This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Win32/Hiloti.gen!D - Google redirects / other

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone. I've been having a really tough time getting rid of a nasty trojan virus. It was originally identified as "Trojan Win32/Hiloti.gen!D" via Microsoft Security Essentials, which I run as my full virus program.

The initial symptoms were:
  • The hiding all of my desktop icons and files on my two SSDs
  • Autorunning a fake virus scanning program that gives a bunch of errors and wants you to purchase a full version
  • Adding fake proxy servers to my browsers to prevent them from connecting.
  • Random web popups
  • Redirecting search and other web links to random pages

To make a long story short, I've already done the following:
  • Ran Trend Micro's Housecall
  • Did an msconfig and unchecked a couple things from the startup
  • Ran Malwarebytes
  • Ran ESET online scanner
  • Ran SuperAntiSpyware Proffessional
  • Ran Microsoft Malicious Software Removal Tool

Doing those things helped a little, but I still had a bunch of issues. So, I found a site about ComboFix and ran that (didn't see until after that I shouldn't do it until someone asks me too). I let it run and it fixed a majority of the issues. However, I'm still having quite a few problems:
  • Random web popups
  • Redirecting search and other web links to random pages
  • Chrome browser is completely disabled
  • Firefox crashes on load

After running ComboFix I re-ran several of the other spyware scanners and everything is coming back clean. So, I'm looking for some help to remove the rest of this stupid thing. Here is my ComboFix log:

==================================================================

ComboFix 11-07-02.03 - shingy 07/03/2011 15:43:20.1.4 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.4095.2957 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
c:\programdata\Tarma Installer
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\_Setup.dll
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\20101023125440.log
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\20110212115853.log
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\_Default.tiz
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\AxInterop.ImageEnXLibrary_1.9000.0.0_L_75236aeec3d51fd0_MSIL.tiz
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\CFToolkit_4.1.0.0_a87e673e9ecb6e8e_MSIL.tiz
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\DROPPED_20100101190241.tiz
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\DROPPED_20100101190244.tiz
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\DROPPED_20100101190312.tiz
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\FreeOCR_2.1.0.8_L_075a6c69191ec1db_x86.tiz
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\Interop.ImageLibrary_1.9000.0.0_L_8cdfa8b955dbb1c7_MSIL.tiz
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\Interop.PDFAX0717_7.17.0.0_L_3d5fa783dbb69c0f_MSIL.tiz
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Setup.dat
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Setup.exe
c:\programdata\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Setup.ico
c:\users\shingy\AppData\Roaming\Adobe\plugs
c:\users\shingy\AppData\Roaming\Adobe\shed
c:\users\shingy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Repair
.
.
((((((((((((((((((((((((( Files Created from 2011-06-03 to 2011-07-03 )))))))))))))))))))))))))))))))
.
.
2011-07-03 20:18 . 2011-07-03 20:18 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-07-03 18:33 . 2011-07-03 18:33 ——– d—–w- c:\users\shingy\AppData\Roaming\Malwarebytes
2011-07-03 18:33 . 2011-05-29 13:11 39984 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-03 18:33 . 2011-07-03 18:33 ——– d—–w- c:\programdata\Malwarebytes
2011-07-03 18:33 . 2011-07-03 18:33 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-03 18:33 . 2011-05-29 13:11 25912 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-07-03 18:11 . 2011-07-03 18:11 110080 —-a-r- c:\users\shingy\AppData\Roaming\Microsoft\Installer\{8AE3EC14-EAF8-4064-958A-C340C66EDD44}\IconF7A21AF7.exe
2011-07-03 18:11 . 2011-07-03 18:11 110080 —-a-r- c:\users\shingy\AppData\Roaming\Microsoft\Installer\{8AE3EC14-EAF8-4064-958A-C340C66EDD44}\IconD7F16134.exe
2011-07-03 18:11 . 2011-07-03 18:11 110080 —-a-r- c:\users\shingy\AppData\Roaming\Microsoft\Installer\{8AE3EC14-EAF8-4064-958A-C340C66EDD44}\Icon1226A4C5.exe
2011-07-03 18:11 . 2011-07-03 18:11 ——– d—–w- C:\sh4ldr
2011-07-03 18:11 . 2011-07-03 18:11 ——– d—–w- c:\program files\Enigma Software Group
2011-07-03 18:11 . 2011-07-03 18:11 ——– d—–w- c:\windows\8AE3EC14EAF84064958AC340C66EDD44.TMP
2011-07-03 18:11 . 2011-07-03 18:11 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard
2011-07-03 16:29 . 2011-07-03 16:29 ——– d—–w- c:\program files (x86)\ESET
2011-07-03 16:27 . 2011-07-03 16:27 ——– d—–w- C:\Combo-Fix
2011-07-03 16:03 . 2010-07-16 18:53 816016 —-a-w- c:\windows\system32\drivers\pctEFA64.sys
2011-07-03 16:03 . 2010-06-29 14:35 452872 —-a-w- c:\windows\system32\drivers\pctDS64.sys
2011-07-03 16:03 . 2011-03-10 13:08 279344 —-a-w- c:\windows\system32\drivers\PCTSD64.sys
2011-07-03 15:51 . 2011-05-12 12:59 140800 —-a-w- c:\windows\system32\drivers\pctwfpfilter64.sys
2011-07-03 15:51 . 2011-05-06 17:27 334976 —-a-w- c:\windows\system32\drivers\pctgntdi64.sys
2011-07-03 15:51 . 2011-05-11 13:55 282440 —-a-w- c:\windows\system32\drivers\PCTCore64.sys
2011-07-03 15:51 . 2011-05-06 17:28 92896 —-a-w- c:\windows\system32\drivers\pctplsg64.sys
2011-07-03 15:51 . 2011-07-03 19:29 ——– d—–w- c:\program files (x86)\Spyware Doctor
2011-07-03 15:51 . 2011-07-03 16:03 ——– d—–w- c:\programdata\PC Tools
2011-07-03 15:51 . 2011-07-03 16:03 ——– d—–w- c:\program files (x86)\Common Files\PC Tools
2011-07-03 15:51 . 2011-07-03 15:51 ——– d—–w- c:\users\shingy\AppData\Roaming\PC Tools
2011-07-03 15:49 . 2011-07-03 15:51 ——– d—–w- c:\users\shingy\AppData\Roaming\GetRightToGo
2011-07-03 15:03 . 2011-07-03 15:03 ——– d—–w- c:\users\shingy\AppData\Roaming\SUPERAntiSpyware.com
2011-07-03 15:03 . 2011-07-03 15:03 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2011-07-03 15:03 . 2011-07-03 15:03 ——– d—–w- c:\programdata\!SASCORE
2011-07-03 15:03 . 2011-07-03 15:03 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-07-03 05:51 . 2011-07-03 05:51 0 —ha-w- c:\users\shingy\AppData\Local\BITD829.tmp
2011-07-03 05:49 . 2011-07-03 05:49 129024 —-a-w- c:\windows\RegBootClean64.exe
2011-07-02 14:53 . 2011-06-07 17:10 8873296 —ha-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{39E81162-070E-4892-AFA4-BA50B8B43855}\mpengine.dll
2011-06-23 02:13 . 2011-06-23 02:13 ——– d–h–w- c:\users\shingy\AppData\Roaming\Advanced Font Viewer
2011-06-23 02:11 . 2011-06-23 02:11 ——– d–h–w- c:\users\shingy\AppData\Roaming\Free Font Renamer
2011-06-11 22:11 . 2011-06-11 22:11 ——– d–h–w- c:\users\shingy\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-06-07 21:57 . 2011-06-26 14:02 ——– d–h–w- c:\programdata\Skype Extras
2011-06-07 21:57 . 2011-06-07 21:57 ——– d–h–w- c:\program files (x86)\Common Files\Skype
2011-06-07 21:57 . 2011-06-07 21:57 ——– d–h–r- c:\program files (x86)\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-07 17:10 . 2010-10-12 10:43 8873296 —ha-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-22 20:18 . 2011-05-25 10:05 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-09 06:58 . 2011-05-24 11:21 142336 —-a-w- c:\windows\system32\poqexec.exe
2011-04-09 06:45 . 2011-05-11 18:36 5509504 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:13 . 2011-05-11 18:36 3957632 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-04-09 06:13 . 2011-05-11 18:36 3901824 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-04-09 05:56 . 2011-05-24 11:21 123904 —-a-w- c:\windows\SysWow64\poqexec.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —ha-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —ha-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —ha-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —ha-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="c:\applications\Internet\AIM\aim.exe" [2006-08-01 67112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\windows\system32\config\systemprofile\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592]
.
c:\users\shingy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\shingy\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Outlook.lnk - c:\program files\Microsoft Office\Office14\OUTLOOK.EXE [2010-3-23 24505696]
Mozilla Firefox.lnk - c:\applications\Internet\Firefox\firefox.exe [N/A]
Toodledo Sync Tool.lnk - c:\windows\Installer\{7D0C60CD-F5FF-4758-8A96-247D0DA74C52}\_ABFE74A9AD95D30FB3A626.exe [2010-10-30 894]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HideSCANetwork"= 1 (0x1)
"HideSCAVolume"= 1 (0x1)
"HideSCABattery"= 1 (0x1)
"TaskbarNoThumbnail"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-10 136176]
R3 Amazon Download Agent;Amazon Download Agent;c:\program files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2009-10-23 401920]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-10-11 1038088]
R3 FoxAwdWINFLASH64;FoxAwdWINFLASH64;c:\users\shingy\AppData\Local\Temp\_3BEB.tmp\FOXAWD~1.SYS [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-10 136176]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\Spyware Doctor\pctsAuxs.exe [2011-02-18 371472]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 magicJack;magicJack;c:\mjusbsp\srvany.exe [2003-04-18 8192]
R4 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi64.sys [x]
R4 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x]
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x]
S0 tdrpman251;Acronis Try&Decide and Restore Points filter (build 251);c:\windows\system32\DRIVERS\tdrpm251.sys [x]
S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2010-10-16 2326920]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-12-15 373640]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-05-31 15928]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [x]
S3 lvpepf64;Volume Adapter;c:\windows\system32\DRIVERS\lv302a64.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - PCTSDInjDriver64
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-10 23:32]
.
2011-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-10 23:32]
.
2011-06-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1333310377-3377235737-4070044975-1000Core.job
- c:\users\shingy\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-21 11:38]
.
2011-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1333310377-3377235737-4070044975-1000UA.job
- c:\users\shingy\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-21 11:38]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —ha-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —ha-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —ha-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —ha-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2010-05-31 57928]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\acaptuser64.dll
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:62606
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: Interfaces\{D0C175EF-44D5-4A7E-AF98-9E259E7A17A2}: NameServer = 192.168.1.1
FF - ProfilePath - c:\users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 62606
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKLM-Run-CD Autorun - c:\program files (x86)\TweakNow PowerPack 2010\CDAuto.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-07-03 16:42:50
ComboFix-quarantined-files.txt 2011-07-03 20:42
.
Pre-Run: 21,419,479,040 bytes free
Post-Run: 22,867,181,568 bytes free
.
- - End Of File - - 74AF48E8DB1F13A2B0D848087279E0FB

==================================================================

And, here is my HiJackThis log:

==================================================================

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:19:10 AM, on 7/4/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\Applications\Internet\AIM\aim.exe
C:\Users\shingy\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Applications\Internet\uTorrent\uTorrent.exe
C:\Users\shingy\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:62606
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKCU\..\Run: [AIM] C:\Applications\Internet\AIM\aim.exe -cnetwait.odl
O4 - HKUS\S-1-5-18\..\Run: [cdloader] "C:\Windows\system32\config\systemprofile\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [cdloader] "C:\Windows\system32\config\systemprofile\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK (User 'Default user')
O4 - Startup: Dropbox.lnk = C:\Users\shingy\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Microsoft Outlook.lnk = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
O4 - Global Startup: Mozilla Firefox.lnk = C:\Applications\Internet\Firefox\firefox.exe
O4 - Global Startup: Toodledo Sync Tool.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Applications\Internet\AIM\aim.exe
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C175EF-44D5-4A7E-AF98-9E259E7A17A2}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - (no file)
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Amazon Download Agent - Amazon.com - C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 10021 bytes

==================================================================

HELP!!

Thanks in advance.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post









COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:62606
    
    FireFox:::
    FF - ProfilePath - c:\users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 62606
    FF - prefs.js: network.proxy.type - 0
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.














  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply











  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Thank you for your help. I ran the three scans - here are the results, ComboFix: ================================== ComboFix 11-07-05.02 - shingy 07/05/2011 11:55:21.2.4 - x64 Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.4095.2432 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\shingy\Desktop\CFScript.txt AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2011-06-05 to 2011-07-05 ))))))))))))))))))))))))))))))) . . 2011-07-05 16:24 . 2011-07-05 16:24 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-07-05 11:27 . 2011-06-07 17:10 8873296 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5B690D69-9976-4C9C-A3D6-C1A89C34B7D3}\mpengine.dll 2011-07-04 03:21 . 2011-07-04 03:21 ——– d—–w- c:\users\shingy\AppData\Local\Adobe 2011-07-03 18:33 . 2011-07-03 18:33 ——– d—–w- c:\users\shingy\AppData\Roaming\Malwarebytes 2011-07-03 18:33 . 2011-07-03 18:33 ——– d—–w- c:\programdata\Malwarebytes 2011-07-03 18:11 . 2011-07-03 18:11 110080 —-a-r- c:\users\shingy\AppData\Roaming\Microsoft\Installer\{8AE3EC14-EAF8-4064-958A-C340C66EDD44}\IconF7A21AF7.exe 2011-07-03 18:11 . 2011-07-03 18:11 110080 —-a-r- c:\users\shingy\AppData\Roaming\Microsoft\Installer\{8AE3EC14-EAF8-4064-958A-C340C66EDD44}\IconD7F16134.exe 2011-07-03 18:11 . 2011-07-03 18:11 110080 —-a-r- c:\users\shingy\AppData\Roaming\Microsoft\Installer\{8AE3EC14-EAF8-4064-958A-C340C66EDD44}\Icon1226A4C5.exe 2011-07-03 18:11 . 2011-07-03 18:11 ——– d—–w- c:\program files\Enigma Software Group 2011-07-03 18:11 . 2011-07-03 18:11 ——– d—–w- c:\windows\8AE3EC14EAF84064958AC340C66EDD44.TMP 2011-07-03 18:11 . 2011-07-03 18:11 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2011-07-03 16:29 . 2011-07-03 16:29 ——– d—–w- c:\program files (x86)\ESET 2011-07-03 16:03 . 2010-07-16 18:53 816016 —-a-w- c:\windows\system32\drivers\pctEFA64.sys 2011-07-03 16:03 . 2010-06-29 14:35 452872 —-a-w- c:\windows\system32\drivers\pctDS64.sys 2011-07-03 16:03 . 2011-03-10 13:08 279344 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2011-07-03 15:51 . 2011-05-12 12:59 140800 —-a-w- c:\windows\system32\drivers\pctwfpfilter64.sys 2011-07-03 15:51 . 2011-05-06 17:27 334976 —-a-w- c:\windows\system32\drivers\pctgntdi64.sys 2011-07-03 15:51 . 2011-05-11 13:55 282440 —-a-w- c:\windows\system32\drivers\PCTCore64.sys 2011-07-03 15:51 . 2011-05-06 17:28 92896 —-a-w- c:\windows\system32\drivers\pctplsg64.sys 2011-07-03 15:51 . 2011-07-03 19:29 ——– d—–w- c:\program files (x86)\Spyware Doctor 2011-07-03 15:51 . 2011-07-03 16:03 ——– d—–w- c:\programdata\PC Tools 2011-07-03 15:51 . 2011-07-03 16:03 ——– d—–w- c:\program files (x86)\Common Files\PC Tools 2011-07-03 15:51 . 2011-07-03 15:51 ——– d—–w- c:\users\shingy\AppData\Roaming\PC Tools 2011-07-03 15:49 . 2011-07-03 15:51 ——– d—–w- c:\users\shingy\AppData\Roaming\GetRightToGo 2011-07-03 15:03 . 2011-07-03 15:03 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-07-03 15:03 . 2011-07-03 15:03 ——– d—–w- c:\programdata\!SASCORE 2011-07-03 05:51 . 2011-07-03 05:51 0 —-a-w- c:\users\shingy\AppData\Local\BITD829.tmp 2011-07-03 05:49 . 2011-07-03 05:49 129024 —-a-w- c:\windows\RegBootClean64.exe 2011-06-23 02:13 . 2011-06-23 02:13 ——– d—–w- c:\users\shingy\AppData\Roaming\Advanced Font Viewer 2011-06-23 02:11 . 2011-06-23 02:11 ——– d—–w- c:\users\shingy\AppData\Roaming\Free Font Renamer 2011-06-11 22:11 . 2011-06-11 22:11 ——– d—–w- c:\users\shingy\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2011-06-07 21:57 . 2011-06-26 14:02 ——– d—–w- c:\programdata\Skype Extras 2011-06-07 21:57 . 2011-06-07 21:57 ——– d—–w- c:\program files (x86)\Common Files\Skype 2011-06-07 21:57 . 2011-06-07 21:57 ——– d—–r- c:\program files (x86)\Skype . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-06-07 17:10 . 2010-10-12 10:43 8873296 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-04-22 20:18 . 2011-05-25 10:05 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-04-09 06:58 . 2011-05-24 11:21 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-04-09 06:45 . 2011-05-11 18:36 5509504 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-04-09 06:13 . 2011-05-11 18:36 3957632 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-04-09 06:13 . 2011-05-11 18:36 3901824 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-04-09 05:56 . 2011-05-24 11:21 123904 —-a-w- c:\windows\SysWow64\poqexec.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AIM"="c:\applications\Internet\AIM\aim.exe" [2006-08-01 67112] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "cdloader"="c:\windows\system32\config\systemprofile\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592] . c:\users\shingy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\shingy\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Microsoft Outlook.lnk - c:\program files\Microsoft Office\Office14\OUTLOOK.EXE [2010-3-23 24505696] Mozilla Firefox.lnk - c:\applications\Internet\Firefox\firefox.exe [N/A] Toodledo Sync Tool.lnk - c:\windows\Installer\{7D0C60CD-F5FF-4758-8A96-247D0DA74C52}\_ABFE74A9AD95D30FB3A626.exe [2010-10-30 894] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "HideSCANetwork"= 1 (0x1) "HideSCAVolume"= 1 (0x1) "HideSCABattery"= 1 (0x1) "TaskbarNoThumbnail"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-10 136176] R3 Amazon Download Agent;Amazon Download Agent;c:\program files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2009-10-23 401920] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-10-11 1038088] R3 FoxAwdWINFLASH64;FoxAwdWINFLASH64;c:\users\shingy\AppData\Local\Temp\_3BEB.tmp\FOXAWD~1.SYS [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-10 136176] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\Spyware Doctor\pctsAuxs.exe [2011-02-18 371472] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 magicJack;magicJack;c:\mjusbsp\srvany.exe [x] R4 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi64.sys [x] R4 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [x] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x] S0 tdrpman251;Acronis Try&Decide and Restore Points filter (build 251);c:\windows\system32\DRIVERS\tdrpm251.sys [x] S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [x] S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2010-10-16 2326920] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-12-15 373640] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-05-31 15928] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [x] S3 lvpepf64;Volume Adapter;c:\windows\system32\DRIVERS\lv302a64.sys [x] S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x] S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x] S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-07-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-10 23:32] . 2011-07-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-10 23:32] . 2011-06-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1333310377-3377235737-4070044975-1000Core.job - c:\users\shingy\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-21 11:38] . 2011-07-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1333310377-3377235737-4070044975-1000UA.job - c:\users\shingy\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-21 11:38] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\shingy\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2010-05-31 57928] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\acaptuser64.dll . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\system32\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105 LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll TCP: Interfaces\{D0C175EF-44D5-4A7E-AF98-9E259E7A17A2}: NameServer = 192.168.1.1 FF - ProfilePath - c:\users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) HKLM-Run-CD Autorun - c:\program files (x86)\TweakNow PowerPack 2010\CDAuto.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-07-05 12:44:27 ComboFix-quarantined-files.txt 2011-07-05 16:44 . Pre-Run: 22,428,483,584 bytes free Post-Run: 22,052,134,912 bytes free . - - End Of File - - 61C5697CB40DD90468F74B6731FD6E04
aswMBR: ===================================== aswMBR version 0.9.7.705 Copyright© 2011 AVAST Software Run date: 2011-07-05 19:21:46 —————————– 19:21:46.403 OS Version: Windows x64 6.1.7600 19:21:46.403 Number of processors: 4 586 0x1707 19:21:46.403 ComputerName: DESKTOP UserName: shingy 19:21:47.136 Initialize success 19:21:50.490 AVAST engine defs: 11070501 19:21:55.887 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-2 19:21:55.887 Disk 0 Vendor: OCZ-VERT 1.11 Size: 57241MB BusType: 3 19:21:55.887 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-3 19:21:55.887 Disk 1 Vendor: OCZ-VERT 1.6_ Size: 30533MB BusType: 3 19:21:55.887 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IAAStorageDevice-4 19:21:55.887 Disk 2 Vendor: WDC_WD25 01.0 Size: 238418MB BusType: 3 19:21:55.981 Disk 0 MBR read successfully 19:21:55.997 Disk 0 MBR scan 19:21:55.997 Disk 0 Windows 7 default MBR code found via API 19:21:55.997 Disk 0 unknown MBR code 19:21:55.997 Disk 0 MBR hidden 19:21:56.090 Service scanning 19:21:56.792 Disk 0 trace - called modules: 19:21:56.808 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa800630f254]<< 19:21:56.808 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80062f9060] 19:21:56.823 3 CLASSPNP.SYS[fffff8800188c43f] -> nt!IofCallDriver -> [0xfffffa800434fcf0] 19:21:56.823 \Driver\PCTCore[0xfffffa8003ee5470] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0xfffffa800630f254 19:21:57.385 AVAST engine scan C:\Windows 19:52:46.942 File: C:\Windows\System32\drivers\adfs.sys **SUSPICIOUS** 19:52:56.832 File: C:\Windows\System32\drivers\en-US\bfe.dll.mui **SUSPICIOUS** 19:53:00.935 File: C:\Windows\System32\drivers\en-US\ndiscap.sys.mui **SUSPICIOUS** 19:53:01.653 File: C:\Windows\System32\drivers\en-US\pacer.sys.mui **SUSPICIOUS** 19:53:02.651 File: C:\Windows\System32\drivers\en-US\qwavedrv.sys.mui **SUSPICIOUS** 19:53:03.462 File: C:\Windows\System32\drivers\en-US\scfilter.sys.mui **SUSPICIOUS** 19:53:04.320 File: C:\Windows\System32\drivers\en-US\tcpip.sys.mui **SUSPICIOUS** 19:53:58.062 File: C:\Windows\System32\drivers\wimmount.sys **SUSPICIOUS** 21:31:06.653 AVAST engine scan C:\Users\shingy 21:45:33.718 AVAST engine scan C:\ProgramData 21:53:50.859 Scan finished successfully 22:19:32.392 Disk 0 MBR has been saved successfully to "C:\Users\shingy\Desktop\MBR.dat" 22:19:32.392 The log file has been saved successfully to "C:\Users\shingy\Desktop\aswMBR.txt"
OTL:

======================================

OTL logfile created on: 7/5/2011 10:23:24 PM - Run 1
OTL by OldTimer - Version 3.2.26.0 Folder = C:\Users\shingy\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 39.54% Memory free
9.86 Gb Paging File | 7.49 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): e:\pagefile.sys 6000 6000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55.90 Gb Total Space | 20.28 Gb Free Space | 36.27% Space Free | Partition Type: NTFS
Drive D: | 232.79 Gb Total Space | 111.21 Gb Free Space | 47.77% Space Free | Partition Type: NTFS
Drive E: | 29.82 Gb Total Space | 10.56 Gb Free Space | 35.42% Space Free | Partition Type: NTFS
Drive H: | 122.22 Mb Total Space | 122.21 Mb Free Space | 100.00% Space Free | Partition Type: FAT

Computer Name: DESKTOP | User Name: shingy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\shingy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)


========== Modules (SafeList) ==========

MOD - C:\Users\shingy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (NisSrv) – C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (sdCoreService) – C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (afcdpsrv) – C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Amazon Download Agent) – C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe (Amazon.com)
SRV - (AcrSch2Svc) – C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (PCTCore) – C:\Windows\SysNative\drivers\PCTCore64.sys (PC Tools)
DRV:64bit: - (pctplsg) – C:\Windows\SysNative\drivers\pctplsg64.sys (PC Tools)
DRV:64bit: - (pctgntdi) – C:\Windows\SysNative\drivers\pctgntdi64.sys (PC Tools)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (PCTSD) – C:\Windows\SysNative\drivers\PCTSD64.sys (PC Tools)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (afcdp) – C:\Windows\SysNative\drivers\afcdp.sys (Acronis)
DRV:64bit: - (tdrpman251) Acronis Try&Decide; and Restore Points filter (build 251) – C:\Windows\SysNative\drivers\tdrpm251.sys (Acronis)
DRV:64bit: - (timounter) – C:\Windows\SysNative\drivers\timntr.sys (Acronis)
DRV:64bit: - (snapman) – C:\Windows\SysNative\drivers\snapman.sys (Acronis)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (pctDS) – C:\Windows\SysNative\drivers\pctDS64.sys (PC Tools)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.)
DRV:64bit: - (lvpepf64) – C:\Windows\SysNative\drivers\lv302a64.sys (Logitech Inc.)
DRV:64bit: - (KeyScrambler) – C:\Windows\SysNative\drivers\keyscrambler.sys (QFX Software Corporation)
DRV:64bit: - (HPFXBULK) – C:\Windows\SysNative\drivers\hpfx64bulk.sys (Hewlett Packard)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - (adfs) – C:\Windows\SysWow64\drivers\adfs.sys (Adobe Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 3E 90 39 36 39 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo"

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Applications\Internet\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll File not found
FF - HKLM\Software\MozillaPlugins\@worldwinner.com/Launcher2,version=1.9.0.23: C:\Program Files (x86)\WorldWinner.com, Inc\WorldWinner Games\npwwload.dll (WorldWinner.com, Inc.)
FF:64bit: - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\shingy\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF:64bit: - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\shingy\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\shingy\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\shingy\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/30 21:35:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKCU\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/30 21:35:50 | 000,000,000 | —D | M]
FF - HKCU\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/06/30 21:36:27 | 000,000,000 | —D | M] (No name found) – C:\Users\shingy\AppData\Roaming\Mozilla\Extensions
[2011/07/02 22:11:06 | 000,000,000 | —D | M] (No name found) – C:\Users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\extensions
[2011/06/30 22:14:47 | 000,000,000 | —D | M] (IE Tab 2 (FF 3.6+)) – C:\Users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
[2011/06/30 22:14:47 | 000,000,000 | —D | M] (FEBE) – C:\Users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2011/07/01 18:43:30 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\extensions\[removed]
[2011/06/30 21:35:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) –
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{04426594-BCE6-4705-B811-BCDBA2FD9C7B}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{0FA2149E-BB2C-4AC2-A8D3-479599819475}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{35106BCA-6C78-48C7-AC28-56DF30B51D2A}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{35106BCA-6C78-48C7-AC28-56DF30B51D2C}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{582195F5-92E7-40A0-A127-DB71295901D7}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{987311C6-B504-4AA2-90BF-60CC49808D42}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{A76CD07B-F0D7-4EF9-9566-8FAEF6E290E4}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{EDA7B1D7-F793-4E03-B074-E6F303317FB0}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{F645A8C9-E969-42D9-B3F3-F325537222FD}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
[2011/06/16 00:17:34 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/07/03 16:18:35 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (CKeyScramblerBHO Object) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (CKeyScramblerBHO Object) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [CD Autorun] File not found
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AIM] File not found
O4 - Startup: C:\Users\shingy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\shingy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCANetwork = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAVolume = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCABattery = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoThumbnail = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra 'Tools' menuitem : &KeyScrambler;… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra 'Tools' menuitem : &KeyScrambler;… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Applications\Internet\AIM\aim.exe (America Online, Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - Reg Error: Key error. File not found
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\acaptuser64.dll) - C:\Windows\SysNative\acaptuser64.dll (Adobe Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\Windows\SysWow64\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\SysWow64\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.VP60 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\SysWow64\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/07/05 18:23:13 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/07/05 12:45:08 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/07/05 11:45:34 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/07/05 11:45:34 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/07/05 11:44:27 | 000,000,000 | —D | C] – C:\ComboFix
[2011/07/05 11:42:19 | 000,000,000 | —D | C] – C:\Qoobox
[2011/07/05 11:34:02 | 004,132,182 | R— | C] (Swearware) – C:\Users\shingy\Desktop\ComboFix.exe
[2011/07/03 23:21:48 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Local\Adobe
[2011/07/03 15:36:11 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/07/03 14:33:49 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Malwarebytes
[2011/07/03 14:33:41 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/07/03 14:11:29 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
[2011/07/03 14:11:28 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2011/07/03 14:11:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2011/07/03 12:29:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/07/03 12:27:35 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/07/03 12:23:11 | 000,000,000 | R–D | C] – C:\Users\shingy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/07/03 12:03:32 | 000,816,016 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctEFA64.sys
[2011/07/03 12:03:32 | 000,452,872 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctDS64.sys
[2011/07/03 12:03:26 | 000,279,344 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTSD64.sys
[2011/07/03 12:03:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2011/07/03 11:51:42 | 000,334,976 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctgntdi64.sys
[2011/07/03 11:51:42 | 000,140,800 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctwfpfilter64.sys
[2011/07/03 11:51:38 | 000,282,440 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTCore64.sys
[2011/07/03 11:51:37 | 000,092,896 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctplsg64.sys
[2011/07/03 11:51:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spyware Doctor
[2011/07/03 11:51:33 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\PC Tools
[2011/07/03 11:51:33 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2011/07/03 11:51:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PC Tools
[2011/07/03 11:51:25 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2011/07/03 11:49:44 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\GetRightToGo
[2011/07/03 11:03:31 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/07/03 11:03:25 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2011/07/02 21:49:24 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\Weird_Al_Yankovic-Alpocalypse-2011-MTD
[2011/07/02 10:50:35 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\shingy\Desktop\HiJackThis.exe
[2011/07/02 02:59:34 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\shingy\Desktop\OTL.exe
[2011/07/02 02:59:20 | 001,925,512 | —- | C] (AVAST Software) – C:\Users\shingy\Desktop\aswMBR.exe
[2011/06/30 21:36:24 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Mozilla
[2011/06/30 21:35:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/06/29 22:07:31 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\Captivate Training
[2011/06/29 21:08:02 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\PDA lake pics
[2011/06/29 12:07:30 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drvinst.exe
[2011/06/29 12:07:30 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\devrtl.dll
[2011/06/29 12:07:28 | 002,326,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2011/06/29 12:07:28 | 002,228,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2011/06/29 12:07:28 | 001,401,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2011/06/29 12:07:27 | 001,553,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2011/06/29 12:07:26 | 000,779,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2011/06/29 12:07:26 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2011/06/29 12:07:26 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2011/06/29 12:07:26 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2011/06/29 12:07:26 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2011/06/29 12:07:26 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2011/06/29 12:07:25 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2011/06/29 12:07:25 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssphtb.dll
[2011/06/29 12:07:25 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2011/06/29 12:07:25 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2011/06/27 21:08:43 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\Recipes
[2011/06/22 22:13:29 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Advanced Font Viewer
[2011/06/22 22:11:15 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Free Font Renamer
[2011/06/19 13:55:34 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\Resume
[2011/06/18 18:01:44 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/06/18 18:01:44 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/06/18 18:01:43 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/06/18 18:01:43 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/18 18:01:43 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/06/18 18:01:43 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/18 18:01:42 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/18 18:01:42 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/18 18:01:42 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/06/18 18:01:42 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/06/18 18:01:41 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/06/18 18:01:41 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/06/18 18:01:41 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/06/18 18:01:41 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/06/18 18:01:29 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/06/18 18:01:28 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/06/18 18:01:24 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/11 18:11:16 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/07 17:57:56 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/06/07 17:57:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/06/07 17:57:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/06/07 17:57:46 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\shingy\AppData\Local\*.tmp files -> C:\Users\shingy\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/05 22:19:32 | 000,000,512 | —- | M] () – C:\Users\shingy\Desktop\MBR.dat
[2011/07/05 21:53:02 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/05 21:42:04 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1333310377-3377235737-4070044975-1000UA.job
[2011/07/05 18:30:18 | 000,013,664 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/05 18:30:18 | 000,013,664 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/05 18:28:30 | 000,747,550 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/07/05 18:28:30 | 000,637,934 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/07/05 18:28:30 | 000,112,408 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/07/05 18:23:12 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/05 18:23:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/05 11:34:05 | 004,132,182 | R— | M] (Swearware) – C:\Users\shingy\Desktop\ComboFix.exe
[2011/07/03 16:18:35 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/07/03 14:11:29 | 000,002,260 | —- | M] () – C:\Users\shingy\Desktop\SpyHunter.lnk
[2011/07/03 12:03:26 | 000,002,051 | —- | M] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2011/07/03 01:51:12 | 000,000,000 | —- | M] () – C:\Users\shingy\AppData\Local\{9F4BA5F5-273D-486F-94B2-CA5E529BA41C}
[2011/07/03 01:49:09 | 000,129,024 | —- | M] () – C:\Windows\RegBootClean64.exe
[2011/07/03 01:45:17 | 006,675,798 | —- | M] () – C:\Users\shingy\AppData\Local\census.cache
[2011/07/03 01:43:58 | 000,070,078 | —- | M] () – C:\Users\shingy\AppData\Local\ars.cache
[2011/07/03 00:33:46 | 000,002,736 | —- | M] () – C:\Users\shingy\AppData\Roaming\2582.DB9
[2011/07/02 23:59:44 | 000,000,232 | —- | M] () – C:\ProgramData\~39444216
[2011/07/02 23:59:44 | 000,000,176 | —- | M] () – C:\ProgramData\~39444216r
[2011/07/02 19:49:45 | 000,069,547 | —- | M] () – C:\Users\shingy\Desktop\Products_ Phones, Wireless Devices, Gift Cards, Accessories - Verizon Wireless.pdf
[2011/07/02 10:50:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\shingy\Desktop\HiJackThis.exe
[2011/07/02 02:59:44 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\shingy\Desktop\OTL.exe
[2011/07/02 02:59:36 | 001,925,512 | —- | M] (AVAST Software) – C:\Users\shingy\Desktop\aswMBR.exe
[2011/06/30 21:36:27 | 000,001,138 | —- | M] () – C:\Users\shingy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/06/30 21:05:15 | 016,853,784 | —- | M] () – C:\Users\shingy\Desktop\5b3e03h9.default.zip
[2011/06/30 07:18:44 | 005,049,816 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/29 22:42:45 | 000,002,368 | —- | M] () – C:\Users\shingy\Desktop\Google Chrome.lnk
[2011/06/29 19:13:34 | 000,002,194 | —- | M] () – C:\Users\shingy\Desktop\Google Earth.lnk
[2011/06/26 22:33:16 | 065,693,959 | —- | M] () – C:\Users\shingy\Desktop\Louis CK - 2005.12.29 Hoboken, NJ Bootleg (full recording).mp4
[2011/06/26 02:45:56 | 000,256,000 | —- | M] () – C:\Windows\PEV.exe
[2011/06/22 22:16:43 | 000,494,658 | —- | M] () – C:\Users\shingy\Desktop\KIEA_2011_report.pdf
[2011/06/22 21:49:43 | 001,818,056 | —- | M] () – C:\Users\shingy\Desktop\CougarLife BBB complaint.pdf
[2011/06/20 20:59:36 | 000,000,192 | —- | M] () – C:\Windows\winamp.ini
[2011/06/11 03:42:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1333310377-3377235737-4070044975-1000Core.job
[2011/06/07 20:43:34 | 000,471,261 | —- | M] () – C:\Users\shingy\Desktop\MJCCA • A Page from the Book Festival presents Ben Mezrich.pdf
[2011/06/07 17:57:50 | 000,002,533 | —- | M] () – C:\Users\shingy\Desktop\Skype.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\shingy\AppData\Local\*.tmp files -> C:\Users\shingy\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/05 19:20:43 | 000,000,512 | —- | C] () – C:\Users\shingy\Desktop\MBR.dat
[2011/07/05 11:45:35 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/07/05 11:45:34 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/07/05 11:45:34 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/07/05 11:45:34 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/07/05 11:45:34 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/07/03 15:57:47 | 000,002,665 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Toodledo Sync Tool.lnk
[2011/07/03 15:57:46 | 000,001,782 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk
[2011/07/03 15:57:45 | 000,001,105 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Outlook.lnk
[2011/07/03 15:55:52 | 000,000,827 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinISO.lnk
[2011/07/03 15:55:51 | 000,001,266 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Update.lnk
[2011/07/03 15:55:50 | 000,001,174 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photoshop CS4.lnk
[2011/07/03 15:55:49 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero.lnk
[2011/07/03 15:55:48 | 000,001,897 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/07/03 15:55:47 | 000,002,627 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft ICE.lnk
[2011/07/03 15:55:46 | 000,002,447 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes.lnk
[2011/07/03 15:55:44 | 000,001,554 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Illustrator CS4.lnk
[2011/07/03 15:55:43 | 000,002,304 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
[2011/07/03 15:55:42 | 000,001,135 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dreamweaver CS4.lnk
[2011/07/03 15:55:41 | 000,001,621 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CuteFTP.lnk
[2011/07/03 15:55:40 | 000,000,973 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CS5.lnk
[2011/07/03 15:55:39 | 000,000,997 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2011/07/03 15:55:38 | 000,001,179 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Captivate Reviewer 2.0.lnk
[2011/07/03 15:55:37 | 000,001,267 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Captivate Quiz Results Analyzer.lnk
[2011/07/03 15:55:35 | 000,000,999 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Captivate 5.lnk
[2011/07/03 15:55:34 | 000,001,265 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis True Image.lnk
[2011/07/03 14:11:29 | 000,002,260 | —- | C] () – C:\Users\shingy\Desktop\SpyHunter.lnk
[2011/07/03 12:03:26 | 000,002,051 | —- | C] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2011/07/03 11:51:42 | 000,007,357 | —- | C] () – C:\Windows\SysNative\drivers\pctgntdi64.cat
[2011/07/03 11:51:38 | 000,007,353 | —- | C] () – C:\Windows\SysNative\drivers\pctcore64.cat
[2011/07/03 11:51:37 | 000,007,353 | —- | C] () – C:\Windows\SysNative\drivers\pctplsg64.cat
[2011/07/03 01:51:12 | 000,000,000 | —- | C] () – C:\Users\shingy\AppData\Local\{9F4BA5F5-273D-486F-94B2-CA5E529BA41C}
[2011/07/03 01:49:00 | 000,129,024 | —- | C] () – C:\Windows\RegBootClean64.exe
[2011/07/03 01:45:17 | 006,675,798 | —- | C] () – C:\Users\shingy\AppData\Local\census.cache
[2011/07/03 01:43:58 | 000,070,078 | —- | C] () – C:\Users\shingy\AppData\Local\ars.cache
[2011/07/02 23:59:44 | 000,000,232 | —- | C] () – C:\ProgramData\~39444216
[2011/07/02 23:59:44 | 000,000,176 | —- | C] () – C:\ProgramData\~39444216r
[2011/07/02 23:45:59 | 000,002,736 | —- | C] () – C:\Users\shingy\AppData\Roaming\2582.DB9
[2011/07/02 19:49:45 | 000,069,547 | —- | C] () – C:\Users\shingy\Desktop\Products_ Phones, Wireless Devices, Gift Cards, Accessories - Verizon Wireless.pdf
[2011/06/30 21:36:16 | 000,001,138 | —- | C] () – C:\Users\shingy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/06/30 21:05:11 | 016,853,784 | —- | C] () – C:\Users\shingy\Desktop\5b3e03h9.default.zip
[2011/06/29 19:12:52 | 000,002,194 | —- | C] () – C:\Users\shingy\Desktop\Google Earth.lnk
[2011/06/26 22:06:48 | 065,693,959 | —- | C] () – C:\Users\shingy\Desktop\Louis CK - 2005.12.29 Hoboken, NJ Bootleg (full recording).mp4
[2011/06/21 18:50:39 | 001,818,056 | —- | C] () – C:\Users\shingy\Desktop\CougarLife BBB complaint.pdf
[2011/06/13 18:28:19 | 000,002,533 | —- | C] () – C:\Users\shingy\Desktop\Skype.lnk
[2011/06/07 20:43:34 | 000,471,261 | —- | C] () – C:\Users\shingy\Desktop\MJCCA • A Page from the Book Festival presents Ben Mezrich.pdf
[2011/05/14 11:11:26 | 000,083,968 | —- | C] () – C:\Windows\UnGins.exe
[2011/04/07 22:23:10 | 000,000,236 | —- | C] () – C:\Users\shingy\AppData\Roaming\Recorder.ini
[2011/02/13 13:34:00 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/02/01 20:58:03 | 000,000,036 | —- | C] () – C:\Windows\verypdf.ini
[2011/02/01 20:57:53 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\pwdremover.dat
[2010/12/31 13:21:20 | 000,003,584 | —- | C] () – C:\Users\shingy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/15 15:33:32 | 000,002,975 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2010/11/09 23:41:55 | 000,000,036 | —- | C] () – C:\Users\shingy\AppData\Local\housecall.guid.cache
[2010/11/06 10:30:20 | 000,219,868 | —- | C] () – C:\Windows\SysWow64\mlfcache.dat
[2010/10/23 12:55:11 | 000,962,560 | —- | C] () – C:\Windows\tesseract.exe
[2010/10/23 11:37:33 | 000,000,125 | —- | C] () – C:\Windows\BuzzTWCP.INI
[2010/10/23 11:37:33 | 000,000,101 | —- | C] () – C:\Windows\BUZZTWLC.INI
[2010/10/23 11:37:33 | 000,000,088 | —- | C] () – C:\Windows\BuzzTWSC.INI
[2010/10/16 22:32:42 | 000,134,078 | —- | C] () – C:\Windows\hppins06.dat.temp
[2010/10/16 22:32:42 | 000,001,247 | —- | C] () – C:\Windows\hppmdl06.dat.temp
[2010/10/16 22:31:39 | 000,000,094 | —- | C] () – C:\Users\shingy\AppData\Local\fusioncache.dat
[2010/10/16 22:24:09 | 000,000,120 | —- | C] () – C:\Windows\hpbvspst.ini
[2010/10/16 22:23:12 | 000,133,490 | —- | C] () – C:\Windows\hppins06.dat
[2010/10/16 22:23:12 | 000,001,247 | —- | C] () – C:\Windows\hppmdl06.dat
[2010/10/16 18:06:51 | 000,000,000 | —- | C] () – C:\Windows\HPMProp.INI
[2010/10/16 11:58:22 | 000,004,096 | —- | C] () – C:\Users\shingy\AppData\Local\keyfile3.drm
[2010/10/10 20:31:08 | 000,010,752 | —- | C] () – C:\Windows\SysWow64\BASSMOD.dll
[2010/10/10 19:25:38 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\pxhpinst.exe
[2010/10/10 19:25:37 | 000,000,192 | —- | C] () – C:\Windows\winamp.ini
[2010/10/10 19:24:48 | 000,168,448 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2010/10/10 19:24:47 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2010/10/10 19:24:47 | 002,255,360 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2010/10/10 19:24:47 | 000,795,648 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/10/10 19:24:47 | 000,130,048 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/10/10 19:24:46 | 000,067,584 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/10/10 14:55:26 | 000,007,606 | —- | C] () – C:\Users\shingy\AppData\Local\resmon.resmoncfg
[2010/10/10 13:29:14 | 000,000,442 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/10/10 11:40:34 | 000,760,544 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/10 10:01:35 | 000,000,056 | —- | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/10/10 09:59:58 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/10/10 09:33:26 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2010/10/16 16:58:37 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Acronis
[2011/06/22 22:13:30 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Advanced Font Viewer
[2010/10/10 18:46:31 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Aim
[2011/03/01 22:49:19 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Artisteer
[2011/06/11 18:11:16 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/05 18:23:24 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Dropbox
[2011/06/22 22:11:15 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Free Font Renamer
[2011/07/03 11:51:33 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\GetRightToGo
[2010/10/10 20:30:15 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\GlobalSCAPE
[2011/04/02 17:10:12 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\mjusbsp
[2011/01/29 18:58:07 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\MSNStockQuote
[2011/04/03 13:01:17 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\TaxCut
[2010/10/16 18:50:02 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\TweakNow PowerPack 2010
[2011/07/04 11:46:09 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\uTorrent
[2011/03/12 11:54:51 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Worldwinner
[2011/04/05 07:12:59 | 000,032,650 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/10/10 19:23:22 | 000,001,024 | —- | M] () – C:\.rnd
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/10/10 00:04:10 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/06/11 18:22:46 | 000,000,000 | —- | M] () – C:\CaptivateLog.log
[2011/07/05 12:44:43 | 000,019,231 | —- | M] () – C:\ComboFix.txt
[2010/10/10 18:44:51 | 000,000,360 | —- | M] () – C:\IPH.PH
[2011/02/01 20:58:10 | 000,000,049 | —- | M] () – C:\pdfinfo.ini

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/10/09 20:33:26 | 000,000,221 | -HS- | M] () – C:\Users\shingy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/07/02 02:59:36 | 001,925,512 | —- | M] (AVAST Software) – C:\Users\shingy\Desktop\aswMBR.exe
[2011/07/05 11:34:05 | 004,132,182 | R— | M] (Swearware) – C:\Users\shingy\Desktop\ComboFix.exe
[2011/07/02 10:50:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\shingy\Desktop\HiJackThis.exe
[2011/07/02 02:59:44 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\shingy\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | —- | M] () – C:\Windows\ADDINS\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/10/11 18:52:57 | 000,000,402 | -HS- | M] () – C:\Users\shingy\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2010/10/16 22:32:52 | 000,004,465 | —- | M] () – C:\ProgramData\hpzinstall.log
[2010/10/16 22:27:54 | 000,000,442 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2011/07/02 23:59:44 | 000,000,232 | —- | M] () – C:\ProgramData\~39444216
[2011/07/02 23:59:44 | 000,000,176 | —- | M] () – C:\ProgramData\~39444216r

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

=====================================

OTL Extras logfile created on: 7/5/2011 10:23:24 PM - Run 1
OTL by OldTimer - Version 3.2.26.0 Folder = C:\Users\shingy\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 39.54% Memory free
9.86 Gb Paging File | 7.49 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): e:\pagefile.sys 6000 6000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55.90 Gb Total Space | 20.28 Gb Free Space | 36.27% Space Free | Partition Type: NTFS
Drive D: | 232.79 Gb Total Space | 111.21 Gb Free Space | 47.77% Space Free | Partition Type: NTFS
Drive E: | 29.82 Gb Total Space | 10.56 Gb Free Space | 35.42% Space Free | Partition Type: NTFS
Drive H: | 122.22 Mb Total Space | 122.21 Mb Free Space | 100.00% Space Free | Partition Type: FAT

Computer Name: DESKTOP | User Name: shingy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %* File not found
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" && icacls "%1" /grant administrators:F (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Applications\Other\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Applications\Other\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Applications\Other\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" && icacls "%1" /grant administrators:F (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Applications\Other\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Applications\Other\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Applications\Other\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{108A39BF-4ED1-4293-B11A-06BD521FB8F7}" = FreeOCR 3.0
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{3CDE6FFC-99E4-4035-8B9A-2A7A77FBE11D}" = Google Apps Migration For Microsoft Outlook® [removed]
"{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
"{4ACA6F0A-97D9-4CD0-9F66-2CFB30A97E3C}" = Microsoft Image Composite Editor
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{73BA9A8F-6B40-BF79-541E-464156FBA764}" = ccc-utility64
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{8AE3EC14-EAF8-4064-958A-C340C66EDD44}" = SpyHunter
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-1000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{AC76BA86-1033-0000-0064-0003D0000004}" = Adobe Acrobat 9 Pro Extended 64-bit Add-On
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B361F88B-D513-9D45-E7F2-871B61C46D32}" = WMV9/VC-1 Video Playback
"{B6EFD9A5-2ECE-4C22-BAEC-D16E73EA2013}" = iTunes
"{C5970161-E13E-6661-BBDA-A08268313C83}" = ATI Catalyst Install Manager
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{E77543EE-6FB5-4FF6-AB70-635392C8C756}" = Microsoft Security Client
"{EE269999-1AB7-7B39-7944-513CF3426CB8}" = AMD Drag and Drop Transcoding
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FDD06F32-C9C8-429C-A7B0-915D8A5AD406}" = 64 Bit HP CIO Components Installer
"HP Color LaserJet CM1015_CM1017" = HP Color LaserJet CM1015/CM1017 MFP 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"MyDefrag v4.3.1_is1" = MyDefrag v4.3.1
"Office14.SingleImage" = Microsoft Office Professional 2010
"Speccy" = Speccy
"Unlocker" = Unlocker 1.9.0-x64

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{10964A8F-21C1-45EA-BC2D-F84B505C3848}" = H&R; Block Deluxe + Efile + State 2010
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{230B9098-A165-491F-B499-8F41AA7139F6}" = WorldWinner Games
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{281D28EC-1357-4778-B2D7-DEA56D70EF96}" = Logitech High Quality Video
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{33EFDAD7-1686-465A-AE0A-26F22E380315}" = Product_Min_QFolder
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39B975A6-93A3-4C71-9EAD-7BE9F9DF3D22}" = Product_Full_QFolder
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{41712893-452C-46E1-8530-584BBB790868}" = Google Apps Migration For Microsoft® Exchange 2.2.685.1005
"{477F4441-5BF5-4F1A-A4AA-358A66BAEB5A}" = hppFonts
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F0BC3F7-5583-48D1-8A08-ECD99EE14456}" = hpzTLBXFX
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57DA304D-27B0-40D1-A796-92CEFF20FA32}" = hppIOFiles
"{5BE17922-9A31-461F-9CEB-D053181A1E30}" = hppScanTo
"{5D112C61-C8D0-4718-8DD7-B9115EB9AF90}" = LogMeIn
"{5FD89EA1-99C2-40EE-BBF5-20F8991ED756}" = Catalyst Control Center - Branding
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{6331C6C0-3754-E910-7113-5013355C8E47}" = CCC Help English
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{66A36166-A0A0-4AD2-AF46-29548DFA0EBF}" = hppCLJCM1017
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{69B6B9E1-A5DF-3177-2B1D-3B672F29EF86}" = Adobe Captivate Quiz Results Analyzer
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7B4174E8-FE92-4269-808A-3B8D116D9538}" = Advanced Security for Outlook
"{7D0C60CD-F5FF-4758-8A96-247D0DA74C52}" = Toodledo Sync Application
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8432FFD1-6F4D-F9B8-D641-5932E60359A2}" = Adobe Captivate Reviewer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8E355243-1A34-4EE8-A743-C166E68CF5C0}" = Adobe Captivate 5
"{91F34319-08DE-457a-99C0-0BCDFAC145B9}" = CuteFTP 8 Professional
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95C3927C-C899-C5D8-0EA7-67895FC979B2}" = ccc-core-static
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A99C1048-A569-4B65-A3DD-3584B0A4AA69}" = Microsoft MSN MoneyCentral Stock Quotes Add-In for Excel
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AE751709-EA28-4148-96D5-A524BBB08F05}" = hppusgCM1017
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B0DE7025-6319-4FCD-8364-095B8774BC33}" = H&R; Block Georgia 2010
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C2F1F96A-057E-5819-B52E-FEA1D1D2933B}" = Acronis True Image Home
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C6EC2466-7463-4C90-97D6-5077A223F0FE}" = hppTLBXFXCM1017
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Premium
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D710ECA1-820E-4EAD-9640-B2E3AD9E95CB}" = hppscanCM1017
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{ED4B50B7-C06B-57FE-7985-AA83DDBEEEF5}" = Catalyst Control Center Graphics Previews Common
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F01A9563-2A27-6ABC-2E04-03B7873DF7E0}" = Catalyst Control Center InstallProxy
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F8815B8B-3404-4B58-9FF3-46642E331FD8}" = hppManualsCM1017
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Accent OFFICE Password Recovery" = Accent OFFICE Password Recovery 2.60
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
"AdobeCaptivateReviewer2.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Captivate Reviewer
"AIM Ad Hack_is1" = AIM Ad Hack
"Amazon Games & Software Downloader_is1" = Amazon Games & Software Downloader
"AOL Instant Messenger" = AOL Instant Messenger
"Artisteer 2" = Artisteer 2
"AutoHotkey" = AutoHotkey 1.0.97.01
"AutoMacroRecorder_is1" = Auto Macro Recorder V5.7 (Pro V5.2) Trial Version
"Business Functions_is1" = Business Functions
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"ESET Online Scanner" = ESET Online Scanner v3
"KeyScrambler" = KeyScrambler
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.7.0
"Mozilla Firefox 5.0 (x86 en-US)" = Mozilla Firefox 5.0 (x86 en-US)
"OpenAL" = OpenAL
"OpenRA" = OpenRA
"PDF Password Remover v2.2_is1" = PDF Password Remover v2.2
"QuizResultsAnalyzer.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Captivate Quiz Results Analyzer
"ReaJpeg 1.1" = ReaJpeg 1.1
"Spyware Doctor" = Spyware Doctor 8.0
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"UT2004" = Unreal Tournament 2004
"uTorrent" = µTorrent
"UZTool_is1" = UZTool 1.1.0
"vShare" = vShare Plugin
"Winamp" = Winamp (remove only)
"WinISO_is1" = WinISO 5.3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"magicJack" = magicJack

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/1/2011 8:55:33 AM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 4/2/2011 4:29:43 PM | Computer Name = Desktop | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_stisvc, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7b325 Exception code: 0xc0000005 Fault offset: 0x000000000004ca16
Faulting
process id: 0x8e4 Faulting application start time: 0x01cbf1529da97696 Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: f0c37e4c-5d67-11e0-bb96-0024e821f2d0

Error - 4/2/2011 8:11:06 PM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 4/3/2011 12:12:10 PM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 4/3/2011 2:34:34 PM | Computer Name = Desktop | Source = Bonjour Service | ID = 100
Description = 304: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/3/2011 2:34:34 PM | Computer Name = Desktop | Source = Bonjour Service | ID = 100
Description = 308: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/3/2011 2:34:34 PM | Computer Name = Desktop | Source = Bonjour Service | ID = 100
Description = 440: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/4/2011 8:07:35 AM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 4/5/2011 8:48:31 AM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 4/6/2011 7:59:53 AM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 7/5/2011 7:15:18 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/5/2011 7:15:18 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/5/2011 7:15:20 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/5/2011 7:15:20 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/5/2011 7:15:20 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/5/2011 11:41:49 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7034
Description = The hpqcxs08 service terminated unexpectedly. It has done this 1
time(s).

Error - 7/5/2011 11:41:49 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7034
Description = The HP CUE DeviceDiscovery Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 7/5/2011 12:07:39 PM | Computer Name = Desktop | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 7/5/2011 12:25:33 PM | Computer Name = Desktop | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 7/5/2011 6:40:54 PM | Computer Name = Desktop | Source = BROWSER | ID = 8032
Description =


< End of report >
Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)



After running this scan please tell me what problems remain with the computer.
Thank you again for your help. The symptoms I was exhibiting before don't seem to be there any more.
  • Random web popups
  • Redirecting search and other web links to random pages
  • Chrome browser is completely disabled
  • Firefox crashes on load

But, is there a way to confirm that everything is completely clean?

Here is my TDSSKiller log:

========================================


2011/07/06 07:34:40.0561 4696 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21
2011/07/06 07:34:40.0888 4696 ================================================================================
2011/07/06 07:34:40.0888 4696 SystemInfo:
2011/07/06 07:34:40.0888 4696
2011/07/06 07:34:40.0888 4696 OS Version: 6.1.7600 ServicePack: 0.0
2011/07/06 07:34:40.0888 4696 Product type: Workstation
2011/07/06 07:34:40.0888 4696 ComputerName: DESKTOP
2011/07/06 07:34:40.0888 4696 UserName: shingy
2011/07/06 07:34:40.0888 4696 Windows directory: C:\Windows
2011/07/06 07:34:40.0888 4696 System windows directory: C:\Windows
2011/07/06 07:34:40.0888 4696 Running under WOW64
2011/07/06 07:34:40.0888 4696 Processor architecture: Intel x64
2011/07/06 07:34:40.0888 4696 Number of processors: 4
2011/07/06 07:34:40.0888 4696 Page size: 0x1000
2011/07/06 07:34:40.0888 4696 Boot type: Normal boot
2011/07/06 07:34:40.0888 4696 ================================================================================
2011/07/06 07:34:41.0247 4696 Initialize success
2011/07/06 07:35:05.0848 2940 ================================================================================
2011/07/06 07:35:05.0848 2940 Scan started
2011/07/06 07:35:05.0848 2940 Mode: Manual;
2011/07/06 07:35:05.0848 2940 ================================================================================
2011/07/06 07:35:05.0958 2940 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/07/06 07:35:05.0973 2940 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
2011/07/06 07:35:05.0989 2940 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/07/06 07:35:06.0004 2940 adfs (2f0683fd2df1d92e891caca14b45a8c1) C:\Windows\system32\drivers\adfs.sys
2011/07/06 07:35:06.0036 2940 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/07/06 07:35:06.0051 2940 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2011/07/06 07:35:06.0067 2940 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2011/07/06 07:35:06.0098 2940 afcdp (3426a6eaa09077f3ab946fb9ceb85d8e) C:\Windows\system32\DRIVERS\afcdp.sys
2011/07/06 07:35:06.0129 2940 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
2011/07/06 07:35:06.0145 2940 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
2011/07/06 07:35:06.0160 2940 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
2011/07/06 07:35:06.0176 2940 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
2011/07/06 07:35:06.0192 2940 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2011/07/06 07:35:06.0316 2940 amdkmdag (df943a113060d3abfda4730ae4163d6f) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/07/06 07:35:06.0410 2940 amdkmdap (4003b34b4a83de29cd1c88eb6c869e58) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/07/06 07:35:06.0426 2940 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2011/07/06 07:35:06.0441 2940 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
2011/07/06 07:35:06.0457 2940 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/07/06 07:35:06.0472 2940 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
2011/07/06 07:35:06.0504 2940 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
2011/07/06 07:35:06.0535 2940 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2011/07/06 07:35:06.0550 2940 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2011/07/06 07:35:06.0566 2940 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/07/06 07:35:06.0582 2940 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
2011/07/06 07:35:06.0613 2940 AtiHDAudioService (4bf5bca6e2608cd8a00bc4a6673a9f47) C:\Windows\system32\drivers\AtihdW76.sys
2011/07/06 07:35:06.0644 2940 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2011/07/06 07:35:06.0660 2940 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2011/07/06 07:35:06.0691 2940 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2011/07/06 07:35:06.0706 2940 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/07/06 07:35:06.0738 2940 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
2011/07/06 07:35:06.0753 2940 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/07/06 07:35:06.0769 2940 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/07/06 07:35:06.0784 2940 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2011/07/06 07:35:06.0800 2940 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/07/06 07:35:06.0816 2940 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/07/06 07:35:06.0831 2940 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/07/06 07:35:06.0847 2940 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/07/06 07:35:06.0894 2940 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/07/06 07:35:06.0909 2940 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
2011/07/06 07:35:06.0925 2940 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2011/07/06 07:35:06.0940 2940 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2011/07/06 07:35:06.0972 2940 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/07/06 07:35:06.0987 2940 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
2011/07/06 07:35:07.0018 2940 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
2011/07/06 07:35:07.0034 2940 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2011/07/06 07:35:07.0050 2940 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/07/06 07:35:07.0065 2940 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/07/06 07:35:07.0096 2940 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
2011/07/06 07:35:07.0143 2940 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
2011/07/06 07:35:07.0159 2940 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2011/07/06 07:35:07.0174 2940 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2011/07/06 07:35:07.0206 2940 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2011/07/06 07:35:07.0221 2940 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
2011/07/06 07:35:07.0284 2940 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2011/07/06 07:35:07.0346 2940 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2011/07/06 07:35:07.0362 2940 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
2011/07/06 07:35:07.0393 2940 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2011/07/06 07:35:07.0408 2940 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2011/07/06 07:35:07.0424 2940 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2011/07/06 07:35:07.0455 2940 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2011/07/06 07:35:07.0471 2940 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2011/07/06 07:35:07.0486 2940 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/07/06 07:35:07.0518 2940 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
2011/07/06 07:35:07.0549 2940 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2011/07/06 07:35:07.0564 2940 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2011/07/06 07:35:07.0580 2940 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
2011/07/06 07:35:07.0596 2940 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/07/06 07:35:07.0611 2940 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/07/06 07:35:07.0642 2940 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2011/07/06 07:35:07.0658 2940 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
2011/07/06 07:35:07.0674 2940 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/07/06 07:35:07.0689 2940 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/07/06 07:35:07.0705 2940 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2011/07/06 07:35:07.0720 2940 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2011/07/06 07:35:07.0752 2940 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
2011/07/06 07:35:07.0783 2940 HPFXBULK (12fe6ea361178a8313f7fbe45c1c50ff) C:\Windows\system32\drivers\hpfx64bulk.sys
2011/07/06 07:35:07.0814 2940 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/07/06 07:35:07.0830 2940 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
2011/07/06 07:35:07.0861 2940 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
2011/07/06 07:35:07.0876 2940 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/07/06 07:35:07.0892 2940 iaStor (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
2011/07/06 07:35:07.0908 2940 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
2011/07/06 07:35:07.0939 2940 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2011/07/06 07:35:07.0970 2940 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
2011/07/06 07:35:07.0986 2940 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2011/07/06 07:35:08.0001 2940 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/07/06 07:35:08.0032 2940 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/07/06 07:35:08.0048 2940 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2011/07/06 07:35:08.0064 2940 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2011/07/06 07:35:08.0079 2940 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
2011/07/06 07:35:08.0095 2940 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/07/06 07:35:08.0110 2940 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/07/06 07:35:08.0126 2940 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/07/06 07:35:08.0142 2940 KeyScrambler (f6ff56d9ce08da7f37e018a33decc3fc) C:\Windows\system32\drivers\keyscrambler.sys
2011/07/06 07:35:08.0173 2940 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
2011/07/06 07:35:08.0188 2940 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
2011/07/06 07:35:08.0204 2940 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2011/07/06 07:35:08.0235 2940 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2011/07/06 07:35:08.0266 2940 LMIInfo (0317335b15ff3bda8e10197e3434cfc0) C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys
2011/07/06 07:35:08.0282 2940 lmimirr (413ecdcfad9a82804d3674c8d7eec24e) C:\Windows\system32\DRIVERS\lmimirr.sys
2011/07/06 07:35:08.0313 2940 LMIRfsDriver (c57d3faa50e6f395759ffb7c709bd944) C:\Windows\system32\drivers\LMIRfsDriver.sys
2011/07/06 07:35:08.0344 2940 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/07/06 07:35:08.0360 2940 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/07/06 07:35:08.0376 2940 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/07/06 07:35:08.0391 2940 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/07/06 07:35:08.0407 2940 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2011/07/06 07:35:08.0422 2940 lvpepf64 (4a503882318bb2f59218d401614e6af6) C:\Windows\system32\DRIVERS\lv302a64.sys
2011/07/06 07:35:08.0438 2940 LVRS64 (125ae13c293889001b8456cf3eb04a40) C:\Windows\system32\DRIVERS\lvrs64.sys
2011/07/06 07:35:08.0454 2940 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2011/07/06 07:35:08.0485 2940 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/07/06 07:35:08.0500 2940 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2011/07/06 07:35:08.0516 2940 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2011/07/06 07:35:08.0532 2940 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
2011/07/06 07:35:08.0547 2940 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2011/07/06 07:35:08.0563 2940 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
2011/07/06 07:35:08.0594 2940 MpFilter (e6ba8e5a4a871899e23d64573ef58ee9) C:\Windows\system32\DRIVERS\MpFilter.sys
2011/07/06 07:35:08.0610 2940 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
2011/07/06 07:35:08.0625 2940 MpNWMon (98b09a4f2c462441030b83a80a3f6fb3) C:\Windows\system32\DRIVERS\MpNWMon.sys
2011/07/06 07:35:08.0641 2940 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2011/07/06 07:35:08.0656 2940 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
2011/07/06 07:35:08.0672 2940 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/07/06 07:35:08.0688 2940 mrxsmb10 (a8c2d7673c8a010569390c826a0efaf4) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/07/06 07:35:08.0703 2940 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/07/06 07:35:08.0719 2940 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
2011/07/06 07:35:08.0734 2940 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
2011/07/06 07:35:08.0766 2940 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2011/07/06 07:35:08.0781 2940 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2011/07/06 07:35:08.0797 2940 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/07/06 07:35:08.0828 2940 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2011/07/06 07:35:08.0844 2940 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/07/06 07:35:08.0859 2940 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2011/07/06 07:35:08.0875 2940 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
2011/07/06 07:35:08.0906 2940 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/07/06 07:35:08.0922 2940 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2011/07/06 07:35:08.0937 2940 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/07/06 07:35:08.0953 2940 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2011/07/06 07:35:08.0968 2940 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2011/07/06 07:35:09.0000 2940 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
2011/07/06 07:35:09.0031 2940 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/07/06 07:35:09.0046 2940 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/07/06 07:35:09.0062 2940 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/07/06 07:35:09.0078 2940 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/07/06 07:35:09.0093 2940 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
2011/07/06 07:35:09.0109 2940 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2011/07/06 07:35:09.0140 2940 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
2011/07/06 07:35:09.0171 2940 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/07/06 07:35:09.0187 2940 NisDrv (3713e8452b88d3e0be095e06b6fbc776) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
2011/07/06 07:35:09.0218 2940 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2011/07/06 07:35:09.0234 2940 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2011/07/06 07:35:09.0280 2940 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
2011/07/06 07:35:09.0296 2940 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2011/07/06 07:35:09.0468 2940 nvlddmkm (f12c5f17d48d9f5c70e4408b3ccb5443) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/07/06 07:35:09.0592 2940 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
2011/07/06 07:35:09.0608 2940 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
2011/07/06 07:35:09.0639 2940 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/07/06 07:35:09.0655 2940 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/07/06 07:35:09.0686 2940 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2011/07/06 07:35:09.0702 2940 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
2011/07/06 07:35:09.0733 2940 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
2011/07/06 07:35:09.0748 2940 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
2011/07/06 07:35:09.0764 2940 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/07/06 07:35:09.0780 2940 PCTCore (2cbdb9792dc47fe0bc34dfb9f0beaba4) C:\Windows\system32\drivers\PCTCore64.sys
2011/07/06 07:35:09.0795 2940 pctDS (ff43e3b1687e4e2140de6349ea5c7372) C:\Windows\system32\drivers\pctDS64.sys
2011/07/06 07:35:09.0826 2940 pctgntdi (6169a3c8e2c9ce88e6d3058cfbfcff03) C:\Windows\system32\drivers\pctgntdi64.sys
2011/07/06 07:35:09.0842 2940 pctplsg (eb27b1b0a1be8ae632c30bb16c4381b3) C:\Windows\System32\drivers\pctplsg64.sys
2011/07/06 07:35:09.0858 2940 PCTSD (dea3e7a33e268d4f1fbb4516c784646b) C:\Windows\system32\Drivers\PCTSD64.sys
2011/07/06 07:35:09.0873 2940 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2011/07/06 07:35:09.0904 2940 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2011/07/06 07:35:09.0982 2940 PID_PEPI (ae0b94363da0f60d42b9d05b352f61ed) C:\Windows\system32\DRIVERS\LV302V64.SYS
2011/07/06 07:35:10.0029 2940 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
2011/07/06 07:35:10.0045 2940 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2011/07/06 07:35:10.0076 2940 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
2011/07/06 07:35:10.0107 2940 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2011/07/06 07:35:10.0138 2940 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/07/06 07:35:10.0154 2940 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2011/07/06 07:35:10.0170 2940 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2011/07/06 07:35:10.0185 2940 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/07/06 07:35:10.0216 2940 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/07/06 07:35:10.0232 2940 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/07/06 07:35:10.0248 2940 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2011/07/06 07:35:10.0263 2940 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
2011/07/06 07:35:10.0279 2940 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/07/06 07:35:10.0294 2940 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/07/06 07:35:10.0326 2940 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
2011/07/06 07:35:10.0341 2940 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2011/07/06 07:35:10.0357 2940 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2011/07/06 07:35:10.0372 2940 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
2011/07/06 07:35:10.0388 2940 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
2011/07/06 07:35:10.0435 2940 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2011/07/06 07:35:10.0450 2940 RTL8167 (4b42bc58294e83a6a92ec8b88c14c4a3) C:\Windows\system32\DRIVERS\Rt64win7.sys
2011/07/06 07:35:10.0466 2940 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
2011/07/06 07:35:10.0497 2940 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/07/06 07:35:10.0513 2940 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
2011/07/06 07:35:10.0544 2940 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/07/06 07:35:10.0575 2940 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2011/07/06 07:35:10.0591 2940 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2011/07/06 07:35:10.0606 2940 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2011/07/06 07:35:10.0638 2940 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/07/06 07:35:10.0653 2940 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/07/06 07:35:10.0669 2940 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/07/06 07:35:10.0684 2940 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/07/06 07:35:10.0716 2940 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/07/06 07:35:10.0731 2940 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/07/06 07:35:10.0747 2940 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2011/07/06 07:35:10.0778 2940 snapman (446eb38ce4a6d040f548b2f547ca96ff) C:\Windows\system32\DRIVERS\snapman.sys
2011/07/06 07:35:10.0794 2940 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2011/07/06 07:35:10.0840 2940 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
2011/07/06 07:35:10.0856 2940 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
2011/07/06 07:35:10.0872 2940 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
2011/07/06 07:35:10.0903 2940 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2011/07/06 07:35:10.0918 2940 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
2011/07/06 07:35:10.0934 2940 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
2011/07/06 07:35:10.0950 2940 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
2011/07/06 07:35:11.0012 2940 Tcpip (61dc720bb065d607d5823f13d2a64321) C:\Windows\system32\drivers\tcpip.sys
2011/07/06 07:35:11.0059 2940 TCPIP6 (61dc720bb065d607d5823f13d2a64321) C:\Windows\system32\DRIVERS\tcpip.sys
2011/07/06 07:35:11.0090 2940 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
2011/07/06 07:35:11.0106 2940 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2011/07/06 07:35:11.0137 2940 tdrpman251 (df9179b7bdf0c5b71f9c3d93c016bae5) C:\Windows\system32\DRIVERS\tdrpm251.sys
2011/07/06 07:35:11.0168 2940 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2011/07/06 07:35:11.0184 2940 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
2011/07/06 07:35:11.0199 2940 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
2011/07/06 07:35:11.0246 2940 timounter (f7546ead58cc3000ac02cf9529b9934e) C:\Windows\system32\DRIVERS\timntr.sys
2011/07/06 07:35:11.0277 2940 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/07/06 07:35:11.0293 2940 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
2011/07/06 07:35:11.0308 2940 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2011/07/06 07:35:11.0324 2940 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
2011/07/06 07:35:11.0355 2940 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/07/06 07:35:11.0371 2940 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
2011/07/06 07:35:11.0386 2940 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2011/07/06 07:35:11.0418 2940 USBAAPL64 (f724b03c3dfaacf08d17d38bf3333583) C:\Windows\system32\Drivers\usbaapl64.sys
2011/07/06 07:35:11.0433 2940 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys
2011/07/06 07:35:11.0449 2940 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/07/06 07:35:11.0464 2940 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
2011/07/06 07:35:11.0480 2940 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
2011/07/06 07:35:11.0496 2940 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
2011/07/06 07:35:11.0511 2940 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
2011/07/06 07:35:11.0542 2940 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2011/07/06 07:35:11.0558 2940 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
2011/07/06 07:35:11.0574 2940 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/07/06 07:35:11.0589 2940 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/07/06 07:35:11.0620 2940 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/07/06 07:35:11.0636 2940 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/07/06 07:35:11.0652 2940 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2011/07/06 07:35:11.0683 2940 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/07/06 07:35:11.0698 2940 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
2011/07/06 07:35:11.0714 2940 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
2011/07/06 07:35:11.0730 2940 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
2011/07/06 07:35:11.0745 2940 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/07/06 07:35:11.0761 2940 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
2011/07/06 07:35:11.0792 2940 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
2011/07/06 07:35:11.0808 2940 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/07/06 07:35:11.0823 2940 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2011/07/06 07:35:11.0854 2940 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2011/07/06 07:35:11.0886 2940 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/06 07:35:11.0901 2940 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/06 07:35:11.0932 2940 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2011/07/06 07:35:11.0948 2940 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2011/07/06 07:35:11.0995 2940 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/07/06 07:35:12.0010 2940 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2011/07/06 07:35:12.0057 2940 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/07/06 07:35:12.0088 2940 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/07/06 07:35:12.0120 2940 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2011/07/06 07:35:12.0151 2940 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
2011/07/06 07:35:12.0166 2940 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/07/06 07:35:12.0198 2940 MBR (0x1B8) (6f9a1d528242bc09104b85e0becf5554) \Device\Harddisk0\DR0
2011/07/06 07:35:12.0213 2940 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.a (0)
2011/07/06 07:35:12.0213 2940 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
2011/07/06 07:35:12.0244 2940 MBR (0x1B8) (cdb4de4bbd714f152979da2dcbef57eb) \Device\Harddisk2\DR2
2011/07/06 07:35:12.0244 2940 Boot (0x1200) (8e8c34c413fd65ef612ad5750b80b447) \Device\Harddisk0\DR0\Partition0
2011/07/06 07:35:12.0260 2940 Boot (0x1200) (c9079b8ad1a0d8060d65c859c5d8d60e) \Device\Harddisk1\DR1\Partition0
2011/07/06 07:35:12.0276 2940 Boot (0x1200) (7c17aefd9180d6e5c15305d70c536f53) \Device\Harddisk2\DR2\Partition0
2011/07/06 07:35:12.0291 2940 ================================================================================
2011/07/06 07:35:12.0291 2940 Scan finished
2011/07/06 07:35:12.0291 2940 ================================================================================
2011/07/06 07:35:12.0291 3500 Detected object count: 1
2011/07/06 07:35:12.0291 3500 Actual detected object count: 1
2011/07/06 07:35:33.0663 3500 \Device\Harddisk0\DR0 (Rootkit.Boot.SST.a) - will be cured after reboot
2011/07/06 07:35:33.0663 3500 \Device\Harddisk0\DR0 - ok
2011/07/06 07:35:33.0663 3500 Rootkit.Boot.SST.a(\Device\Harddisk0\DR0) - User select action: Cure
Quick update - even though FF no longer crashes on load, it is still messing with the proxy settings each time I load the browser. But, it seems like that might be related to what we did with the custom ComboFix settings. What do you think?

But, is there a way to confirm that everything is completely clean?

I never give a guarantee like that but from the logs and automated scans we have run I would be as confident as I can be that the computer is clean of infections.



even though FF no longer crashes on load, it is still messing with the proxy settings each time I load the browser.

What exactly do you mean when you say messing with proxy settings,I can see no proxy server values in the logs now.
Every time I load FireFox my proxy settings are like this:
[external image: Posted Image]

When I set it to "no proxy" it works, but as soon as I close the browser and re-open, the settings revert.

I don't know what we're doing, but I brought up ComboFix because of the custom settings we used:
FireFox:::
FF - ProfilePath - c:\users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 62606
FF - prefs.js: network.proxy.type - 0

Could that be related to this, or is it something else?

Thanks again for all your help.

FireFox:::
FF - ProfilePath - c:\users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 62606
FF - prefs.js: network.proxy.type - 0

This script was run to remove that proxy server.


Open Internet explorer,click Tools>internet options>connections>lan settings.Make sure use a proxy is unchecked,click ok

Then in the screenshot you have,select no proxy and ok.See if this helps.
I cannot see anything in the logs to suggest why that is happening,can you uninstall/reinstall Firefox,that should resolve it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI