-9982-A7F2714213FD}" = lport=2178 | protocol=6 | dir=in | app=system |
"{68C8CA7E-765D-4A95-99E2-DDAA656E6C0B}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=c:\windows\system32\svchost.exe |
"{6C0E71E0-72B4-4628-AA93-4E12D092BE0B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{70E09DE2-93B2-4981-B45E-BC427FF817BA}" = lport=137 | protocol=17 | dir=in | app=system |
"{739A9FD2-4A8E-4DD7-82BB-3C06349AFADF}" = lport=2869 | protocol=6 | dir=in | name=tcp 2869 |
"{7A32997B-3F02-482C-802D-5D1456CAEC8A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{7CF7B466-A5CA-4884-AC17-4B86FE175DE9}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{7EDCB580-137C-4545-A563-95D70C849CA8}" = lport=162 | protocol=17 | dir=in | svc=snmptrap | app=c:\windows\system32\snmptrap.exe |
"{7FF0CF21-9EBD-4C2B-9421-9840E2833AB6}" = lport=445 | protocol=6 | dir=in | app=system |
"{8141E78E-CC07-4C2D-AE26-A7980DAA0324}" = lport=37674 | protocol=17 | dir=in | name=oovoo udp port 37674 |
"{85D0AB22-3FEB-4611-92C4-5C89B5AF4702}" = lport=445 | protocol=6 | dir=in | app=system |
"{8C51166E-830E-43C1-9473-EB8CCAD951E8}" = lport=rpc | protocol=6 | dir=in | svc=* | app=c:\windows\system32\svchost.exe |
"{8D9B7A10-458D-46B0-BACF-8A5C4805DCE1}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{8EE65F29-9FC7-4209-B8F1-47B55CC7B73F}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{8F691683-84AD-4635-B997-9020EB3AD23A}" = rport=138 | protocol=17 | dir=out | app=system |
"{911CB8BE-DBF2-4997-90F4-9AB0714DD370}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{91303A09-1BFB-4FDC-9580-3BA124EDA9F2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{93A72CBA-CBE5-4AA5-8E35-2CA465C19C3C}" = lport=rpc | protocol=6 | dir=in | svc=eventlog | app=c:\windows\system32\svchost.exe |
"{96B3E57A-F613-478F-9DA8-AD7D9C21A6EE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{985A8788-517E-48E4-AC64-D9E6FB5A46A7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{99B0A725-DFD4-4901-8249-DA11F2329B0F}" = lport=1723 | protocol=6 | dir=in | app=system |
"{9B5FF91B-FBE0-4AD7-B06A-1A0D2FD3D9EA}" = lport=rpc | protocol=6 | dir=in | svc=bits | app=c:\windows\system32\svchost.exe |
"{A74052AA-E272-4F69-A85F-1BCF967E0852}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{B005FB84-12C8-4F96-9902-BE8667D738A9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{B188741E-A5D0-44D9-BF10-AA1455CE4666}" = rport=137 | protocol=17 | dir=out | app=system |
"{B375DE51-CD1C-4590-AC29-DDBD8EF8DC24}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=c:\windows\system32\svchost.exe |
"{B3B9A200-98B3-4A33-865F-B5EE1B579421}" = lport=139 | protocol=6 | dir=in | app=system |
"{B414B291-4FCD-45E7-953C-DFB452D391F6}" = rport=1701 | protocol=17 | dir=out | app=system |
"{B76592D2-A0C5-483E-A5DD-AF0EE71FB4A6}" = lport=1900 | protocol=17 | dir=in | name=udp 1900 |
"{B7DED796-CC30-4D94-BC04-37AAED19E53D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{B8184C98-12E6-48D1-9326-87116EB8F794}" = lport=445 | protocol=6 | dir=in | app=system |
"{BAF25516-BE82-4F85-8244-05267E266797}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{C029F3E7-07EE-4AA6-905A-8A7AA0F41929}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C8E327BC-37F6-453D-822D-748F8257A321}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{D04474E6-7757-4369-A598-C4CD18B60AA4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D213C58B-3FC5-4148-B9E9-F92C1340D398}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D869F732-C1C5-4263-9945-46BEBB86FAC1}" = lport=443 | protocol=17 | dir=in | name=oovoo udp port 443 |
"{D8832935-4EE4-4361-BF36-4E6A0169BB5D}" = lport=10243 | protocol=6 | dir=in | app=system |
"{D89D9687-4242-48A1-98EE-8EB204005EE7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D9A77DD8-B7AD-4B32-8F4F-F0D43208863B}" = rport=1723 | protocol=6 | dir=out | app=system |
"{DA0067A8-85C2-4FBA-B9B6-274B9A0797E9}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\vdsldr.exe |
"{DA1489AF-EDA1-4761-AB79-0649217E41E2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DCA91C41-EB6D-4A1D-89C1-E35A871FD8C9}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{DFAF9D2F-3970-45F1-84B5-3DDC8183740B}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\services.exe |
"{E9FE6EB1-0C12-4117-9D7B-DDCD4BC1A8CD}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{EADD0F08-9580-49DB-AAB2-74F38C744507}" = rport=3702 | protocol=17 | dir=out | svc=bits | app=c:\windows\system32\svchost.exe |
"{ECC28BE8-28C0-4A9F-901A-76D424AD0CE8}" = lport=80 | protocol=6 | dir=in | app=system |
"{ED623114-5A4F-46E1-8108-3D8301E33C74}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{F15FFCC5-DF2E-4CFF-8566-A74171C79C86}" = lport=443 | protocol=6 | dir=in | name=oovoo tcp port 443 |
"{F5F0BF04-A97E-42F4-BD42-FE0E41C09775}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\p2phost.exe |
"{F7B74DBC-7576-41A3-9F97-DFA71055E76B}" = rport=139 | protocol=6 | dir=out | app=system |
"{F7E871C4-9BC3-4D2B-9196-41CB3B85903B}" = lport=rpc | protocol=6 | dir=in | svc=vds | app=c:\windows\system32\vds.exe |
"{F94EC883-9E89-4424-BB2A-0CF1EDFFCD7E}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{F9EF5668-E5ED-46E1-8E4A-83BF44E4F4DA}" = lport=rpc | protocol=6 | dir=in | svc=ktmrm | app=c:\windows\system32\svchost.exe |
"{FE7B6E20-B913-4D46-BD61-FF31A883979D}" = rport=2869 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0086CFE2-A80B-4FD6-8E1A-5078361E33AC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0385FDDC-57D0-44D7-B0E4-88C208E4C081}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{046CCD29-F822-496C-82D6-B023EF23ADA7}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{0CAFCE15-16E8-4EC8-BF6B-A1F83A620BFA}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{103A0452-52D5-4681-95F5-78A6DCB74478}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{12E00FFD-3646-462D-A3F9-71AFCAFBD196}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{14FABEE5-A404-4A6F-A1A6-14E0959B9184}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{1988BCC0-A824-47F8-950F-37C513143FAE}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{1D9D8ACB-16F9-42D8-A75C-5B3CB2DA0E1C}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{213FC70F-7FD3-46A2-993D-6B257C71F69E}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{2BD29C4B-D4C9-494E-9CB1-CEA8418E0B84}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{2C826650-FA53-430F-9D63-D83BA24AF343}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2CC223CC-F9A1-486A-91BB-818E2F06408C}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{31662F1F-C177-4F9B-AAF7-0895DF71CD87}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{342B9CEF-A6CD-4CFB-8920-654B14D1DF2A}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{3B22458A-BF94-4267-8968-05F88F256831}" = protocol=17 | dir=in | app=c:\program files\kill3rcombo\elsword\data\x2.exe |
"{3BAAA5FD-CEE0-49AF-83D4-E13B548FDE1E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{40819FE3-93AA-476E-984B-EDB7A113A310}" = protocol=6 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{486AC7C5-D263-44BE-A61F-6BA6693B9288}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{49B7EECD-9747-412A-9270-2C63200937AE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{500B4613-6AA5-4C98-8C89-562F2D347A15}" = protocol=6 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{50637EC8-B46C-4DA0-A706-75CF5C8F8B8D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{53717A99-EEB2-4B0C-BAA1-FB8F4B386EC0}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{562305DC-7C9C-44B7-B05D-15A2F5A4DB70}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{576393AC-E293-44AB-8C1B-33D6A48ADFEF}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{58F4FB11-7A4F-46F5-BAA0-0A0A989D4CB4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{5B07F41D-7C18-4926-9F62-91DA21648E9D}" = protocol=6 | dir=in | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{5B95FC6D-0A8B-4546-8F83-698BB3E4F8E3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{5D6207F5-484D-4269-BFAC-31543C1614F4}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5DED0B33-A8B9-4EDC-8BA4-94E7DE8DF72B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{5F1838D1-E0D7-4C0B-A5CC-9E790EB7861F}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{5FF0ED00-BFD2-4D3B-8370-ED04BD9D8C02}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{604230BF-67E3-45B1-85B6-3D3E5826E0DE}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{609C7472-0D25-4007-90ED-8C3D2EB6233D}" = dir=in | app=c:\windows\system32\mspatcha32.exe |
"{615C5117-E7E0-432E-84E3-9CD5F9269091}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{626BA43A-9A81-4172-BECF-090871821805}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
"{63EC3A9E-8610-45D0-9465-8A2E14073885}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{6A4E9429-0F91-4D69-8E70-D286DEE1AE54}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{6AA809A9-EA88-4DCF-B866-4CFE77B0D1D8}" = protocol=6 | dir=in | app=c:\windows\system32\msdtc.exe |
"{6C5DF96D-FF90-4538-850F-CD555DC3A362}" = protocol=6 | dir=in | app=c:\program files\kill3rcombo\elsword\data\x2.exe |
"{6F56E693-F039-4A67-9BBD-AB55A1A3CB95}" = protocol=6 | dir=in | svc=msiscsi | app=c:\windows\system32\svchost.exe |
"{728420E9-AF39-4C1C-A4CC-8D7000E02CFD}" = protocol=17 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{7769B0DF-82D4-464E-8BDD-003643430614}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{7879066D-D7C9-4024-9036-10774C9471F4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{79F54E8B-AF44-4981-8EB2-9EBCFC71DE22}" = protocol=6 | dir=out | app=system |
"{7CA0BB6C-A24A-45DA-990B-E7452DFFE545}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{7FAC9E5E-0A9C-4E03-BC09-3C248491D22C}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{88C37B6C-795B-42C8-96BD-CE2AF15476D0}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{8BAE783F-327D-466C-B00C-3812731FF4A4}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{8CEC9233-4D46-4E58-83A1-9F030FEDB5A8}" = protocol=6 | dir=out | app=c:\windows\system32\p2phost.exe |
"{8E10E36D-345B-434B-9934-A695CE9A6D30}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{8E2245F7-A17B-40E9-A2CB-6DCB154F8962}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{9128A6A5-9148-4310-9D94-2A1569D23C6E}" = protocol=6 | dir=in | app=c:\windows\system32\wbem\unsecapp.exe |
"{92C277D3-5B6D-44A6-A125-41EBF944A7E3}" = protocol=6 | dir=out | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{9CBA9492-C733-4B26-9B68-34FB2BF28AD2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{9D77AB4F-F7A9-4B81-9DD8-4DFD94B65698}" = protocol=6 | dir=in | app=c:\windows\system32\plasrv.exe |
"{9DBBAB43-1DCC-4339-A379-2BDF6E7344FF}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{A89569FC-3535-42B6-8D78-BC26FEDF1EB2}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{AB12BE70-9013-4157-8786-EBD103BFC841}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B0D6644D-6454-403A-96E6-EAFBCAB119D0}" = protocol=6 | dir=in | app=c:\windows\system32\p2phost.exe |
"{B14F8E43-BC3D-44D9-B466-F531D10FFACA}" = protocol=6 | dir=out | app=c:\program files\windows collaboration\wincollab.exe |
"{B4FFD915-5982-46CC-AFFE-DA9CEB0220C0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B5F147F4-6435-4058-9706-04337E4DF79C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{B8705072-DCD1-4ADC-9C40-976A01CD4D72}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{BA4BD2A1-C2CD-4C35-87E2-EFEEB39E7218}" = protocol=17 | dir=in | app=c:\program files\windows collaboration\wincollab.exe |
"{BD1FE5A2-FBB9-4A29-B831-B79D4FACC1DC}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{C344AFFF-DD0D-4B03-942B-FCB506AB858B}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{C399EBC5-6ADB-4740-940A-2C3DD60D1CA9}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{C70351E9-A743-4B0A-B086-2587A00EF2B7}" = protocol=6 | dir=out | app=c:\windows\system32\msdtc.exe |
"{C9C5374D-67D0-455C-8EEE-DC36E3E3816A}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{D0CBAF08-F2EB-40C7-85EC-93828EF2E213}" = dir=in | app=c:\windows\system32\mspatcha32.exe |
"{D10B3EEE-81C6-4541-A644-6C39F861DCA6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{D72F7E9A-13FC-4C3E-96EB-9E42EE171F5C}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{DA3468DF-6D89-4D89-A3C1-F04B20064CF7}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{DB2F4B36-FC03-4FBC-ACC5-DEF2A197E8ED}" = protocol=6 | dir=out | app=system |
"{DBC9CF4E-4917-43FF-8280-8E342592A270}" = protocol=6 | dir=out | svc=msiscsi | app=c:\windows\system32\svchost.exe |
"{DC04144C-C3CD-4B06-A99D-F3B4BE3A9E6A}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{DC831E6C-B936-45E4-BB13-BF7E4DE7A597}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{E13B09FE-9FB8-4CE1-8C1A-3C221FAE5577}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{E1EA6EF0-421F-4FEB-B4AA-FF6E7D0596D3}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E5176FE6-0A1E-40C7-88DB-91E84D1BA675}" = protocol=17 | dir=out | app=c:\program files\windows collaboration\wincollab.exe |
"{E8D508CF-E4A8-41A0-9B4E-50ED3F06077D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{EA1CACE4-A179-4402-98B0-762E8E83A423}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{F0A96DB2-8071-44F2-97F8-D16694C9B791}" = protocol=6 | dir=in | app=c:\program files\windows collaboration\wincollab.exe |
"{F18AB301-086F-4A93-B15E-FE358B37820A}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{F52D2C57-E987-4CDB-B624-2E8B5ED93B5A}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{F6B72DA3-5893-4B25-B311-137F853FA1DF}" = protocol=17 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{FE339B7E-2E73-40C8-8B58-4D4C614DA0FF}" = dir=in | app=c:\windows\system32\mspatcha32.exe |
"TCP Query User{37764860-422E-4A6E-AF11-B060BFA468FA}C:\program files\kaiba corp vds\kcvds.exe" = protocol=6 | dir=in | app=c:\program files\kaiba corp vds\kcvds.exe |
"TCP Query User{4D3CBA7D-7B96-458D-95E7-DB5215CA3496}C:\ntreev usa\grand chase\main.exe" = protocol=6 | dir=in | app=c:\ntreev usa\grand chase\main.exe |
"TCP Query User{4F7D76BE-1920-41A2-A1FB-985DBB7D6083}C:\program files\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files\oovoo\oovoo.exe |
"TCP Query User{64FC23B9-4A1C-4F1C-BE95-18486BA3316F}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{CB28B2AD-A364-474E-B0F2-19ACE0EEE867}C:\program files\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files\oovoo\oovoo.exe |
"TCP Query User{CFA27859-2C24-4103-8223-5B54172036CF}C:\game\softnyxgame\gunboundis\nyxlauncher.exe" = protocol=6 | dir=in | app=c:\game\softnyxgame\gunboundis\nyxlauncher.exe |
"TCP Query User{FB1D733C-6EB5-4F48-8ECE-054E9CEC1D11}C:\game\softnyxgame\gunboundis\gunbound.gme" = protocol=6 | dir=in | app=c:\game\softnyxgame\gunboundis\gunbound.gme |
"TCP Query User{FF863AAE-CE6A-4851-9719-34F9F5A226C3}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{03EC07F5-49EF-431E-9829-BFDB5C91128D}C:\program files\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files\oovoo\oovoo.exe |
"UDP Query User{0CF673B3-6AA8-4DA9-A750-AE464DB2DC26}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{1D4E2DDC-E83F-40B0-A205-5C3F07C9EF73}C:\program files\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files\oovoo\oovoo.exe |
"UDP Query User{3489BE07-2240-400E-8BAC-C75095D0E699}C:\game\softnyxgame\gunboundis\nyxlauncher.exe" = protocol=17 | dir=in | app=c:\game\softnyxgame\gunboundis\nyxlauncher.exe |
"UDP Query User{3AEA6C69-7B47-4A8A-B095-C0C98ACFA4AF}C:\program files\kaiba corp vds\kcvds.exe" = protocol=17 | dir=in | app=c:\program files\kaiba corp vds\kcvds.exe |
"UDP Query User{6DF0C774-E35C-4017-9F30-D05C9977FF4E}C:\ntreev usa\grand chase\main.exe" = protocol=17 | dir=in | app=c:\ntreev usa\grand chase\main.exe |
"UDP Query User{6E8BB2D6-F89A-484F-B768-AAD63891BBFD}C:\game\softnyxgame\gunboundis\gunbound.gme" = protocol=17 | dir=in | app=c:\game\softnyxgame\gunboundis\gunbound.gme |
"UDP Query User{99770BC5-1384-4930-A90A-9F4D82786A62}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00405945-70C1-4B1D-9A3C-45A2883366AF}" = PS_AIO_05_C4600_Software_Min
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 22
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{353FE16B-30FE-469A-BF55-B978F4218003}" = iTunes
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{44C81D1A-0520-49BB-B510-98B8DD414EA1}" = HP Photosmart C4600 All-In-One Driver Software 13.0 Rel .5
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{63AFACBC-4795-4A1B-8037-5085DC03FC54}" = Microsoft LifeCam
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{6EFDBA50-4ABE-4194-86F7-F3BD0A011F5B}_is1" = Shop To Win
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7CDD7C4C-5224-40E4-951F-51C12FEAB8AB}" = C4600
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C7EEF2B9-8C16-4A04-B98D-B1A952A47E55}" = Linksys Wireless-G USB Network Adapter
"{C89C8D86-4423-4A58-AA40-DD259ACE07C1}" = KhalSetup
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{E655DDFC-24DB-4FC3-8474-271E911309B4}_is1" = Elsword version 1.04
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_6" = AIM 6
"ERUNT_is1" = ERUNT 1.1j
"Foxit Reader" = Foxit Reader
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.0.0 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MapleStory" = MapleStory
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Shop for HP Supplies" = Shop for HP Supplies
"Veetle TV" = Veetle TV 0.9.16
"ViewpointMediaPlayer" = Viewpoint Media Player
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/10/2010 5:41:51 PM | Computer Name = user-PC | Source = Application Hang | ID = 1002
Description = The program MapleStory.exe version 1.0.0.1 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1508 Start Time: 01cb38c586042b09 Termination Time: 405

Error - 8/11/2010 9:20:17 PM | Computer Name = user-PC | Source = Application Hang | ID = 1002
Description = The program MapleStory.exe version 1.0.0.1 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1694 Start Time: 01cb39bbf429b057 Termination Time: 73

Error - 8/12/2010 3:36:28 AM | Computer Name = user-PC | Source = Google Update | ID = 20
Description =

Error - 8/12/2010 3:39:39 AM | Computer Name = user-PC | Source = Google Update | ID = 20
Description =

Error - 8/12/2010 4:36:28 AM | Computer Name = user-PC | Source = Google Update | ID = 20
Description =

Error - 8/12/2010 4:39:39 AM | Computer Name = user-PC | Source = Google Update | ID = 20
Description =

Error - 8/12/2010 5:36:27 AM | Computer Name = user-PC | Source = Google Update | ID = 20
Description =

Error - 8/12/2010 5:39:39 AM | Computer Name = user-PC | Source = Google Update | ID = 20
Description =

Error - 8/12/2010 6:36:27 AM | Computer Name = user-PC | Source = Google Update | ID = 20
Description =

Error - 8/12/2010 6:39:39 AM | Computer Name = user-PC | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 6/19/2011 12:52:13 AM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 6/19/2011 12:52:15 AM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 6/19/2011 12:56:53 AM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 6/19/2011 12:56:56 AM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 6/20/2011 3:23:54 AM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 6/20/2011 3:23:56 AM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 6/20/2011 3:28:12 AM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 6/20/2011 3:28:15 AM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 6/20/2011 6:25:50 PM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 6/20/2011 6:25:53 PM | Computer Name = user-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.


< End of report >
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 11-06-19.0r1 - client 06/20/2011 19:02:58.6.2 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.2.1033.18.2035.776 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\AudioSes32.dll c:\programdata\iertutil32.exe c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{ad11e981-6c6d-45f2-9eee-2ee95120b2fc} c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{ad11e981-6c6d-45f2-9eee-2ee95120b2fc}\chrome.manifest c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{ad11e981-6c6d-45f2-9eee-2ee95120b2fc}\chrome\xulcache.jar c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{ad11e981-6c6d-45f2-9eee-2ee95120b2fc}\defaults\preferences\xulcache.js c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{ad11e981-6c6d-45f2-9eee-2ee95120b2fc}\install.rdf . . ((((((((((((((((((((((((( Files Created from 2011-05-20 to 2011-06-20 ))))))))))))))))))))))))))))))) . . 2011-06-20 23:08 . 2011-06-20 23:11 ——– d—–w- c:\users\client\AppData\Local\temp 2011-06-20 23:08 . 2011-06-20 23:08 ——– d—–w- c:\users\user\AppData\Local\temp 2011-06-20 23:08 . 2011-06-20 23:08 ——– d—–w- c:\users\Public\AppData\Local\temp 2011-06-20 23:08 . 2011-06-20 23:08 ——– d—–w- c:\users\Guest\AppData\Local\temp 2011-06-20 23:08 . 2011-06-20 23:08 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-12 21:20 . 2011-06-12 21:20 ——– d—–w- c:\program files\Kill3rCombo 2011-06-08 22:09 . 2011-06-08 22:09 ——– d—–w- c:\program files\Shop to Win 18 2011-06-08 22:09 . 2011-06-08 22:09 ——– d—–w- c:\program files\Shop To Win 2011-05-30 15:20 . 2011-05-30 15:19 779776 —-a-w- c:\windows\system32\mspatcha32.exe 2011-05-30 15:20 . 2011-05-30 15:20 356864 —-a-w- c:\windows\system32\AudioSes32.dll 2011-05-29 01:07 . 2011-06-20 04:00 ——– d—–w- c:\users\client\AppData\Roaming\go 2011-05-29 01:07 . 2011-06-20 04:30 ——– d—–w- c:\programdata\Easybits GO 2011-05-26 02:19 . 2011-05-26 02:19 ——– d—–w- c:\programdata\Nexon 2011-05-23 19:14 . 2011-05-29 01:07 ——– d—–w- c:\programdata\Skype Extras . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-06 20:20 . 2011-04-06 20:20 91424 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 20:20 . 2011-04-06 20:20 75040 —-a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 20:20 . 2011-04-06 20:20 197920 —-a-w- c:\windows\system32\dnssdX.dll 2011-04-06 20:20 . 2011-04-06 20:20 107808 —-a-w- c:\windows\system32\dns-sd.exe 2011-04-29 19:35 . 2011-04-03 04:22 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{027B4116-75B9-4FA0-9BDB-773B1F914F07}] 2011-05-30 15:20 356864 —-a-w- c:\windows\System32\AudioSes32.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CA2F8E90-0E43-46AD-89C0-7634A233ED00}] 2010-12-29 18:20 14432 —-a-w- c:\program files\Shop to Win 18\Shop to Win 18.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-10-11 1232896] "WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 2159104] "Aim6"="c:\program files\AIM6\aim6.exe" [2009-07-09 49968] "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-11-20 2590456] "ooVoo.exe"="c:\program files\ooVoo\oovoo.exe" [2011-05-18 22631608] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-05-27 15147400] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912] "VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2009-10-24 597792] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-12-09 74752] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160] . c:\users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0bootdelete . R2 gupdate1ca77a318b0b950;Google Update Service (gupdate1ca77a318b0b950);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 133104] R3 apf001;apf001;c:\game\SoftnyxGame\GunBoundIS\apf001.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 133104] R3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2010-06-03 15944] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-10-29 3407292] R3 XDva281;XDva281;c:\windows\system32\XDva281.sys [x] R3 XDva300;XDva300;c:\windows\system32\XDva300.sys [x] R3 XDva380;XDva380;c:\windows\system32\XDva380.sys [x] R3 XDva385;XDva385;c:\windows\system32\XDva385.sys [x] S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224] S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652] S2 wscsvc32;Security Center ;c:\windows\system32\mspatcha32.exe [2011-05-30 779776] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-06-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 01:09] . 2011-06-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 01:09] . 2011-06-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001Core.job - c:\users\client\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-28 22:36] . 2011-06-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001UA.job - c:\users\client\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-28 22:36] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = ;*.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://urlseek40.vmn.net/search.php?lg=en&type=dns&tbn=oovoo2_0dn&q= FF - user.js: yahoo.homepage.dontask - true . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file) BHO-{E5764080-1A10-F38C-39E8-861EAFE0CDFA} - c:\programdata\AudioSes32.dll WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file) HKCU-Run-OM2_Monitor - c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe HKLM-Run-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe . . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ———————— Other Running Processes ———————— . c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Microsoft LifeCam\MSCamS32.exe c:\programdata\iertutil32.exe c:\windows\system32\WUDFHost.exe c:\windows\system32\conime.exe c:\windows\system32\igfxsrvc.exe c:\program files\OpenOffice.org 3\program\soffice.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\OpenOffice.org 3\program\soffice.bin c:\program files\iPod\bin\iPodService.exe c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe c:\program files\HP\Digital Imaging\bin\hpqbam08.exe c:\program files\AIM6\aolsoftware.exe c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE . ************************************************************************** . Completion time: 2011-06-20 19:15:45 - machine was rebooted ComboFix-quarantined-files.txt 2011-06-20 23:15 . Pre-Run: 135,637,975,040 bytes free Post-Run: 139,678,588,928 bytes free . - - End Of File - - 22D8496AE0FE3B24004A1F589FA9B984
Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.










  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 6907 Windows 6.0.6000 Internet Explorer 7.0.6000.17037 6/21/2011 2:16:04 AM mbam-log-2011-06-21 (02-16-04).txt Scan type: Quick scan Objects scanned: 178043 Time elapsed: 3 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 9 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FE4C2C37-EDC8-4C00-B864-3C38CF3BA834} (Adware.Adshot) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{027B4116-75B9-4FA0-9BDB-773B1F914F07} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{027B4116-75B9-4FA0-9BDB-773B1F914F07} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{027B4116-75B9-4FA0-9BDB-773B1F914F07} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\7bde84a2-f58f-46ec-9eac-f1f90fead080 (Malware.Trace) -> Value: 7bde84a2-f58f-46ec-9eac-f1f90fead080 -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Windows\System32\config\systemprofile\AppData\Roaming\020000007a57a9991270c.manifest (Malware.Trace) -> Quarantined and deleted successfully. c:\Windows\System32\config\systemprofile\AppData\Roaming\020000007a57a9991270o.manifest (Malware.Trace) -> Quarantined and deleted successfully. c:\Windows\System32\config\systemprofile\AppData\Roaming\020000007a57a9991270p.manifest (Malware.Trace) -> Quarantined and deleted successfully. c:\Windows\System32\config\systemprofile\AppData\Roaming\020000007a57a9991270s.manifest (Malware.Trace) -> Quarantined and deleted successfully. c:\Windows\System32\020000007a57a9991270c.manifest (Malware.Trace) -> Quarantined and deleted successfully. c:\Windows\System32\020000007a57a9991270o.manifest (Malware.Trace) -> Quarantined and deleted successfully. c:\Windows\System32\020000007a57a9991270p.manifest (Malware.Trace) -> Quarantined and deleted successfully. c:\Windows\System32\020000007a57a9991270s.manifest (Malware.Trace) -> Quarantined and deleted successfully. c:\Windows\System32\audioses32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
and when I downloaded the ESET online scanner and I scanned it, it didn't say anything about a details tab and when I clicked finish, no log popped up :(
OTL logfile created on: 6/21/2011 12:50:43 PM - Run 2
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\client\Desktop
Windows Vista Home Basic Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.86 Gb Available Physical Memory | 43.49% Memory free
4.19 Gb Paging File | 2.43 Gb Available in Paging File | 58.02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 128.86 Gb Free Space | 55.33% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: client | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\client\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
PRC - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AIM6\aim6.exe (AOL LLC)
PRC - C:\Program Files\AIM6\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\Windows\vVX3000.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\client\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (wscsvc32) – File not found
SRV - (NMIndexingService) – File not found
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (PMBDeviceInfoProvider) – C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (hitmanpro35) – C:\Windows\System32\drivers\hitmanpro35.sys ()
DRV - (RMCAST) RMCAST (Pgm) – C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (BVRPMPR5) – C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (VX3000) – C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation)
DRV - (PRISM_A02) – C:\Windows\System32\drivers\WUSB20XP.sys (Cisco-Linksys, LLC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 16 41 7B 02 B9 75 A0 4F 9B DB 77 3B 1F 91 4F 07 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:3.2.5.2
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0.14908
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:[removed]
FF - prefs.js..keyword.URL: "http://urlseek40.vmn.net/search.php?lg=en&type=dns&tbn=oovoo2_0dn&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/07 17:03:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/29 15:35:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/03 00:22:29 | 000,000,000 | —D | M]

[2009/09/20 15:22:49 | 000,000,000 | —D | M] (No name found) – C:\Users\client\AppData\Roaming\mozilla\Extensions
[2009/09/20 15:22:49 | 000,000,000 | —D | M] (No name found) – C:\Users\client\AppData\Roaming\mozilla\Extensions\[removed]
[2011/06/20 19:07:57 | 000,000,000 | —D | M] (No name found) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions
[2009/10/12 21:17:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/16 11:19:07 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/04/03 00:23:38 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/06/08 18:09:14 | 000,000,000 | —D | M] (ShopToWin18) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\{fb320179-bf62-4606-9d75-5e82785ed1bf}
[2011/04/03 00:23:44 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\client\AppData\Roaming\mozilla\Firefox\Profiles\kl6gjpcx.default\extensions\[removed]
[2011/04/03 00:22:32 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/03 15:52:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/16 22:07:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/01 00:59:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/02 23:59:41 | 000,000,000 | —D | M] (The Browser Highlighter) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\USERS\CLIENT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KL6GJPCX.DEFAULT\EXTENSIONS\{6E764C17-863A-450F-BDD0-6772BD5AAA18}.XPI
[2011/04/29 15:35:34 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/09/15 05:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/03 23:55:44 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2010/12/09 06:47:06 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/06/20 19:11:21 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O2 - BHO: (Shop to Win 18) - {CA2F8E90-0E43-46AD-89C0-7634A233ED00} - C:\Program Files\Shop to Win 18\Shop to Win 18.dll (Shop To Win, LLC)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [Aim6] C:\Program Files\AIM6\aim6.exe (AOL LLC)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\client\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\client\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (bootdelete) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\Windows\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/06/21 02:18:22 | 000,000,000 | —D | C] – C:\Users\client\AppData\Local\AOL
[2011/06/21 02:16:45 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/06/20 19:15:48 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/06/20 19:15:48 | 000,000,000 | —D | C] – C:\Users\client\AppData\Local\temp
[2011/06/20 19:11:24 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2011/06/20 19:00:20 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/06/20 19:00:20 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/06/20 19:00:20 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2011/06/20 19:00:20 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/06/20 19:00:09 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/20 18:20:08 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Users\client\Desktop\OTL.exe
[2011/06/12 17:24:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elsword
[2011/06/12 17:20:09 | 000,000,000 | —D | C] – C:\Program Files\Kill3rCombo
[2011/06/08 18:09:13 | 000,000,000 | —D | C] – C:\Users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 18
[2011/06/08 18:09:09 | 000,000,000 | —D | C] – C:\Program Files\Shop to Win 18
[2011/06/08 18:09:08 | 000,000,000 | —D | C] – C:\Program Files\Shop To Win
[2011/05/28 21:07:41 | 000,000,000 | —D | C] – C:\Users\client\AppData\Roaming\go
[2011/05/28 21:07:37 | 000,000,000 | —D | C] – C:\ProgramData\Easybits GO
[2011/05/25 22:19:56 | 000,000,000 | —D | C] – C:\ProgramData\Nexon
[2011/05/23 15:14:28 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[1 C:\Users\client\Desktop\*.tmp files -> C:\Users\client\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/21 12:39:34 | 000,000,144 | —- | M] () – C:\ProgramData\10e58f40
[2011/06/21 12:30:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/21 12:27:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001UA.job
[2011/06/21 12:19:54 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/21 12:19:54 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/21 03:29:26 | 000,230,424 | —- | M] () – C:\img2-001.raw
[2011/06/21 02:25:33 | 000,622,906 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/06/21 02:25:33 | 000,108,122 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/06/21 02:20:44 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/21 02:19:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/21 02:19:46 | 2134,736,896 | -HS- | M] () – C:\hiberfil.sys
[2011/06/20 19:19:08 | 000,000,086 | —- | M] () – C:\Windows\System32\986423088
[2011/06/20 19:11:21 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/06/20 19:00:59 | 000,000,808 | —- | M] () – C:\Users\client\Desktop\ComboFix - Shortcut.lnk
[2011/06/20 18:33:59 | 000,091,414 | —- | M] () – C:\Users\client\Desktop\asfasfasfasfassa.png
[2011/06/20 18:27:13 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001Core.job
[2011/06/20 18:20:13 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\client\Desktop\OTL.exe
[2011/06/20 18:17:16 | 001,309,375 | —- | M] () – C:\Users\client\Desktop\tdsskiller.zip
[2011/06/19 23:48:59 | 000,003,499 | —- | M] () – C:\Users\client\Desktop\sss.jpg
[2011/06/19 13:48:04 | 000,010,273 | —- | M] () – C:\Users\client\Desktop\asfas.jpg
[2011/06/19 12:17:55 | 000,043,008 | —- | M] () – C:\Users\client\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/18 18:52:40 | 015,326,334 | —- | M] () – C:\Users\client\Desktop\lmao.wmv
[2011/06/18 17:16:39 | 000,063,962 | —- | M] () – C:\Users\client\Desktop\Untitled.jpg
[2011/06/14 18:23:13 | 000,002,047 | —- | M] () – C:\Users\client\Desktop\Google Chrome.lnk
[2011/06/14 18:23:13 | 000,002,009 | —- | M] () – C:\Users\client\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/06/12 17:24:09 | 000,000,936 | —- | M] () – C:\Users\Public\Desktop\Elsword.lnk
[2011/06/08 18:09:03 | 000,001,726 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[2011/05/29 09:11:30 | 000,039,984 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[1 C:\Users\client\Desktop\*.tmp files -> C:\Users\client\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/20 19:00:59 | 000,000,808 | —- | C] () – C:\Users\client\Desktop\ComboFix - Shortcut.lnk
[2011/06/20 19:00:20 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/06/20 19:00:20 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/06/20 19:00:20 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/06/20 19:00:20 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/06/20 19:00:20 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/06/20 18:33:57 | 000,091,414 | —- | C] () – C:\Users\client\Desktop\asfasfasfasfassa.png
[2011/06/20 18:16:45 | 001,309,375 | —- | C] () – C:\Users\client\Desktop\tdsskiller.zip
[2011/06/19 23:48:58 | 000,003,499 | —- | C] () – C:\Users\client\Desktop\sss.jpg
[2011/06/19 13:48:04 | 000,010,273 | —- | C] () – C:\Users\client\Desktop\asfas.jpg
[2011/06/18 18:51:40 | 015,326,334 | —- | C] () – C:\Users\client\Desktop\lmao.wmv
[2011/06/18 17:16:39 | 000,063,962 | —- | C] () – C:\Users\client\Desktop\Untitled.jpg
[2011/06/12 17:24:09 | 000,000,936 | —- | C] () – C:\Users\Public\Desktop\Elsword.lnk
[2011/05/31 19:30:45 | 000,000,144 | —- | C] () – C:\ProgramData\10e58f40
[2011/05/30 11:20:02 | 000,000,086 | —- | C] () – C:\Windows\System32\986423088
[2011/05/28 21:07:42 | 000,001,585 | —- | C] () – C:\Users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play games (EasyBits GO).lnk
[2011/04/30 16:49:13 | 000,000,007 | -HS- | C] () – C:\Users\client\AppData\Roaming\date
[2011/04/30 16:49:13 | 000,000,002 | -HS- | C] () – C:\Users\client\AppData\Roaming\evf6
[2011/01/21 17:20:26 | 000,000,034 | -H– | C] () – C:\Windows\System32\Converter_sysquict.dat
[2011/01/21 17:20:15 | 000,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/01/21 17:20:14 | 000,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/01/21 17:20:14 | 000,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/01/21 17:20:13 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2011/01/21 17:20:13 | 000,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/05/29 15:44:47 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat
[2010/05/27 21:48:59 | 000,000,004 | —- | C] () – C:\Users\client\AppData\Roaming\czyiwa.dat
[2010/05/27 19:52:44 | 000,085,504 | RHS- | C] () – C:\Windows\System32\msdtw.dll
[2010/05/23 16:17:31 | 000,000,000 | —- | C] () – C:\Users\client\AppData\Local\prvlcl.dat
[2010/04/12 20:52:17 | 000,015,944 | —- | C] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2010/04/12 19:54:11 | 000,000,168 | –S- | C] () – C:\Users\client\AppData\Local\3498221558.dat
[2010/04/12 19:53:15 | 000,010,920 | -HS- | C] () – C:\Users\client\AppData\Local\4T227ly4
[2010/04/12 19:53:15 | 000,010,920 | -HS- | C] () – C:\ProgramData\4T227ly4
[2010/01/07 16:59:13 | 000,163,685 | —- | C] () – C:\Windows\hpoins36.dat.temp
[2010/01/07 16:59:13 | 000,000,652 | —- | C] () – C:\Windows\hpomdl36.dat.temp
[2010/01/07 16:48:23 | 000,062,333 | —- | C] () – C:\Windows\hpqins01.dat
[2010/01/03 23:42:48 | 000,163,747 | —- | C] () – C:\Windows\hpoins36.dat
[2010/01/03 23:42:48 | 000,000,652 | —- | C] () – C:\Windows\hpomdl36.dat
[2009/10/09 20:51:57 | 000,024,064 | —- | C] () – C:\Users\client\AppData\Roaming\UserTile.png
[2009/09/11 22:14:45 | 000,000,552 | —- | C] () – C:\Users\client\AppData\Local\d3d8caps.dat
[2009/09/11 19:06:29 | 000,040,960 | —- | C] () – C:\Windows\System32\IsUser11b.dll
[2009/09/10 02:05:04 | 000,043,008 | —- | C] () – C:\Users\client\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/08 14:22:29 | 000,001,356 | —- | C] () – C:\Users\client\AppData\Local\d3d9caps.dat
[2009/09/07 13:16:16 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/02/11 19:55:18 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1437.dll
[2008/02/11 19:34:48 | 002,215,364 | —- | C] () – C:\Windows\System32\igklg400.bin
[2008/02/11 19:34:48 | 001,971,732 | —- | C] () – C:\Windows\System32\igklg450.bin
[2008/02/11 19:34:48 | 000,029,932 | —- | C] () – C:\Windows\System32\igmedcompkrn.bin
[2007/04/10 17:46:48 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini
[2006/11/02 08:53:49 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:44:53 | 000,283,664 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 06:33:01 | 000,622,906 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,108,122 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:35:16 | 000,006,672 | —- | C] () – C:\Users\client\AppData\Local\ar-SAq.dat
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/11/02 03:22:43 | 000,099,999 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2006/11/02 03:22:43 | 000,018,271 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[1999/01/22 14:46:58 | 000,065,536 | —- | C] () – C:\Windows\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2009/09/11 19:51:44 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\acccore
[2009/09/16 19:34:48 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\Blitware
[2010/01/03 23:56:43 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\Foxit
[2010/02/07 23:44:22 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\Foxit Software
[2009/11/01 18:36:31 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\GetRightToGo
[2011/06/21 00:08:22 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\go
[2010/07/03 20:12:38 | 000,000,000 | -H-D | M] – C:\Users\client\AppData\Roaming\ijjigame
[2010/06/01 22:03:34 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\LimeWire
[2011/04/22 01:34:59 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\LolClient
[2010/03/01 16:35:11 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\ooVoo Details
[2010/06/08 15:05:27 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\oovooinstaller
[2010/09/13 20:44:45 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\OpenOffice.org
[2009/10/09 20:51:57 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\PeerNetworking
[2010/10/05 06:45:39 | 000,000,000 | —D | M] – C:\Users\client\AppData\Roaming\VOWSoft
[2011/06/21 02:18:47 | 000,032,526 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2006/11/02 05:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2009/09/07 16:31:13 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2011/06/20 19:15:46 | 000,010,430 | —- | M] () – C:\ComboFix.txt
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/06/21 02:19:46 | 2134,736,896 | -HS- | M] () – C:\hiberfil.sys
[2010/07/03 20:06:05 | 000,002,578 | —- | M] () – C:\ijjiFFPlugin.log
[2011/06/21 03:29:26 | 000,230,424 | —- | M] () – C:\img2-001.raw
[2009/09/15 17:17:18 | 000,921,624 | —- | M] () – C:\img2-003.raw
[2009/09/11 19:51:34 | 000,000,347 | -H– | M] () – C:\IPH.PH
[2010/06/13 23:39:45 | 000,741,721 | —- | M] () – C:\ituneslib.itl
[2010/07/30 22:13:18 | 000,129,814 | —- | M] () – C:\Maple0000.jpg
[2010/05/29 20:53:01 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/05/29 20:53:01 | 000,005,120 | -H– | M] () – C:\ntuser.dat.LOG1
[2010/05/29 20:53:00 | 000,000,000 | -H– | M] () – C:\ntuser.dat.LOG2
[2010/05/29 20:53:00 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{f117c357-6b74-11df-ada0-000f66723b95}.TM.blf
[2010/05/29 20:53:00 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{f117c357-6b74-11df-ada0-000f66723b95}.TMContainer00000000000000000001.regtrans-ms
[2010/05/29 20:53:00 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{f117c357-6b74-11df-ada0-000f66723b95}.TMContainer00000000000000000002.regtrans-ms
[2010/05/29 20:53:00 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{f117c363-6b74-11df-ada0-000f66723b95}.TM.blf
[2010/05/29 20:53:00 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{f117c363-6b74-11df-ada0-000f66723b95}.TMContainer00000000000000000001.regtrans-ms
[2010/05/29 20:53:00 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{f117c363-6b74-11df-ada0-000f66723b95}.TMContainer00000000000000000002.regtrans-ms
[2011/06/21 02:19:44 | 2448,662,528 | -HS- | M] () – C:\pagefile.sys
[2010/06/01 19:04:01 | 000,000,726 | —- | M] () – C:\rkill.log
[2011/06/20 18:20:11 | 000,057,370 | —- | M] () – C:\TDSSKiller.2.5.5.0_20.06.2011_18.17.50_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 08:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 08:35:34 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/10/06 16:37:30 | 000,315,392 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpfpp083.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/09/10 02:16:36 | 000,001,666 | -H– | M] () – C:\Users\client\AppData\Roaming\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2009/10/11 04:47:08 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 06:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/21 19:18:01 | 000,000,286 | -HS- | M] () – C:\Users\client\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/06/20 18:20:13 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\client\Desktop\OTL.exe
[1 C:\Users\client\Desktop\*.tmp files -> C:\Users\client\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2007/04/10 17:46:48 | 000,013,023 | —- | M] () – C:\Windows\VX3000.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/10/16 17:36:14 | 000,004,072 | —- | M] () – C:\Users\client\Favorites\=].jpg
[2009/09/08 14:22:41 | 000,000,402 | -HS- | M] () – C:\Users\client\Favorites\desktop.ini
[2010/10/12 20:55:41 | 004,472,941 | —- | M] () – C:\Users\client\Favorites\Girl Im Sure You Want More.mp3
[2010/11/27 11:16:58 | 000,001,854 | —- | M] () – C:\Users\client\Favorites\Safari.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2011/06/21 12:39:34 | 000,000,144 | —- | M] () – C:\ProgramData\10e58f40
[2010/04/12 20:43:37 | 000,010,920 | -HS- | M] () – C:\ProgramData\4T227ly4
[2010/01/07 17:04:27 | 000,002,755 | —- | M] () – C:\ProgramData\hpzinstall.log

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-17 07:02:32

< End of report >
My computer has been starting up a little faster now and it doesn't take forever for mozilla to load anymore. It's an improvement! And whenever I go search up something, sometimes it totally just sends me to a site that has nothing to do with what I searched up. Is there something wrong with my computer or do I have a virus?
  • Please download Rootkit Unhooker and save it to your desktop.
    Link 1

  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"








Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
RkU Version: 3.8.389.593, Type LE (SR2) ============================================== OS Name: Windows Vista Version 6.0.6000 Number of processors #2 ============================================== >Drivers ============================================== 0x8B545000 C:\Windows\system32\DRIVERS\igdkmd32.sys 7057408 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver) 0x82000000 C:\Windows\system32\ntkrnlpa.exe 3805184 bytes (Microsoft Corporation, NT Kernel & System) 0x82000000 PnpManager 3805184 bytes 0x82000000 RAW 3805184 bytes 0x82000000 WMIxWDM 3805184 bytes 0x92A00000 Win32k 2097152 bytes 0x92A00000 C:\Windows\System32\win32k.sys 2097152 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0x92E22000 C:\Windows\system32\DRIVERS\VX3000.sys 1957888 bytes (Microsoft Corporation, Microsoft LifeCam VX3000 Device Driver) 0x81EBF000 C:\Windows\System32\Drivers\Ntfs.sys 1081344 bytes (Microsoft Corporation, NT File System Driver) 0x8064B000 C:\Windows\system32\drivers\ndis.sys 1064960 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver) 0x8051F000 C:\Windows\system32\CI.dll 921600 bytes (Microsoft Corporation, Code Integrity Module) 0xAF0E2000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0x8C12B000 C:\Windows\System32\drivers\tcpip.sys 872448 bytes (Microsoft Corporation, TCP/IP Driver) 0x8B4A8000 C:\Windows\System32\drivers\dxgkrnl.sys 643072 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0xA5032000 C:\Windows\system32\drivers\spsys.sys 581632 bytes (Microsoft Corporation, security processor) 0x804A4000 C:\Windows\system32\drivers\Wdf01000.sys 503808 bytes (Microsoft Corporation, WDF Dynamic) 0x81E55000 C:\Windows\System32\Drivers\ksecdd.sys 434176 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xA6797000 C:\Windows\system32\drivers\HTTP.sys 430080 bytes (Microsoft Corporation, HTTP Protocol Stack) 0x80266000 C:\Windows\system32\mcupdate_GenuineIntel.dll 393216 bytes (Microsoft Corporation, Intel Microcode Update Library) 0x8C498000 C:\Windows\system32\DRIVERS\WUSB20XP.sys 339968 bytes (Cisco-Linksys, LLC., PRISM Wireless NDIS 5.1 Driver) 0xA6645000 C:\Windows\System32\DRIVERS\srv.sys 331776 bytes (Microsoft Corporation, Server driver) 0x807B6000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0x8C0E4000 C:\Windows\system32\drivers\afd.sys 290816 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x80461000 C:\Windows\system32\drivers\acpi.sys 274432 bytes (Microsoft Corporation, ACPI Driver for NT) 0x8BDC0000 C:\Windows\system32\DRIVERS\storport.sys 262144 bytes (Microsoft Corporation, Microsoft Storage Port Driver) 0x8BFC1000 C:\Windows\system32\drivers\HdAudio.sys 258048 bytes (Microsoft Corporation, High Definition Audio Function Driver) 0x8B46B000 C:\Windows\system32\DRIVERS\USBPORT.SYS 249856 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0x8021A000 C:\Windows\system32\CLFS.SYS 241664 bytes (Microsoft Corporation, Common Log File System Driver) 0x8C072000 C:\Windows\system32\DRIVERS\rdbss.sys 241664 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xA66CC000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0x81FC7000 C:\Windows\system32\drivers\NETIO.SYS 233472 bytes (Microsoft Corporation, Network I/O Subsystem) 0x81E1F000 C:\Windows\system32\drivers\volsnap.sys 221184 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0x823A1000 ACPI_HAL 212992 bytes 0x823A1000 C:\Windows\system32\hal.dll 212992 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0x8BC17000 C:\Windows\system32\DRIVERS\usbhub.sys 212992 bytes (Microsoft Corporation, Default Hub Driver for USB) 0x8BE05000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0x8075F000 C:\Windows\system32\drivers\fltmgr.sys 200704 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xA5002000 C:\Windows\system32\DRIVERS\RMCAST.sys 196608 bytes (Microsoft Corporation, Reliable Multicast Transport) 0x8BF94000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x8B40F000 C:\Windows\system32\DRIVERS\msiscsi.sys 176128 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver) 0x80620000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0xA6515000 C:\Windows\system32\DRIVERS\nwifi.sys 176128 bytes (Microsoft Corporation, NativeWiFi Miniport Driver) 0x8BD1B000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library) 0x8C44B000 C:\Windows\system32\DRIVERS\Dot4.sys 151552 bytes (Microsoft Corporation, IEEE-1284.4-1999 Driver) 0x8BF6F000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0x87BDB000 C:\Windows\System32\drivers\ecache.sys 151552 bytes (Microsoft Corporation, Special Memory Device Cache) 0x80434000 C:\Windows\system32\drivers\pci.sys 151552 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xA6696000 C:\Windows\System32\DRIVERS\srv2.sys 147456 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0x8BD7B000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x87BA9000 C:\Windows\system32\DRIVERS\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll) 0x8BEB2000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0xA6723000 C:\Windows\system32\drivers\mrxdav.sys 131072 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0x80790000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension) 0xA6705000 C:\Windows\system32\DRIVERS\mrxsmb.sys 122880 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xA33A4000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver) 0xA64E7000 C:\Windows\System32\DRIVERS\srvnet.sys 110592 bytes (Microsoft Corporation, Server Network driver) 0xA6400000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0x8BE60000 C:\Windows\System32\drivers\fwpkclnt.sys 102400 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0x8B448000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0x8C011000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Client MUP Surrogate Driver) 0x8BDA9000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0x8C5E9000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xAF7BB000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver) 0x8C0CE000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler) 0x8BE4B000 C:\Windows\system32\DRIVERS\tdx.sys 86016 bytes (Microsoft Corporation, TDI Translation Driver) 0xAA406000 C:\Windows\system32\DRIVERS\WUDFRd.sys 86016 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Reflector) 0xA6783000 C:\Windows\System32\drivers\mpsdrv.sys 81920 bytes (Microsoft Corporation, Microsoft Protection Service Driver) 0x8BE37000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver) 0x8BD68000 C:\Windows\system32\DRIVERS\raspptp.sys 77824 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xA6502000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0x8C0AD000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0x8AC01000 C:\Windows\system32\DRIVERS\HDAudBus.sys 73728 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0xA66BA000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 73728 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0x8C470000 C:\Windows\system32\drivers\usbaudio.sys 73728 bytes (Microsoft Corporation, USB Audio Class Driver) 0x8C439000 C:\Windows\system32\DRIVERS\USBSTOR.SYS 73728 bytes (Microsoft Corporation, USB Mass Storage Class Driver) 0xAF0D0000 C:\Windows\system32\DRIVERS\WUDFPf.sys 73728 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0x87BCA000 C:\Windows\system32\DRIVERS\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0x8074F000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver) 0x88584000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library) 0x88514000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0x80415000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager) 0x88554000 C:\Windows\System32\Drivers\NDProxy.SYS 65536 bytes (Microsoft Corporation, NDIS Proxy) 0x8894C000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver) 0x81E10000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0x80609000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver) 0x8891F000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0x88910000 C:\Windows\system32\DRIVERS\Rtlh86.sys 61440 bytes (Realtek Corporation, Realtek 8101/8168/8169 NDIS6 32-bit Driver) 0x8892E000 C:\Windows\system32\DRIVERS\termdd.sys 61440 bytes (Microsoft Corporation, Terminal Server Driver) 0x80425000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver) 0xA3E10000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver) 0x8B43A000 C:\Windows\system32\DRIVERS\intelppm.sys 57344 bytes (Microsoft Corporation, Processor Device Driver) 0x8C0C0000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0x8BE79000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0x80400000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0x8AC52000 C:\Windows\system32\DRIVERS\usbehci.sys 57344 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0x8BC4B000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0x8BC7F000 C:\Windows\system32\DRIVERS\dot4usb.sys 53248 bytes (Microsoft Corporation, DOT4USB filter driver) 0x8BC65000 C:\Windows\system32\DRIVERS\STREAM.SYS 53248 bytes (Microsoft Corporation, WDM CODEC Class Device Driver 2.0) 0x8BD5B000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0x8BC72000 C:\Windows\system32\DRIVERS\usbscan.sys 53248 bytes (Microsoft Corporation, USB Scanner Driver) 0x8AC13000 C:\Windows\System32\drivers\watchdog.sys 53248 bytes (Microsoft Corporation, Watchdog Driver) 0x8020D000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR) 0x8BED3000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0x88817000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes 0x8B460000 C:\Windows\system32\DRIVERS\fdc.sys 45056 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0x8BD50000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver) 0x8BD45000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver) 0x8BE87000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0x8BD9E000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0x8C55A000 C:\Windows\System32\drivers\tcpipreg.sys 45056 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0x8B404000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0x8880C000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x88801000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0x92D60000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0x8841A000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0x92DA6000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver) 0x8C028000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0x92DE2000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0x92D6A000 C:\Windows\system32\DRIVERS\usbprint.sys 40960 bytes (Microsoft Corporation, USB Printer driver) 0x8BEE8000 C:\Windows\system32\DRIVERS\asyncmac.sys 36864 bytes (Microsoft Corporation, MS Remote Access serial network driver) 0xCF192000 C:\Windows\System32\Drivers\BlackBox.SYS 36864 bytes (RKU Driver) 0x80600000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver) 0x8BF30000 C:\Windows\system32\DRIVERS\Dot4Prt.sys 36864 bytes (Microsoft Corporation, IEEE-1284.4 Print Class Driver) 0x87A80000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0x8BF39000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0x8BF42000 C:\Windows\system32\DRIVERS\kbdhid.sys 36864 bytes (Microsoft Corporation, HID Keyboard Filter Driver) 0x8025D000 C:\Windows\system32\PSHED.dll 36864 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver) 0x8AC32000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xA3E00000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0x8AC29000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x80204000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0x8AC3B000 C:\Windows\system32\drivers\ws2ifsl.sys 36864 bytes (Microsoft Corporation, Winsock2 IFS Layer) 0x807AE000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0x80255000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0x8AD68000 C:\Windows\System32\Drivers\dump_atapi.sys 32768 bytes 0x802C6000 C:\Windows\system32\kdcom.dll 32768 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0x8AD70000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0x80459000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0x8AD20000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x8AD28000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x80618000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor) 0x8885A000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0x88861000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0x8040E000 C:\Windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0x88853000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0x8ADD6000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0xA3258000 C:\Windows\system32\drivers\mbam.sys 16384 bytes (Malwarebytes Corporation, Malwarebytes' Anti-Malware) 0x888E4000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0x888E2000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) ============================================== >Stealth ==============================================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI