This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT Log Help

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm now infected from at least two different poor choices of downloads over the past year. I get occasional browser hijacking and have to kill some processes each time I start my computer. SpyBot S&D TeaTimer is not blocking the changes, I may have white-listed some things that I should not have at some point.

Here is my HJT log. I had killed some bad processes before running this scan, if this has created an incomplete scan I will gladly restart and scan again. Thank you:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:27:48 AM, on 7/12/2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
D:\downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:50707
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: YTNavAssist.YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll
F3 - REG:win.ini: load=C:\Users\Eric\AppData\Local\Temp\csrss.exe
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [FREEzeFrogSA] "C:\Program Files\FREEzeFrog\bin\1.0.670.0\FREEzeFrogSA.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [conhost] C:\Users\Eric\AppData\Roaming\Microsoft\conhost.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk.disabled
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk.disabled
O4 - Global Startup: Bluetooth Manager.lnk.disabled
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apache2.2 - Unknown owner - D:\xampp\apache\bin\apache.exe (file missing)
O23 - Service: Sprint Con App Svc (CASprint) - Unknown owner - C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: mysql - Unknown owner - D:\xampp\mysql\bin\mysqld.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: RosettaStoneDaemon - Rosetta Stone Ltd. - C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - Unknown owner - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 8821 bytes
:welcome:

You do have a few things going on. Do not run any other scanners on your own it will just interfere with what we need to do

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.





Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7143 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 7/15/2011 7:13:54 AM mbam-log-2011-07-15 (07-13-54).txt Scan type: Quick scan Objects scanned: 158151 Time elapsed: 5 minute(s), 22 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 9 Registry Values Infected: 5 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 25 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1602F07D-8BF3-4c08-BDD6-DDDB1C48AEDC} (Adware.ClickPotato) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{69725738-CD68-4f36-8D02-8C43722EE5DA} (Adware.Hotbar) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AC6D819E-AA8F-4418-A3BB-D165C1B18BB5} (Adware.ClickPotato) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FREEzeFrogAx.Info (Adware.FreezeFrog) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FREEzeFrogAx.Info.1 (Adware.FreezeFrog) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\FREEZEFROGSA (Adware.FreezeFrog) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FREEzeFrogSA (Adware.FreezeFrog) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Value: Load -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell.Gen) -> Value: Shell -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer (PUM.Bad.Proxy) -> Value: ProxyServer -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\freezefrogsa\actionurl_current_version (Adware.FreezeFrog) -> Value: actionurl_current_version -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\FREEzeFrogSA (Adware.FreezeFrog) -> Value: FREEzeFrogSA -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\programdata\2aca5cc3-0f83-453d-a079-1076fe1a8b65 (Adware.Seekmo) -> Quarantined and deleted successfully. c:\program files\freezefrog\bin\1.0.670.0 (Adware.FreezeFrog) -> Quarantined and deleted successfully. c:\programdata\freezefrogsa (Adware.FreezeFrog) -> Quarantined and deleted successfully. Files Infected: c:\Users\Eric\AppData\Local\Temp\sREh4nv2.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\aqt.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\axamikag.dll (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\dpj.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\dyt.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\fmx.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\hgc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\idc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\jghq.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\mwu.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\Qutmsv.dll (Trojan.Hiloti) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\rpq.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\syssvc.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\Users\Eric\local settings\application data\uhd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Eric\AppData\Roaming\MSA\mscj.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Users\Eric\AppData\Roaming\MSA\mscjm.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\program files\freezefrog\bin\1.0.670.0\freezefrogsa.exe (Adware.FreezeFrog) -> Quarantined and deleted successfully. c:\program files\freezefrog\bin\1.0.670.0\freezefrogsahook.dll (Adware.FreezeFrog) -> Quarantined and deleted successfully. c:\program files\freezefrog\bin\1.0.670.0\freezefroguninstaller.exe (Adware.FreezeFrog) -> Quarantined and deleted successfully. c:\program files\freezefrog\bin\1.0.670.0\launchhelp.dll (Adware.FreezeFrog) -> Quarantined and deleted successfully. c:\programdata\freezefrogsa\freezefrogsa.dat (Adware.FreezeFrog) -> Quarantined and deleted successfully. c:\programdata\freezefrogsa\freezefrogsaabout.mht (Adware.FreezeFrog) -> Quarantined and deleted successfully. c:\programdata\freezefrogsa\freezefrogsaau.dat (Adware.FreezeFrog) -> Quarantined and deleted successfully. c:\programdata\freezefrogsa\freezefrogsaeula.mht (Adware.FreezeFrog) -> Quarantined and deleted successfully. c:\programdata\freezefrogsa\freezefrogsa_kyf_update.dat (Adware.FreezeFrog) -> Quarantined and deleted successfully. and again after reboot: Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7143 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 7/15/2011 8:06:01 AM mbam-log-2011-07-15 (08-06-01).txt Scan type: Quick scan Objects scanned: 157677 Time elapsed: 8 minute(s), 0 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
:thumbup:

Are your browser searches being redirected ?

This will check for a rootkit type of infection

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]




OTL Scan will show more than HJT

OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
aswMBR version 0.9.7.750 Copyright© 2011 AVAST Software
Run date: 2011-07-15 18:08:47
—————————–
18:08:47.628 OS Version: Windows 6.0.6001 Service Pack 1
18:08:47.628 Number of processors: 2 586 0xF0D
18:08:47.629 ComputerName: CZARERICII UserName: Eric
18:08:49.397 Initialize success
18:08:53.127 AVAST engine defs: 11071501
18:08:58.541 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
18:08:58.544 Disk 0 Vendor: Hitachi_HTS542516K9SA00 BBCOC33P Size: 152627MB BusType: 3
18:08:58.546 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP4T0L0-6
18:08:58.549 Disk 1 Vendor: Hitachi_HTS542516K9SA00 BBCOC33P Size: 152627MB BusType: 3
18:09:00.621 Disk 0 MBR read successfully
18:09:00.624 Disk 0 MBR scan
18:09:00.629 Disk 0 unknown MBR code
18:09:02.654 Disk 0 scanning sectors +312580096
18:09:02.821 Disk 0 scanning C:\Windows\system32\drivers
18:09:39.195 Service scanning
18:09:40.688 Disk 0 trace - called modules:
18:09:40.723 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x85b221f8]<<
18:09:40.727 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86294620]
18:09:40.733 3 CLASSPNP.SYS[8ab09745] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x85b8a8a8]
18:09:40.738 \Driver\atapi[0x85bab3e8] -> IRP_MJ_CREATE -> 0x85b221f8
18:09:40.743 Scan finished successfully
23:21:56.597 Disk 0 MBR has been saved successfully to "C:\Users\Eric\Desktop\MBR.dat"
23:21:56.602 The log file has been saved successfully to "C:\Users\Eric\Desktop\aswMBR.txt"




OTL logfile created on: 7/15/2011 11:26:56 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = D:\downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 65.04% Memory free
6.20 Gb Paging File | 4.94 Gb Available in Paging File | 79.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 15.80 Gb Free Space | 10.70% Space Free | Partition Type: NTFS
Drive D: | 149.05 Gb Total Space | 113.40 Gb Free Space | 76.09% Space Free | Partition Type: NTFS

Computer Name: CZARERICII | User Name: Eric | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - D:\downloads\OTL.exe (OldTimer Tools)
PRC - D:\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - D:\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba\Utilities\KeNotify.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Modules (SafeList) ==========

MOD - D:\downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SprintRcAppSvc) – File not found
SRV - (CLTNetCnService) – File not found
SRV - (CASprint) – File not found
SRV - (Apache2.2) – File not found
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MBAMService) – D:\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ezGOSvc) – C:\Windows\System32\ezGOSvc.dll ()
SRV - (DAUpdaterSvc) – C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (RosettaStoneDaemon) – C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (mysql) – D:\xampp\mysql\bin\mysqld.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (TNaviSrv) – C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TosCoSrv) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) – C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (MSHUSBVideo) – C:\Windows\System32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\Windows\System32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\Windows\System32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\Windows\System32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (NWUSBCDFIL) – C:\Windows\System32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (Nmea) – C:\Windows\System32\drivers\pctnullport.sys (PCTEL Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (LUsbFilt) – C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) – C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (TosRfSnd) – C:\Windows\System32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (tosrfbd) – C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfhid) – C:\Windows\System32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfbnp) – C:\Windows\System32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (NETw4v32) Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (Cdralw2k) – C:\Windows\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\Windows\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (KR10I) – C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION)
DRV - (tosrfec) – C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (tosporte) – C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV - (toshidpt) – C:\Windows\System32\drivers\Toshidpt.sys (TOSHIBA Corporation.)
DRV - (tosrfnds) – C:\Windows\System32\drivers\tosrfnds.sys (TOSHIBA Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2062461591-625251616-2414354262-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
IE - HKU\S-1-5-21-2062461591-625251616-2414354262-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKU\S-1-5-21-2062461591-625251616-2414354262-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\S-1-5-21-2062461591-625251616-2414354262-1000\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-2062461591-625251616-2414354262-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-2062461591-625251616-2414354262-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.%(version)s
FF - prefs.js..extensions.enabledItems: {A31FF884-CCFC-4884-8EB3-FD42EEBAA060}:1.9.1
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50707
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2009/08/28 01:48:11 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Eric\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Eric\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Eric\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Eric\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Eric\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/23 08:28:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/23 08:28:01 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Eric\AppData\Roaming\Move Networks [2010/02/09 19:56:03 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{A31FF884-CCFC-4884-8EB3-FD42EEBAA060}: C:\Users\Eric\AppData\Local\{A31FF884-CCFC-4884-8EB3-FD42EEBAA060}\ [2011/02/26 17:20:42 | 000,000,000 | —D | M]

[2008/07/08 05:46:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Eric\AppData\Roaming\Mozilla\Extensions
[2011/07/15 17:16:54 | 000,000,000 | —D | M] (No name found) – C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\67d86y6d.default\extensions
[2010/04/27 14:58:30 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\67d86y6d.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/24 02:08:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\67d86y6d.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/09/02 06:15:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/02/26 17:20:42 | 000,000,000 | —D | M] (XULRunner) – C:\USERS\ERIC\APPDATA\LOCAL\{A31FF884-CCFC-4884-8EB3-FD42EEBAA060}
[2010/02/09 19:56:03 | 000,000,000 | —D | M] (Move Media Player) – C:\USERS\ERIC\APPDATA\ROAMING\MOVE NETWORKS
[2008/05/29 17:18:26 | 000,106,128 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npstrlnk.dll

O1 HOSTS File: ([2011/05/03 21:00:14 | 000,433,375 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 14917 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [KeNotify] C:\Program Files\Toshiba\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] D:\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2062461591-625251616-2414354262-1000..\Run: [conhost] File not found
O4 - HKU\S-1-5-21-2062461591-625251616-2414354262-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk.disabled ()
O4 - Startup: C:\Users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk.disabled ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Eric\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Eric\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{b518c6b2-02d1-11df-8d3f-00037aa0f4e6}\Shell - "" = AutoRun
O33 - MountPoints2\{b518c6b2-02d1-11df-8d3f-00037aa0f4e6}\Shell\AutoRun\command - "" = H:\SprintPreCopy.exe -L -d:NVTLBLUEUSB
O33 - MountPoints2\{c6b9c8bf-e516-11dd-a79e-001eec352bdb}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKU\S-1-5-21-2062461591-625251616-2414354262-1000..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/15 07:07:32 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Roaming\Malwarebytes
[2011/07/15 07:07:17 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/07/15 07:07:17 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/07/15 07:07:13 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/07/11 19:03:20 | 000,000,000 | —D | C] – C:\ProgramData\eMule
[2011/07/11 19:00:39 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\eMule
[2011/07/11 19:00:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eMule
[2011/07/11 18:59:40 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Roaming\FREEzeFrog
[2011/07/11 18:59:40 | 000,000,000 | —D | C] – C:\Program Files\FREEzeFrog
[2011/06/23 08:55:23 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/15 23:21:56 | 000,000,512 | —- | M] () – C:\Users\Eric\Desktop\MBR.dat
[2011/07/15 22:32:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2062461591-625251616-2414354262-1000UA.job
[2011/07/15 21:56:20 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/15 21:56:20 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/15 20:32:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2062461591-625251616-2414354262-1000Core.job
[2011/07/15 08:02:32 | 000,613,270 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/07/15 08:02:32 | 000,108,196 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/07/15 07:57:15 | 000,137,020 | —- | M] () – C:\ProgramData\nvModes.001
[2011/07/15 07:56:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/15 07:54:18 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/07/14 13:20:02 | 000,001,574 | -HS- | M] () – C:\Users\Eric\AppData\Local\o0r8j32l2vfisvr2oo51y8dg2tk73a7d3r6dbrv6umfu
[2011/07/14 13:20:02 | 000,001,574 | -HS- | M] () – C:\ProgramData\o0r8j32l2vfisvr2oo51y8dg2tk73a7d3r6dbrv6umfu
[2011/07/14 13:19:53 | 000,137,020 | —- | M] () – C:\ProgramData\nvModes.dat
[2011/07/13 04:32:58 | 000,002,048 | —- | M] () – C:\Users\Eric\Desktop\Google Chrome.lnk
[2011/07/13 04:32:58 | 000,002,010 | —- | M] () – C:\Users\Eric\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/07/12 17:23:25 | 000,395,209 | —- | M] () – C:\Users\Eric\Desktop\treasury print.xps
[2011/07/11 21:58:04 | 000,007,004 | —- | M] () – C:\Users\Eric\AppData\Roaming\925E.A91
[2011/07/08 22:43:10 | 000,148,249 | —- | M] () – C:\Users\Eric\Desktop\connection.jpg
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/06/27 11:29:58 | 000,002,377 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/06/23 08:55:23 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/06/22 10:11:25 | 000,001,410 | -HS- | M] () – C:\Users\Eric\AppData\Local\w568slnqkb30e8664s56
[2011/06/22 10:11:25 | 000,001,410 | -HS- | M] () – C:\ProgramData\w568slnqkb30e8664s56
[2011/06/20 02:50:07 | 000,001,550 | -HS- | M] () – C:\Users\Eric\AppData\Local\58buw8x567u4lj0h5muh1i27tls0vo45a5
[2011/06/20 02:50:07 | 000,001,550 | -HS- | M] () – C:\ProgramData\58buw8x567u4lj0h5muh1i27tls0vo45a5
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/15 23:21:56 | 000,000,512 | —- | C] () – C:\Users\Eric\Desktop\MBR.dat
[2011/07/14 13:19:55 | 000,001,574 | -HS- | C] () – C:\Users\Eric\AppData\Local\o0r8j32l2vfisvr2oo51y8dg2tk73a7d3r6dbrv6umfu
[2011/07/14 13:19:55 | 000,001,574 | -HS- | C] () – C:\ProgramData\o0r8j32l2vfisvr2oo51y8dg2tk73a7d3r6dbrv6umfu
[2011/07/12 17:23:17 | 000,395,209 | —- | C] () – C:\Users\Eric\Desktop\treasury print.xps
[2011/07/08 22:43:09 | 000,148,249 | —- | C] () – C:\Users\Eric\Desktop\connection.jpg
[2011/06/22 10:11:19 | 000,001,410 | -HS- | C] () – C:\ProgramData\w568slnqkb30e8664s56
[2011/06/22 10:11:18 | 000,001,410 | -HS- | C] () – C:\Users\Eric\AppData\Local\w568slnqkb30e8664s56
[2011/06/20 02:49:36 | 000,001,550 | -HS- | C] () – C:\Users\Eric\AppData\Local\58buw8x567u4lj0h5muh1i27tls0vo45a5
[2011/06/20 02:49:36 | 000,001,550 | -HS- | C] () – C:\ProgramData\58buw8x567u4lj0h5muh1i27tls0vo45a5
[2011/06/01 16:57:07 | 000,073,600 | —- | C] () – C:\Windows\System32\ezGOSvc.dll
[2011/05/30 08:55:22 | 000,001,610 | -HS- | C] () – C:\Users\Eric\AppData\Local\k53phh05m63xl61w50p78u3805prg
[2011/05/30 08:55:22 | 000,001,610 | -HS- | C] () – C:\ProgramData\k53phh05m63xl61w50p78u3805prg
[2011/05/26 15:15:57 | 000,005,004 | -HS- | C] () – C:\Users\Eric\AppData\Local\4256o56y1a8o6x33021iv38cljbeoo2456lvgt
[2011/05/26 15:15:57 | 000,005,004 | -HS- | C] () – C:\ProgramData\4256o56y1a8o6x33021iv38cljbeoo2456lvgt
[2011/05/22 19:46:21 | 000,001,272 | -HS- | C] () – C:\Users\Eric\AppData\Local\7300xfuydabpb0c364ilhj2vy60n8see17r
[2011/05/22 19:46:21 | 000,001,272 | -HS- | C] () – C:\ProgramData\7300xfuydabpb0c364ilhj2vy60n8see17r
[2011/04/30 22:07:12 | 000,012,020 | -HS- | C] () – C:\Users\Eric\AppData\Local\320678denltbl50eg3g1l57brju58b5n2
[2011/04/30 22:07:12 | 000,012,020 | -HS- | C] () – C:\ProgramData\320678denltbl50eg3g1l57brju58b5n2
[2011/04/22 23:19:21 | 000,049,152 | —- | C] () – C:\Windows\System32\xmbkdjl.dll
[2010/12/03 19:36:12 | 000,007,004 | —- | C] () – C:\Users\Eric\AppData\Roaming\925E.A91
[2010/11/17 14:33:16 | 000,000,680 | —- | C] () – C:\Users\Eric\AppData\Local\d3d9caps.dat
[2010/09/01 14:43:24 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/07/26 13:19:35 | 000,075,776 | —- | C] () – C:\Windows\cadkasdeinst01e.exe
[2010/02/18 14:58:04 | 000,000,262 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/01/16 17:06:50 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2010/01/10 10:10:55 | 000,000,092 | —- | C] () – C:\Users\Eric\AppData\Local\fusioncache.dat
[2009/04/14 20:56:28 | 000,168,448 | —- | C] () – C:\Windows\System32\unrar.dll
[2009/04/04 17:09:34 | 000,223,232 | —- | C] () – C:\Windows\System32\sqlite3.dll
[2009/04/04 17:09:34 | 000,086,016 | —- | C] () – C:\Windows\System32\SQLiteWrapper.dll
[2009/03/08 13:19:13 | 000,187,580 | —- | C] () – C:\Windows\Photo Pos Pro Uninstaller.exe
[2009/01/12 00:14:10 | 000,000,067 | —- | C] () – C:\Windows\swupdate.INI
[2009/01/10 00:12:49 | 000,137,020 | —- | C] () – C:\ProgramData\nvModes.001
[2009/01/10 00:12:48 | 000,137,020 | —- | C] () – C:\ProgramData\nvModes.dat
[2008/10/22 05:29:06 | 000,173,550 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2008/10/15 13:58:34 | 000,024,840 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2008/09/29 19:24:52 | 000,000,798 | —- | C] () – C:\Windows\eReg.dat
[2008/09/07 03:00:25 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2008/09/07 03:00:25 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/07/27 02:07:04 | 000,000,000 | —- | C] () – C:\Users\Eric\AppData\Roaming\wklnhst.dat
[2008/07/15 18:01:57 | 000,027,240 | —- | C] () – C:\Users\Eric\AppData\Roaming\nvModes.001
[2008/07/13 15:51:09 | 000,140,288 | —- | C] () – C:\Users\Eric\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/07/13 13:33:03 | 000,027,240 | —- | C] () – C:\Users\Eric\AppData\Roaming\nvModes.dat
[2008/07/08 05:09:26 | 000,000,013 | RHS- | C] () – C:\Windows\System32\drivers\fbd.sys
[2008/07/08 05:09:26 | 000,000,004 | RHS- | C] () – C:\Windows\System32\drivers\taishop.sys
[2008/02/21 17:25:58 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ3.dat
[2008/02/21 17:25:58 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ2.dat
[2008/02/21 17:25:58 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ1.dat
[2008/02/21 17:25:58 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ0.dat
[2008/02/18 22:05:56 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2008/02/18 22:05:56 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2008/02/18 22:05:56 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2008/02/18 22:05:56 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2008/02/18 22:05:56 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2008/02/18 22:05:55 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2008/02/18 21:18:38 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2008/02/18 21:07:01 | 000,036,864 | —- | C] () – C:\Windows\System32\HWS_Ctrl.dll
[2008/02/18 20:04:46 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2008/02/18 20:04:46 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2008/02/18 20:04:46 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2008/02/18 20:04:46 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2008/02/18 19:23:25 | 000,157,040 | —- | C] () – C:\Windows\fdbpinger.exe
[2007/12/27 08:14:25 | 000,020,480 | —- | C] () – C:\Windows\System32\PosTickerLib.dll
[2007/12/21 20:46:32 | 000,118,784 | —- | C] () – C:\Windows\System32\TosBtAcc.dll
[2007/03/06 19:54:04 | 000,995,328 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,325,128 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,613,270 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,108,196 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 13:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2005/11/23 18:55:42 | 000,024,576 | —- | C] () – C:\Windows\System32\SPCtl.dll
[2005/09/23 08:52:14 | 000,207,872 | —- | C] () – C:\Windows\System32\OneWay.dll
[2005/07/23 01:30:18 | 000,065,536 | —- | C] () – C:\Windows\System32\TosCommAPI.dll
[2002/06/02 11:05:40 | 000,038,912 | —- | C] () – C:\Windows\System32\1Way.dll
[1997/06/13 22:56:08 | 000,056,832 | —- | C] () – C:\Windows\System32\iyvu9_32.dll

========== LOP Check ==========

[2010/11/26 19:03:46 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\.minecraft
[2011/04/04 21:35:16 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Bioshock
[2009/01/18 00:37:09 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\DAEMON Tools Pro
[2011/01/14 17:53:18 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Dropbox
[2010/03/10 13:26:13 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Facebook
[2011/07/11 18:59:40 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\FREEzeFrog
[2011/06/27 11:30:03 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\go
[2010/07/01 23:46:16 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\gtk-2.0
[2008/07/17 23:10:24 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\iWin
[2011/07/15 07:13:53 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\MSA
[2011/01/19 23:43:44 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Notepad++
[2011/04/22 21:53:25 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\PFStaticIP
[2011/04/12 17:06:19 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Remere's Map Editor
[2009/08/30 01:24:02 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\SPORE
[2008/07/27 02:07:06 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Template
[2011/04/21 01:11:25 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Tibia
[2008/07/08 18:03:03 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\TOSHIBA
[2008/10/04 12:55:06 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Uniblue
[2010/05/23 15:20:09 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Unity
[2009/01/12 00:13:19 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\WinBatch
[2011/07/15 07:54:21 | 000,032,584 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:7715B65F

< End of report >

OTL Extras logfile created on: 7/15/2011 11:26:56 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = D:\downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 65.04% Memory free
6.20 Gb Paging File | 4.94 Gb Available in Paging File | 79.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 15.80 Gb Free Space | 10.70% Space Free | Partition Type: NTFS
Drive D: | 149.05 Gb Total Space | 113.40 Gb Free Space | 76.09% Space Free | Partition Type: NTFS

Computer Name: CZARERICII | User Name: Eric | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-2062461591-625251616-2414354262-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DisabledInterfaces" = {20D8012C-D194-407D-9AF3-9F734ADA7280},{D3055FA3-ECC4-4FAD-BB62-4E5B1ACBD7F0},{8759429B-C2D8-46E1-88AA-1395AB2000DE}

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07A62CEF-B168-49F2-817A-E518BD7AAD5E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{0905DD3E-CD44-47F5-9C5A-21A72ACFD40F}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{127DF93D-F71A-4BFF-A957-2C79E8988166}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1ED8A613-FD54-4BB2-BA2D-37EAE8E59F11}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{21976028-35E1-4237-9674-9F25C4176BF6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{22C52F1E-7753-4571-8038-1BC919A9FA9A}" = rport=1701 | protocol=17 | dir=out | app=system |
"{2E5378D8-6A1E-4B20-B7D9-4B10B9A0EEAF}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{32440AE7-F472-4BEF-8C18-490AC4003F12}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{338B6F02-A024-4894-9D1B-E7FE3539F7E7}" = lport=1723 | protocol=6 | dir=in | app=system |
"{348ED737-A3A6-4437-A404-C5AAA37C24D6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3F197F6F-ADE8-4D9C-8CC9-9AAC04F56BC5}" = lport=1701 | protocol=17 | dir=in | app=system |
"{4678571A-82BD-4FCD-8A2E-3AFF4146126F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{46A0A105-EEA5-4DD8-977A-AC59A46A5867}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{5328D633-466F-4CCE-B41B-9605819A650B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{69B6F703-0CEA-49D0-82B5-75865E03A1AF}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{6C9AFB03-90AE-41F9-84FC-3D2A90B06465}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{83A0A326-951B-4F30-936B-74611245CB7E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{85FF778C-AC1D-425C-B0F9-50499EDE4227}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{8F46252E-D913-404C-8FF3-E604D89EC74F}" = rport=1723 | protocol=6 | dir=out | app=system |
"{963CB95E-C4DC-436C-9907-10E5CC2E3470}" = lport=445 | protocol=6 | dir=in | app=system |
"{9C36EF02-409A-4528-9473-DE52CF164AC8}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9E541895-28DE-4A46-8287-606956D87D25}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A164B284-529D-4BC7-9B85-1AB9C8A54AEB}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{AB0A925C-20E9-43EE-BE16-06C69FDAB4B6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C2EBFE73-3DF9-4CAB-A98C-E0A87877F248}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CF5E8EDB-14DE-4FBC-8E3D-D69ABDC47000}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{D018C783-7FCB-4F77-81EF-4771DCEAFB59}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D1F63FAF-3715-433D-B2C1-D309E09C1ABE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D58E35A4-650E-4646-A236-04CB97CDFCBF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D5ED1727-C44E-4E59-8F8F-2F68627CD994}" = lport=10243 | protocol=6 | dir=in | app=system |
"{D928D108-EEE5-4EA9-94E5-465A6FB63DCE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DB12CBC1-AA2A-4C85-AAD6-1CFD40A85210}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F51167FF-5330-47DE-805F-45E3C2A9AAAD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04954D9C-555B-4126-81E5-F4AA23D12023}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{056D8B38-B585-4393-86FC-69B78239956D}" = protocol=17 | dir=in | app=d:\world of warcraft\wow-x.x.x.x-4.0.0.12911-downloader.exe |
"{076CDF91-9D04-4C86-BE2D-223F33830401}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\bioshock\builds\release\bioshock.exe |
"{07FFFC6B-37D4-48DC-8786-F1A517508A0B}" = protocol=17 | dir=in | app=d:\world of warcraft\launcher.patch.exe |
"{0AE15AF9-9E53-4C18-85BD-CE85298AC433}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\i-fluid\i-fluid.exe |
"{0B1E8A27-9C5C-4268-B9F8-37990B769C3F}" = protocol=17 | dir=in | app=c:\program files\dragon age\daoriginslauncher.exe |
"{0F14EE23-83B2-4762-AE7A-4BC370F28C56}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0F6CDF9E-EC21-4068-84E9-42E0F5087501}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifetray.exe |
"{151DA554-FE6A-4928-B31C-C844CFFFEEA8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\swkotor\swkotor.exe |
"{16BE92E9-8087-4BDA-88FB-41E1A34639F1}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{176FF409-6B37-4ACC-9A9F-A0280687BB2D}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{196C28DC-2288-4E08-925D-805C3C54FC55}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{1D71226A-50CD-4063-B58B-AFA92CE3E4DA}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{1D86F522-7739-4332-B6A1-A2DACB520105}" = protocol=17 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization 4 gold\warlords\civ4warlords.exe |
"{22DF2B13-D2D1-4952-80D7-C224FE307BCD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\risk factions\risk factions.exe |
"{31DBB25E-6235-4467-B738-C007247E160C}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{31EE3283-9D1C-4F00-BE1B-EBFBE9C87275}" = protocol=17 | dir=in | app=c:\users\eric\appdata\roaming\dropbox\bin\dropbox.exe |
"{37C1E243-1DF1-46BA-B4CE-4CC82F971124}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{398C1310-698D-4EDE-B0EB-CF91104C6016}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{3D7F4280-955E-4584-AFE3-39F2FF1AFD82}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{3E34BF0F-C58B-4E56-9FA3-E5D25B0D92A5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{3F183805-9B15-4FF4-BB0F-E9BD5D9606C3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{44175F12-BC39-4EAC-ADB8-15C54A16D2B0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5 tribes of the east\bin\h5_mapeditor.exe |
"{44CA57A6-AF2B-4C45-8E96-DA270870721C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\fallout 3 goty\falloutlauncher.exe |
"{452A7E5F-594D-4DBA-9B12-83C4A5BFE135}" = protocol=6 | dir=out | app=system |
"{45CD1855-EE2D-4EF5-BC70-2F5F7EC2C46D}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4843B5EF-C76C-40FD-AAA2-15924131575C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
"{4929142B-418B-454F-B48F-FCB35FB1D6D6}" = protocol=17 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization 4 gold\civilization4.exe |
"{4A59AC74-4179-468E-9BCE-FC2DB6121734}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{4C16A70B-4677-4A36-9B20-E7B86346FBEA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{4CBED8B0-A6DF-484F-B124-129E80C24A76}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{523E5181-2056-49BA-8585-414212552B52}" = protocol=6 | dir=in | app=d:\ea\mass effect\masseffectlauncher.exe |
"{53FB0AB2-1E24-48B5-A5E1-9F5E81A1673B}" = protocol=6 | dir=in | app=c:\program files\dragon age\daoriginslauncher.exe |
"{55FFAFC8-5158-4B89-900E-B4E8EC4DB419}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5\bin\h5_game.exe |
"{57D46522-EDA3-4F7B-8FD5-70ADCA1C3262}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{5CE0BBBC-639D-484C-83BD-C37DA39B5D22}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{6BFA8A02-CB84-4D37-8813-E8C4F18878AF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6D9C8FF5-9085-4EF3-9CC9-67B06B5A96CB}" = dir=in | app=c:\program files\rosettastoneltdservices\rosettastoneltdservices.exe |
"{6D9E939C-7125-4382-ADE0-73DA7E4738E9}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{763D5807-4327-4E6B-9027-F17503A071FD}" = protocol=6 | dir=in | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{76A96903-2C5F-43D0-A651-7616ED231803}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{7CE9223F-E7C0-477C-958F-92C4D2A97495}" = protocol=6 | dir=in | app=c:\users\public\world of warcraft\wow-3.1.1.9835-to-3.1.2.9901-enus-downloader.exe |
"{7E7F719D-3DF8-477E-84D4-106B80D5C062}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{7EBAB662-E52C-4712-920B-024BC0077540}" = dir=in | app=c:\program files\rosettastoneltdservices\rosettastonedaemon.exe |
"{80659690-86F2-4D3D-AC6C-17BA4BAC0F66}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{80669996-F757-4D4C-870A-7A3E62F53311}" = protocol=6 | dir=out | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{813AC9B6-226E-4D0C-8A27-3EE31FCF38B1}" = protocol=6 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization 4 gold\warlords\civ4warlords.exe |
"{82876FCB-271E-4928-9B11-C5859CBEFF4D}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{85B3F002-B58A-4F14-840E-7E2DD618226D}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5 tribes of the east\bin\h5_game.exe |
"{867CA634-5CBC-445C-A907-7566253A5AA0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5 tribes of the east\bin\h5_game.exe |
"{87D3E73B-8630-4859-8D6D-DE1B91D4AD0A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{888D74A9-7608-40E4-B45F-9BBBF97D4511}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{88F3E233-F97B-4EB6-95F2-AB461E087D8D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
"{8E8EAC3B-C169-4A06-9572-D7DA93EC2B45}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8EC0D618-4475-4E43-B604-83EC05865371}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeenc2.exe |
"{903FCA9E-9DEB-4CE9-98FF-5808D490C1F6}" = protocol=6 | dir=in | app=c:\windows\system32\wbem\unsecapp.exe |
"{91975FF0-18E2-442E-B159-37F2D2B97254}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{9B9779EC-422A-441C-B67F-3837ADAEEEF2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\risk factions\risk factions.exe |
"{9EB85F84-F5D4-4E8A-A966-4CA93BD8EFF5}" = protocol=6 | dir=in | app=c:\users\eric\appdata\roaming\dropbox\bin\dropbox.exe |
"{A1175AA1-F978-4997-A260-344A53D33318}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{A201CECF-F38F-4081-9958-6FC00E9566DF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\swkotor\swkotor.exe |
"{A22C0F24-B839-462D-821E-5A33108D6F72}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\i-fluid\i-fluid.exe |
"{A4A6E69E-E458-4FF0-8EB4-2CD3A09C5262}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A4E7F5A7-0F4D-4BCC-84CE-EC93701825F1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A69D5282-2DB8-42B7-87D5-71CB8626203E}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifetray.exe |
"{B0B39B14-F08A-49F5-BDB9-0370398A5506}" = protocol=17 | dir=in | app=c:\program files\dragon age\bin_ship\daorigins.exe |
"{B54C926F-DD69-4798-9BD5-8B42E67885B4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B6E5F722-BB29-4FFF-B1F8-AA85CFA49067}" = protocol=6 | dir=in | app=d:\ea\mass effect\binaries\masseffect.exe |
"{B852DD1F-E0AE-4807-8CD6-8CCFCBFB0EF9}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
"{BA4DA965-9700-47AF-BAD7-795520EDED3F}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{BA62EA50-8E8B-47DF-AB62-A2159B8DC684}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{BB786E58-9BF3-41CE-8030-6BB9FA1F6E89}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5\bina1\testapp.exe |
"{BBFA8EA4-9732-45AF-8B27-78FC9EA1A47A}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{BDC63477-8079-446F-B7FC-3F0677FE4C8F}" = protocol=6 | dir=out | app=c:\program files\rosettastoneltdservices\rosettastoneltdservices.exe |
"{BFECC8BA-851F-4F40-A64B-601362D04503}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeenc2.exe |
"{C2A026D0-723A-4C03-9968-5670199738D3}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C36CD6CF-1B49-4092-A15E-1DC5E9319621}" = protocol=6 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization 4 gold\civilization4.exe |
"{C786C442-7E25-45DD-806D-5D0D6531FF28}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
"{C9D626CB-2CAF-4A24-BC1D-FB370980227A}" = protocol=17 | dir=in | app=d:\ea\mass effect\binaries\masseffect.exe |
"{CD2D14B1-3EF4-4AC4-819D-9DE12CABD05C}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{CD7D7766-B314-4F7A-9665-56AD113A2877}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{CF7F81ED-8C87-4C00-8470-F6BC6B7824BC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D048914F-0E3B-4B6F-BEAF-5FBCBE9C239F}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D06B033E-A6A0-44DE-9B18-95E5CAAE6A45}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{D7E86CC1-7099-423D-A131-29AFF598A05F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5\bin\h5_game.exe |
"{DA928D2D-2E5B-4B73-A59C-1F8CEBC74390}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{DD409E71-7740-43DF-B743-B53B4EE47D80}" = protocol=6 | dir=out | app=c:\program files\rosettastoneltdservices\rosettastonedaemon.exe |
"{E1E464C7-A1E9-4BD8-B698-60293AFA86D2}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{E2D11C50-B57B-46B6-8641-156203590616}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{E33DF766-6E68-48D7-BDE5-1DC5FE5BE6A4}" = protocol=6 | dir=in | app=d:\world of warcraft\wow-x.x.x.x-4.0.0.12911-downloader.exe |
"{E40358C0-9C41-49B6-81E2-AE2715B747E6}" = protocol=6 | dir=in | app=c:\program files\dragon age\bin_ship\daupdatersvc.service.exe |
"{E7B1ADBD-2A48-40B4-ACB3-E1C4E2E01376}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5\bina1\testapp.exe |
"{E8213576-26C2-403C-ABB8-06929899AA9C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{E8E2C0CC-D901-4CF5-94B6-65D2888B65CA}" = protocol=6 | dir=in | app=c:\program files\dragon age\bin_ship\daorigins.exe |
"{EB8F24EF-E73D-4241-B6C2-C1CD9E931EE9}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\fallout 3 goty\falloutlauncher.exe |
"{EC57C636-5611-4660-A8B2-375EAFCF747F}" = protocol=17 | dir=in | app=c:\users\public\world of warcraft\wow-3.1.1.9835-to-3.1.2.9901-enus-downloader.exe |
"{ED0A4B83-7DF5-4140-846A-BF532AF56A0E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
"{EE00CC3E-5C84-453E-8095-D9138DA9A59C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\bioshock\builds\release\bioshock.exe |
"{EE3E6EF3-C346-40B2-A906-07E689886C5F}" = protocol=6 | dir=out | app=system |
"{F0579DA6-0330-4BEC-9A6C-11825B748C83}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5 tribes of the east\bin\h5_game.exe |
"{F4CD676C-8EDB-403E-A4F2-BFE496270316}" = protocol=17 | dir=in | app=d:\ea\mass effect\masseffectlauncher.exe |
"{F6624278-99E8-4B7D-875F-88939DBE8D04}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F720E0BD-BEB2-4398-8AA9-F358C7D14803}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{F961EBB1-3601-4BD9-ADAD-5F957DA9E06C}" = protocol=17 | dir=in | app=c:\program files\dragon age\bin_ship\daupdatersvc.service.exe |
"{F9F9554A-27AA-4610-9F39-05DB712A1CCD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5 tribes of the east\bin\h5_game.exe |
"{F9FDFCA1-9F62-4AC9-82FF-9CA5DC1F0DB6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{FF3AEEF4-A22A-48DD-A368-FB363C3CC0E9}" = protocol=6 | dir=in | app=d:\world of warcraft\launcher.patch.exe |
"{FFAF4D03-4BED-4A8F-B4D1-8B4AA33FDCF5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\heroes of might and magic 5 tribes of the east\bin\h5_mapeditor.exe |
"TCP Query User{035D67F1-C652-483B-86EC-961C510EEB4B}D:\starcraft ii\versions\base15405\sc2.exe" = protocol=6 | dir=in | app=d:\starcraft ii\versions\base15405\sc2.exe |
"TCP Query User{058363B8-49BE-4FE9-B1F7-72133E0AA1BE}C:\users\public\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\world of warcraft\launcher.exe |
"TCP Query User{1023D368-4E82-4BBF-B7C0-7F66CB568690}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{17B55882-6D17-4C2C-A392-6919B2B6186B}C:\program files\steam\steamapps\common\worms reloaded\wormsreloaded.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\worms reloaded\wormsreloaded.exe |
"TCP Query User{1C1E7B82-1752-43C1-842F-6C308BA347B1}D:\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=d:\starcraft ii\support\blizzarddownloader.exe |
"TCP Query User{1D2B8C74-B592-49DB-BC92-3EF0625590B0}D:\starcraft ii\versions\base17326\sc2.exe" = protocol=6 | dir=in | app=d:\starcraft ii\versions\base17326\sc2.exe |
"TCP Query User{3F0A35DB-AAEB-405D-8645-8EC1DDFCF026}C:\users\public\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\users\public\world of warcraft\backgrounddownloader.exe |
"TCP Query User{3FDBA913-F11B-45D0-9BE0-0BD631C4CAB7}C:\program files\3do\heroes3\heroes3.exe" = protocol=6 | dir=in | app=c:\program files\3do\heroes3\heroes3.exe |
"TCP Query User{4323C0D8-407C-449E-BD5D-7AAAEBF5676F}D:\world of warcraft\wow-3.3.3.11685-to-3.3.3.11723-enus-downloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\wow-3.3.3.11685-to-3.3.3.11723-enus-downloader.exe |
"TCP Query User{44F5053D-47EF-4FFF-B326-97B06BCB9237}D:\starcraft ii\versions\base18574\sc2.exe" = protocol=6 | dir=in | app=d:\starcraft ii\versions\base18574\sc2.exe |
"TCP Query User{51978CE7-2D47-42AB-8D68-A4B4FFF9D2A5}C:\program files\napster\napster.exe" = protocol=6 | dir=in | app=c:\program files\napster\napster.exe |
"TCP Query User{519A4B59-21D3-49A0-9F43-B6F17A27F230}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{60228421-A882-4ADF-B09E-D3E28B601718}C:\users\eric\desktop\ot\ots\yurots.exe" = protocol=6 | dir=in | app=c:\users\eric\desktop\ot\ots\yurots.exe |
"TCP Query User{6B7DA19C-D25A-4E52-8FBE-DB10A9B967E2}D:\starcraft ii\versions\base18092\sc2.exe" = protocol=6 | dir=in | app=d:\starcraft ii\versions\base18092\sc2.exe |
"TCP Query User{6EA32D61-3B7B-438B-8AAA-0B5DBF7AC054}D:\python\pythonw.exe" = protocol=6 | dir=in | app=d:\python\pythonw.exe |
"TCP Query User{72A0A033-8F80-47F8-8866-19D1D5906678}C:\users\eric\desktop\ot\styller yourots 8.50 v0.6\styller yourots 8.50 v6.exe" = protocol=6 | dir=in | app=c:\users\eric\desktop\ot\styller yourots 8.50 v0.6\styller yourots 8.50 v6.exe |
"TCP Query User{7B7A01B2-EA55-4BC1-BB81-C1981BAF5397}D:\starcraft ii\versions\base16605\sc2.exe" = protocol=6 | dir=in | app=d:\starcraft ii\versions\base16605\sc2.exe |
"TCP Query User{7BDF4797-1528-4594-93BE-9316744B43CA}D:\eve\bin\exefile.exe" = protocol=6 | dir=in | app=d:\eve\bin\exefile.exe |
"TCP Query User{84E8EAAF-936A-4C31-B159-7ECD08403849}D:\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\backgrounddownloader.exe |
"TCP Query User{899638BA-85E2-4FFD-9D9A-A90F9DB6C2E3}C:\program files\dragon age\bin_ship\daorigins.exe" = protocol=6 | dir=in | app=c:\program files\dragon age\bin_ship\daorigins.exe |
"TCP Query User{8DAA6B76-9690-4B51-AB5E-21E4CAF2065B}C:\program files\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"TCP Query User{8EDD44A3-2CAB-4358-870C-E27B122442AD}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{9508A5EE-AF8F-48CA-8262-2EE1B8DD36A8}D:\starcraft ii\starcraft ii.exe" = protocol=6 | dir=in | app=d:\starcraft ii\starcraft ii.exe |
"TCP Query User{953EB874-FD7F-43C0-A171-5ED14A1BC622}D:\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=d:\world of warcraft\launcher.exe |
"TCP Query User{A4BE5F3F-430C-49B4-A451-49C0474DB17F}C:\program files\ccp\eve\bin\exefile.exe" = protocol=6 | dir=in | app=c:\program files\ccp\eve\bin\exefile.exe |
"TCP Query User{A919A061-6BBC-4DF8-AF34-2A6485700AF4}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{ADCBFEB0-5FC6-47FE-AA1F-CEC5EB18093C}D:\starcraft ii\versions\base16561\sc2.exe" = protocol=6 | dir=in | app=d:\starcraft ii\versions\base16561\sc2.exe |
"TCP Query User{B5BF6FA6-C85C-4435-B800-8F9C383288B5}D:\starcraft ii\versions\base16939\sc2.exe" = protocol=6 | dir=in | app=d:\starcraft ii\versions\base16939\sc2.exe |
"TCP Query User{BCDE91AE-0F1A-4AD9-BA4E-A02019F476AC}C:\program files\microsoft games\age of empires iii\age3.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"TCP Query User{C48E2656-075B-4DF1-A524-D4284A1C2332}D:\world of warcraft\wow-3.3.2.11403-to-3.3.3.11685-enus-downloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\wow-3.3.2.11403-to-3.3.3.11685-enus-downloader.exe |
"TCP Query User{CE28ADBD-12BC-4921-8848-DD9AFE4082BA}D:\starcraft\starcraft.exe" = protocol=6 | dir=in | app=d:\starcraft\starcraft.exe |
"TCP Query User{D0FBCD48-A69F-4D10-8010-2676DBE3C813}D:\starcraft ii\versions\base16755\sc2.exe" = protocol=6 | dir=in | app=d:\starcraft ii\versions\base16755\sc2.exe |
"TCP Query User{D5560A08-A4C7-4855-8FF4-05FEAAB260A4}C:\program files\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\backgrounddownloader.exe |
"TCP Query User{D6E7036F-2853-4A57-A7CC-A4192A0B89A6}C:\program files\napster\napster.exe" = protocol=6 | dir=in | app=c:\program files\napster\napster.exe |
"TCP Query User{E8208A07-B376-4FED-A173-38F2C5D9DE8F}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.icd" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.icd |
"TCP Query User{E9C9A822-FD1B-4926-9FAC-189BA5BC4526}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.icd" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.icd |
"TCP Query User{FDA9105D-5108-411E-8D5F-235CC23B346F}C:\program files\starcraft\starcraft.exe" = protocol=6 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"TCP Query User{FEA4ED2F-3126-4FBE-8E78-398D97CC8148}C:\users\eric\appdata\local\temp\blizzard launcher temporary - b2e19f60\launcher.exe" = protocol=6 | dir=in | app=c:\users\eric\appdata\local\temp\blizzard launcher temporary - b2e19f60\launcher.exe |
"UDP Query User{04AF7BB0-3387-44B3-97C4-220EA2DECDCD}C:\users\public\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\users\public\world of warcraft\backgrounddownloader.exe |
"UDP Query User{0B61A84B-D15F-4A6E-BD23-E25836CD48C0}C:\program files\starcraft\starcraft.exe" = protocol=17 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"UDP Query User{0CEDF17B-6FA6-4C1C-BA4B-1FDD07FBDB8E}C:\users\public\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\world of warcraft\launcher.exe |
"UDP Query User{0E1F1211-B6BA-4E8F-9797-C0AAE0F6FDAE}D:\starcraft ii\versions\base18092\sc2.exe" = protocol=17 | dir=in | app=d:\starcraft ii\versions\base18092\sc2.exe |
"UDP Query User{1656DC9E-A71B-4B13-9A8E-51CF830E1978}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{1E93F04B-FE3A-41E3-B9A9-7BF9810B6928}D:\eve\bin\exefile.exe" = protocol=17 | dir=in | app=d:\eve\bin\exefile.exe |
"UDP Query User{21DFA69E-5DA0-42CE-9B12-59865FE9B61B}C:\program files\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\backgrounddownloader.exe |
"UDP Query User{23792B24-1BEA-4127-8E42-2CCCA66A58AB}C:\program files\ccp\eve\bin\exefile.exe" = protocol=17 | dir=in | app=c:\program files\ccp\eve\bin\exefile.exe |
"UDP Query User{266A437B-60AB-4C3B-996F-88973747B9B9}C:\users\eric\appdata\local\temp\blizzard launcher temporary - b2e19f60\launcher.exe" = protocol=17 | dir=in | app=c:\users\eric\appdata\local\temp\blizzard launcher temporary - b2e19f60\launcher.exe |
"UDP Query User{2878D5EE-87BF-4194-A2CF-433A819E6E53}C:\users\eric\desktop\ot\styller yourots 8.50 v0.6\styller yourots 8.50 v6.exe" = protocol=17 | dir=in | app=c:\users\eric\desktop\ot\styller yourots 8.50 v0.6\styller yourots 8.50 v6.exe |
"UDP Query User{2951229F-C4DB-4FB1-8E49-6A906C7C74C3}D:\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=d:\starcraft ii\support\blizzarddownloader.exe |
"UDP Query User{309F36FE-06F5-4579-B802-002389F1EA85}D:\starcraft ii\versions\base16755\sc2.exe" = protocol=17 | dir=in | app=d:\starcraft ii\versions\base16755\sc2.exe |
"UDP Query User{38B9B7A0-FE3B-4603-A6E6-50EB22F3AF0A}D:\starcraft ii\versions\base18574\sc2.exe" = protocol=17 | dir=in | app=d:\starcraft ii\versions\base18574\sc2.exe |
"UDP Query User{3E1B75F5-F596-4553-A00F-27EC12725981}D:\starcraft ii\starcraft ii.exe" = protocol=17 | dir=in | app=d:\starcraft ii\starcraft ii.exe |
"UDP Query User{444E5C09-1DFB-4478-BBE6-692C50918B5A}D:\world of warcraft\wow-3.3.3.11685-to-3.3.3.11723-enus-downloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\wow-3.3.3.11685-to-3.3.3.11723-enus-downloader.exe |
"UDP Query User{446E7B0B-1C9C-44FF-BDCE-D4C8F5B3EEE2}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{53696C45-538C-4278-B5F8-642557C4CF5D}C:\program files\napster\napster.exe" = protocol=17 | dir=in | app=c:\program files\napster\napster.exe |
"UDP Query User{5527891D-D70B-4BA8-A6E8-D65BA46DAB55}D:\starcraft\starcraft.exe" = protocol=17 | dir=in | app=d:\starcraft\starcraft.exe |
"UDP Query User{568D4147-2547-45D0-BFE4-402AA8BE6566}C:\program files\3do\heroes3\heroes3.exe" = protocol=17 | dir=in | app=c:\program files\3do\heroes3\heroes3.exe |
"UDP Query User{56D476DC-7EB3-43D9-86FC-3A6DA72C2202}C:\program files\microsoft games\age of empires iii\age3.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"UDP Query User{7E51BB3B-3909-47BD-8A86-F79405E756D5}C:\program files\dragon age\bin_ship\daorigins.exe" = protocol=17 | dir=in | app=c:\program files\dragon age\bin_ship\daorigins.exe |
"UDP Query User{8C92E9E1-A63F-4E32-BD45-2F145982E64E}D:\starcraft ii\versions\base16605\sc2.exe" = protocol=17 | dir=in | app=d:\starcraft ii\versions\base16605\sc2.exe |
"UDP Query User{91E1F1D6-9865-4892-961D-E7388AC534C4}C:\users\eric\desktop\ot\ots\yurots.exe" = protocol=17 | dir=in | app=c:\users\eric\desktop\ot\ots\yurots.exe |
"UDP Query User{98E0076A-1B9C-4830-8704-99E6C0F1987A}D:\starcraft ii\versions\base17326\sc2.exe" = protocol=17 | dir=in | app=d:\starcraft ii\versions\base17326\sc2.exe |
"UDP Query User{99680F5C-50F9-4AF8-9739-170DC216F1E8}D:\starcraft ii\versions\base16561\sc2.exe" = protocol=17 | dir=in | app=d:\starcraft ii\versions\base16561\sc2.exe |
"UDP Query User{9A636462-4BDC-4F21-9CAB-40D36F0C6864}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{9EBBB326-B7CA-4761-8A86-6813C6F3AE2E}C:\program files\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"UDP Query User{A09BB716-89CE-466A-AD14-5F43AD42C844}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.icd" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.icd |
"UDP Query User{A0B22BCB-C39D-4CF4-AB2D-57AD7B309146}D:\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=d:\world of warcraft\launcher.exe |
"UDP Query User{A3156332-7F62-40C5-913B-BC74140312FF}C:\program files\steam\steamapps\common\worms reloaded\wormsreloaded.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\worms reloaded\wormsreloaded.exe |
"UDP Query User{A6695F22-72AB-4ECF-8F09-AD652D3E035C}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{AC059982-FFBD-4F73-8DC7-5F0301C4AE38}D:\python\pythonw.exe" = protocol=17 | dir=in | app=d:\python\pythonw.exe |
"UDP Query User{B8F3803F-DA37-4D9B-B14B-0B2EF1AF28F9}D:\starcraft ii\versions\base16939\sc2.exe" = protocol=17 | dir=in | app=d:\starcraft ii\versions\base16939\sc2.exe |
"UDP Query User{BCE106D4-66EB-4EF8-A18F-B339861F407A}D:\starcraft ii\versions\base15405\sc2.exe" = protocol=17 | dir=in | app=d:\starcraft ii\versions\base15405\sc2.exe |
"UDP Query User{C5FF1E11-70B4-47A5-B91D-FFE87290F084}D:\world of warcraft\wow-3.3.2.11403-to-3.3.3.11685-enus-downloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\wow-3.3.2.11403-to-3.3.3.11685-enus-downloader.exe |
"UDP Query User{CFB38DDA-651A-42D5-8A8E-E1F975EFD6F8}C:\program files\napster\napster.exe" = protocol=17 | dir=in | app=c:\program files\napster\napster.exe |
"UDP Query User{D70251C5-51A4-4568-9FF0-A30B37F14468}D:\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\backgrounddownloader.exe |
"UDP Query User{FE76477E-DB6B-40E5-89FB-5769469AF14B}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.icd" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.icd |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{03240EBA-04F2-4652-BC7F-B055902BDCD3}" = Memeo AutoBackup
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 17
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3230518C-2953-4FB9-8485-B3CDFCC36A70}" = Rosetta Stone Ltd Services
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{55502C49-F061-428C-BF26-06ECDFB3AC29}" = Sid Meier's Civilization 4 Gold
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{59E4543A-D49D-4489-B445-473D763C79AF}" = Microsoft Games for Windows - LIVE Redistributable
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{63A6E9A9-A190-46D4-9430-2DB28654AFD8}" = Norton 360
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6F6594CB-DA1B-4FFB-B397-CACE3D5F668B}" = Windows Live Movie Maker Beta
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{7CE12FDF-B758-46A5-A8CD-785EDFDC5B84}" = Workspace Macro 4.6
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CBEAEF3-C6BA-4F0F-8DC2-03B12BC8CF2F}" = Remere's Map Editor
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}" = SimCity 4 Deluxe
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7CB214-DB11-4B5D-A6AF-3B4ED47C68B7}" = Microsoft Game Studios Common Redistributables Pack 1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}" = Black & White® 2
"{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{f719d8a6-46fc-4d71-94c6-ffd17a8c9f35}" = Python 3.1.3
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 4.65
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AVerMedia USB Hybrid Capture Device" = AVerMedia USB Hybrid Capture Device [removed]
"eMule" = eMule
"Flash-Creator 1" = Flash-Creator 1
"Heroes of Might and Magic® III" = Heroes of Might and Magic® III
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{03240EBA-04F2-4652-BC7F-B055902BDCD3}" = Memeo AutoBackup
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.0 (Standard)
"Magic ISO Maker v5.5 (build 0273)" = Magic ISO Maker v5.5 (build 0273)
"MagicDisc 2.7.105" = MagicDisc 2.7.105
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.18)" = Mozilla Firefox (3.6.18)
"Network Play System (Patching)" = Network Play System (Patching)
"Notepad++" = Notepad++
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"Origin" = Origin
"Photo Pos Pro" = Photo Pos Pro
"PhotoPerfect Multiprocessor_is1" = PhotoPerfect 2.91
"Picasa2" = Picasa 2
"Portforward Static IP Address" = Portforward Static IP Address 1.0.45
"ProInst" = Intel® PROSet/Wireless Software
"Quick Macro_is1" = Quick Macro v6.50
"Skype™ for Windows Mobile_is1" = Skype™ for Windows Mobile 3.0
"StarCraft II" = StarCraft II
"Steam App 15170" = Heroes of Might and Magic 5
"Steam App 15370" = Heroes of Might and Magic V: Tribes of the East
"Steam App 15380" = Heroes of Might and Magic V: Hammers of Fate
"Steam App 22370" = Fallout 3 - Game of the Year Edition
"Steam App 22600" = Worms Reloaded
"Steam App 32370" = Star Wars: Knights of the Old Republic
"Steam App 400" = Portal
"Steam App 42910" = Magicka
"Steam App 47800" = RISK Factions
"Steam App 550" = Left 4 Dead 2
"Steam App 564" = Left 4 Dead 2 Add-on Support
"Steam App 7670" = BioShock
"Steam App 8930" = Sid Meier's Civilization V
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Tibia_is1" = Tibia
"TMIPC" = Tibia MULTI-ip changer
"WildTangent toshiba Master Uninstall" = TOSHIBA Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"xampp" = XAMPP 1.6.6a
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2062461591-625251616-2414354262-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Facebook Plug-In" = Facebook Plug-In
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/1/2011 8:23:21 AM | Computer Name = CzarEricII | Source = Perflib | ID = 1008
Description =

Error - 6/1/2011 8:23:22 AM | Computer Name = CzarEricII | Source = Perflib | ID = 1008
Description =

Error - 6/1/2011 8:23:22 AM | Computer Name = CzarEricII | Source = Perflib | ID = 1008
Description =

Error - 6/1/2011 9:47:24 AM | Computer Name = CzarEricII | Source = Application Error | ID = 1000
Description = Faulting application Skype.exe, version 5.1.0.112, time stamp 0x4d4037c2,
faulting module Skype.exe, version 5.1.0.112, time stamp 0x4d4037c2, exception
code 0xc0000005, fault offset 0x00e67086, process id 0xd90, application start time
0x01cc20526bc15060.

Error - 6/1/2011 4:29:37 PM | Computer Name = CzarEricII | Source = Perflib | ID = 1008
Description =

Error - 6/1/2011 4:29:37 PM | Computer Name = CzarEricII | Source = Perflib | ID = 1010
Description =

Error - 6/1/2011 4:29:37 PM | Computer Name = CzarEricII | Source = Perflib | ID = 1008
Description =

Error - 6/1/2011 4:29:37 PM | Computer Name = CzarEricII | Source = Perflib | ID = 1008
Description =

Error - 6/1/2011 4:29:37 PM | Computer Name = CzarEricII | Source = Perflib | ID = 1008
Description =

Error - 6/1/2011 4:29:38 PM | Computer Name = CzarEricII | Source = Perflib | ID = 1008
Description =

[ System Events ]
Error - 7/8/2011 10:13:40 PM | Computer Name = CzarEricII | Source = HTTP | ID = 15016
Description =

Error - 7/8/2011 10:13:48 PM | Computer Name = CzarEricII | Source = Service Control Manager | ID = 7000
Description =

Error - 7/9/2011 12:22:03 AM | Computer Name = CzarEricII | Source = volsnap | ID = 393236
Description = The shadow copies of volume C: were aborted because of a failed free
space computation.

Error - 7/11/2011 1:32:58 AM | Computer Name = CzarEricII | Source = HTTP | ID = 15016
Description =

Error - 7/11/2011 1:33:06 AM | Computer Name = CzarEricII | Source = Service Control Manager | ID = 7000
Description =

Error - 7/13/2011 8:28:27 AM | Computer Name = CzarEricII | Source = Service Control Manager | ID = 7009
Description =

Error - 7/13/2011 8:28:27 AM | Computer Name = CzarEricII | Source = Service Control Manager | ID = 7000
Description =

Error - 7/15/2011 7:56:23 AM | Computer Name = CzarEricII | Source = HTTP | ID = 15016
Description =

Error - 7/15/2011 7:56:36 AM | Computer Name = CzarEricII | Source = Service Control Manager | ID = 7000
Description =

Error - 7/15/2011 7:56:37 AM | Computer Name = CzarEricII | Source = Service Control Manager | ID = 7034
Description =


< End of report >

Thank you so much for your help.
Lets run this program

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
2011/07/17 22:26:51.0222 1816 TDSS rootkit removing tool 2.5.11.0 Jul 11 2011 16:56:56 2011/07/17 22:26:51.0525 1816 ================================================================================ 2011/07/17 22:26:51.0525 1816 SystemInfo: 2011/07/17 22:26:51.0525 1816 2011/07/17 22:26:51.0525 1816 OS Version: 6.0.6001 ServicePack: 1.0 2011/07/17 22:26:51.0525 1816 Product type: Workstation 2011/07/17 22:26:51.0525 1816 ComputerName: CZARERICII 2011/07/17 22:26:51.0525 1816 UserName: Eric 2011/07/17 22:26:51.0525 1816 Windows directory: C:\Windows 2011/07/17 22:26:51.0525 1816 System windows directory: C:\Windows 2011/07/17 22:26:51.0526 1816 Processor architecture: Intel x86 2011/07/17 22:26:51.0526 1816 Number of processors: 2 2011/07/17 22:26:51.0526 1816 Page size: 0x1000 2011/07/17 22:26:51.0526 1816 Boot type: Normal boot 2011/07/17 22:26:51.0526 1816 ================================================================================ 2011/07/17 22:26:53.0933 1816 Initialize success 2011/07/17 22:27:04.0242 4632 ================================================================================ 2011/07/17 22:27:04.0242 4632 Scan started 2011/07/17 22:27:04.0242 4632 Mode: Manual; 2011/07/17 22:27:04.0242 4632 ================================================================================ 2011/07/17 22:27:04.0912 4632 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys 2011/07/17 22:27:04.0964 4632 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 2011/07/17 22:27:05.0076 4632 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 2011/07/17 22:27:05.0136 4632 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 2011/07/17 22:27:05.0173 4632 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 2011/07/17 22:27:05.0298 4632 AFD (48eb99503533c27ac6135648e5474457) C:\Windows\system32\drivers\afd.sys 2011/07/17 22:27:05.0440 4632 AgereSoftModem (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys 2011/07/17 22:27:05.0573 4632 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 2011/07/17 22:27:05.0616 4632 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/07/17 22:27:05.0648 4632 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 2011/07/17 22:27:05.0747 4632 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 2011/07/17 22:27:05.0783 4632 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 2011/07/17 22:27:05.0827 4632 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 2011/07/17 22:27:05.0915 4632 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 2011/07/17 22:27:05.0986 4632 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 2011/07/17 22:27:06.0090 4632 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 2011/07/17 22:27:06.0137 4632 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/07/17 22:27:06.0167 4632 atapi (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys 2011/07/17 22:27:06.0291 4632 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/07/17 22:27:06.0345 4632 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 2011/07/17 22:27:06.0375 4632 bowser (8153396d5551276227fa146900f734e6) C:\Windows\system32\DRIVERS\bowser.sys 2011/07/17 22:27:06.0480 4632 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/07/17 22:27:06.0507 4632 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/07/17 22:27:06.0545 4632 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/07/17 22:27:06.0570 4632 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/07/17 22:27:06.0663 4632 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/07/17 22:27:06.0685 4632 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/07/17 22:27:06.0722 4632 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/07/17 22:27:06.0854 4632 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/07/17 22:27:06.0905 4632 Cdr4_xp (837eef65af62d4e8a37c41d3879f7274) C:\Windows\system32\drivers\Cdr4_xp.sys 2011/07/17 22:27:06.0926 4632 Cdralw2k (579da2f9f5401f55dae2cf8779d61dfc) C:\Windows\system32\drivers\Cdralw2k.sys 2011/07/17 22:27:07.0036 4632 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys 2011/07/17 22:27:07.0071 4632 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 2011/07/17 22:27:07.0120 4632 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys 2011/07/17 22:27:07.0260 4632 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/07/17 22:27:07.0293 4632 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 2011/07/17 22:27:07.0325 4632 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 2011/07/17 22:27:07.0438 4632 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 2011/07/17 22:27:07.0468 4632 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 2011/07/17 22:27:07.0552 4632 DfsC (a3e9fa213f443ac77c7746119d13feec) C:\Windows\system32\Drivers\dfsc.sys 2011/07/17 22:27:07.0701 4632 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys 2011/07/17 22:27:07.0773 4632 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/07/17 22:27:07.0867 4632 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys 2011/07/17 22:27:07.0981 4632 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/07/17 22:27:08.0040 4632 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys 2011/07/17 22:27:08.0103 4632 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 2011/07/17 22:27:08.0216 4632 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 2011/07/17 22:27:08.0338 4632 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys 2011/07/17 22:27:08.0569 4632 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys 2011/07/17 22:27:08.0611 4632 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 2011/07/17 22:27:08.0733 4632 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/07/17 22:27:08.0763 4632 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/07/17 22:27:08.0792 4632 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/07/17 22:27:08.0817 4632 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys 2011/07/17 22:27:08.0926 4632 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/07/17 22:27:08.0953 4632 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 2011/07/17 22:27:08.0996 4632 GEARAspiWDM (4ac51459805264affd5f6fdfb9d9235f) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2011/07/17 22:27:09.0124 4632 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 2011/07/17 22:27:09.0159 4632 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/07/17 22:27:09.0261 4632 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/07/17 22:27:09.0292 4632 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/07/17 22:27:09.0352 4632 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys 2011/07/17 22:27:09.0466 4632 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 2011/07/17 22:27:09.0525 4632 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys 2011/07/17 22:27:09.0623 4632 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 2011/07/17 22:27:09.0673 4632 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/07/17 22:27:09.0708 4632 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 2011/07/17 22:27:09.0817 4632 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/07/17 22:27:09.0930 4632 IntcAzAudAddService (8a4341616976e47712b60f18c7049dcc) C:\Windows\system32\drivers\RTKVHDA.sys 2011/07/17 22:27:10.0061 4632 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2011/07/17 22:27:10.0097 4632 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/07/17 22:27:10.0140 4632 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/07/17 22:27:10.0263 4632 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 2011/07/17 22:27:10.0299 4632 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/07/17 22:27:10.0333 4632 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/07/17 22:27:10.0365 4632 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 2011/07/17 22:27:10.0464 4632 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/07/17 22:27:10.0493 4632 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/07/17 22:27:10.0520 4632 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/07/17 22:27:10.0553 4632 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/07/17 22:27:10.0582 4632 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys 2011/07/17 22:27:10.0696 4632 KR10I (e8ca038f51f7761bd6e3a3b0b8014263) C:\Windows\system32\drivers\kr10i.sys 2011/07/17 22:27:10.0728 4632 KR10N (6a4adb9186dd0e114e623daf57e42b31) C:\Windows\system32\drivers\kr10n.sys 2011/07/17 22:27:10.0791 4632 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys 2011/07/17 22:27:10.0914 4632 LHidFilt (24e0ddb99aeccf86bb37702611761459) C:\Windows\system32\DRIVERS\LHidFilt.Sys 2011/07/17 22:27:10.0974 4632 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/07/17 22:27:11.0017 4632 LMouFilt (d58b330d318361a66a9fe60d7c9b4951) C:\Windows\system32\DRIVERS\LMouFilt.Sys 2011/07/17 22:27:11.0122 4632 LPCFilter (515fc18cabee0158a324b08b1c2667cf) C:\Windows\system32\DRIVERS\LPCFilter.sys 2011/07/17 22:27:11.0171 4632 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 2011/07/17 22:27:11.0209 4632 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 2011/07/17 22:27:11.0305 4632 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 2011/07/17 22:27:11.0352 4632 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/07/17 22:27:11.0451 4632 LUsbFilt (144011d14bd35f4e36136ae057b1aadd) C:\Windows\system32\Drivers\LUsbFilt.Sys 2011/07/17 22:27:11.0510 4632 MBAMProtector (eca00eed9ab95489007b0ef84c7149de) C:\Windows\system32\drivers\mbam.sys 2011/07/17 22:27:11.0623 4632 mcdbus (af61a1c34e2d3f7543f9ccfc323170b8) C:\Windows\system32\DRIVERS\mcdbus.sys 2011/07/17 22:27:11.0685 4632 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 2011/07/17 22:27:11.0779 4632 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 2011/07/17 22:27:11.0911 4632 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/07/17 22:27:12.0007 4632 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/07/17 22:27:12.0177 4632 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/07/17 22:27:12.0380 4632 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/07/17 22:27:12.0554 4632 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/07/17 22:27:12.0622 4632 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 2011/07/17 22:27:12.0756 4632 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/07/17 22:27:12.0811 4632 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/07/17 22:27:12.0935 4632 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys 2011/07/17 22:27:13.0043 4632 mrxsmb (5734a0f2be7e495f7d3ed6efd4b9f5a1) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/07/17 22:27:13.0255 4632 mrxsmb10 (cf6e972f8e0d0f2970360a17572b366b) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/07/17 22:27:13.0313 4632 mrxsmb20 (5c80d8159181c7abf1b14ba703b01e0b) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/07/17 22:27:13.0430 4632 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 2011/07/17 22:27:13.0634 4632 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 2011/07/17 22:27:13.0766 4632 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/07/17 22:27:13.0838 4632 MSHUSBVideo (956741c67abaa78b19aadc5474936842) C:\Windows\system32\Drivers\nx6000.sys 2011/07/17 22:27:13.0925 4632 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/07/17 22:27:13.0981 4632 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/07/17 22:27:14.0016 4632 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/07/17 22:27:14.0101 4632 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/07/17 22:27:14.0149 4632 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys 2011/07/17 22:27:14.0183 4632 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/07/17 22:27:14.0272 4632 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/07/17 22:27:14.0321 4632 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys 2011/07/17 22:27:14.0389 4632 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys 2011/07/17 22:27:14.0492 4632 NDIS (9bdc71790fa08f0a0b5f10462b1bd0b1) C:\Windows\system32\drivers\ndis.sys 2011/07/17 22:27:14.0597 4632 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/07/17 22:27:14.0633 4632 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/07/17 22:27:14.0670 4632 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/07/17 22:27:14.0701 4632 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/07/17 22:27:14.0796 4632 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/07/17 22:27:14.0836 4632 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys 2011/07/17 22:27:14.0967 4632 NETw3v32 (35d5458d9a1b26b2005abffbf4c1c5e7) C:\Windows\system32\DRIVERS\NETw3v32.sys 2011/07/17 22:27:15.0171 4632 NETw4v32 (6522dd40a5f67ced020bd81b856613fb) C:\Windows\system32\DRIVERS\NETw4v32.sys 2011/07/17 22:27:15.0314 4632 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/07/17 22:27:15.0379 4632 Nmea (b0d5188e282dc4edae7020f333427bc8) C:\Windows\system32\DRIVERS\pctnullport.sys 2011/07/17 22:27:15.0405 4632 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys 2011/07/17 22:27:15.0513 4632 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/07/17 22:27:15.0581 4632 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys 2011/07/17 22:27:15.0689 4632 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/07/17 22:27:15.0724 4632 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/07/17 22:27:15.0965 4632 nvlddmkm (18634f41aa3a3ac5bb25714ca3cd1100) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2011/07/17 22:27:16.0108 4632 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 2011/07/17 22:27:16.0141 4632 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 2011/07/17 22:27:16.0192 4632 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 2011/07/17 22:27:16.0288 4632 NWADI (0973c0c696780161f4526586d5eac422) C:\Windows\system32\DRIVERS\NWADIenum.sys 2011/07/17 22:27:16.0398 4632 NWUSBCDFIL (1fde5b2d61d97d803594df4b3bc28c4b) C:\Windows\system32\DRIVERS\NwUsbCdFil.sys 2011/07/17 22:27:16.0437 4632 NWUSBModem (65b471bb7e57c416a1e685ec07d4abfa) C:\Windows\system32\DRIVERS\nwusbmdm.sys 2011/07/17 22:27:16.0550 4632 NWUSBPort (65b471bb7e57c416a1e685ec07d4abfa) C:\Windows\system32\DRIVERS\nwusbser.sys 2011/07/17 22:27:16.0594 4632 NWUSBPort2 (65b471bb7e57c416a1e685ec07d4abfa) C:\Windows\system32\DRIVERS\nwusbser2.sys 2011/07/17 22:27:16.0657 4632 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys 2011/07/17 22:27:16.0779 4632 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/07/17 22:27:16.0813 4632 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys 2011/07/17 22:27:16.0838 4632 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/07/17 22:27:16.0949 4632 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\Windows\system32\Drivers\PCASp50.sys 2011/07/17 22:27:17.0022 4632 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys 2011/07/17 22:27:17.0048 4632 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys 2011/07/17 22:27:17.0093 4632 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys 2011/07/17 22:27:17.0314 4632 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/07/17 22:27:17.0515 4632 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/07/17 22:27:17.0568 4632 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 2011/07/17 22:27:17.0635 4632 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys 2011/07/17 22:27:17.0767 4632 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\Windows\system32\Drivers\PxHelp20.sys 2011/07/17 22:27:17.0862 4632 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 2011/07/17 22:27:17.0967 4632 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/07/17 22:27:18.0007 4632 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/07/17 22:27:18.0052 4632 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/07/17 22:27:18.0168 4632 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/07/17 22:27:18.0207 4632 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/07/17 22:27:18.0237 4632 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys 2011/07/17 22:27:18.0269 4632 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys 2011/07/17 22:27:18.0372 4632 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/07/17 22:27:18.0407 4632 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 2011/07/17 22:27:18.0443 4632 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/07/17 22:27:18.0501 4632 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys 2011/07/17 22:27:18.0780 4632 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\Windows\system32\DRIVERS\RimSerial.sys 2011/07/17 22:27:18.0886 4632 ROOTMODEM (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys 2011/07/17 22:27:19.0016 4632 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/07/17 22:27:19.0072 4632 RTL8169 (5163f804256deb8cf1ef64b780a18caa) C:\Windows\system32\DRIVERS\Rtlh86.sys 2011/07/17 22:27:19.0117 4632 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/07/17 22:27:19.0248 4632 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys 2011/07/17 22:27:19.0279 4632 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/07/17 22:27:19.0319 4632 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/07/17 22:27:19.0353 4632 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/07/17 22:27:19.0452 4632 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/07/17 22:27:19.0506 4632 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 2011/07/17 22:27:19.0534 4632 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 2011/07/17 22:27:19.0556 4632 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 2011/07/17 22:27:19.0581 4632 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/07/17 22:27:19.0643 4632 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 2011/07/17 22:27:19.0746 4632 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 2011/07/17 22:27:19.0779 4632 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 2011/07/17 22:27:19.0819 4632 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys 2011/07/17 22:27:19.0863 4632 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/07/17 22:27:20.0014 4632 sptd (71e276f6d189413266ea22171806597b) C:\Windows\system32\Drivers\sptd.sys 2011/07/17 22:27:20.0014 4632 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b 2011/07/17 22:27:20.0032 4632 sptd - detected LockedFile.Multi.Generic (1) 2011/07/17 22:27:20.0137 4632 srv (2252aef839b1093d16761189f45af885) C:\Windows\system32\DRIVERS\srv.sys 2011/07/17 22:27:20.0184 4632 srv2 (b7ff59408034119476b00a81bb53d5d1) C:\Windows\system32\DRIVERS\srv2.sys 2011/07/17 22:27:20.0213 4632 srvnet (2accc9b12af02030f531e6cca6f8b76e) C:\Windows\system32\DRIVERS\srvnet.sys 2011/07/17 22:27:20.0348 4632 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/07/17 22:27:20.0401 4632 swmsflt (e6c797b33a454840245c0c96e7f08b0a) C:\Windows\System32\drivers\swmsflt.sys 2011/07/17 22:27:20.0441 4632 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/07/17 22:27:20.0477 4632 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/07/17 22:27:20.0582 4632 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/07/17 22:27:20.0667 4632 SynTP (ac4459d34f22b52feb6e619746ff6bd4) C:\Windows\system32\DRIVERS\SynTP.sys 2011/07/17 22:27:20.0759 4632 Tcpip (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\drivers\tcpip.sys 2011/07/17 22:27:20.0892 4632 Tcpip6 (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\DRIVERS\tcpip.sys 2011/07/17 22:27:21.0003 4632 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys 2011/07/17 22:27:21.0047 4632 TcUsb (009aede9fe870c247014450dc1e01d5d) C:\Windows\system32\Drivers\tcusb.sys 2011/07/17 22:27:21.0097 4632 tdcmdpst (1825bceb47bf41c5a9f0e44de82fc27a) C:\Windows\system32\DRIVERS\tdcmdpst.sys 2011/07/17 22:27:21.0199 4632 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/07/17 22:27:21.0230 4632 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/07/17 22:27:21.0262 4632 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys 2011/07/17 22:27:21.0295 4632 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys 2011/07/17 22:27:21.0436 4632 tifm21 (e4c85c291ddb3dc5e4a2f227ca465ba6) C:\Windows\system32\drivers\tifm21.sys 2011/07/17 22:27:21.0614 4632 toshidpt (e362d54fd394999c4178936396664e57) C:\Windows\system32\drivers\Toshidpt.sys 2011/07/17 22:27:21.0676 4632 tosporte (8d624d3bd1f2d78bd1c01a2d4e954b4e) C:\Windows\system32\DRIVERS\tosporte.sys 2011/07/17 22:27:21.0722 4632 tosrfbd (ae43138b0dea239b3621b0faf1bb1fe7) C:\Windows\system32\DRIVERS\tosrfbd.sys 2011/07/17 22:27:21.0832 4632 tosrfbnp (181e217a7a326817d97946d045b3cb46) C:\Windows\system32\Drivers\tosrfbnp.sys 2011/07/17 22:27:21.0909 4632 Tosrfcom (e90ace3b4fa7a85f992bc21eb779c407) C:\Windows\system32\Drivers\tosrfcom.sys 2011/07/17 22:27:22.0000 4632 tosrfec (5c4103544612e5011ef46301b93d1aa6) C:\Windows\system32\DRIVERS\tosrfec.sys 2011/07/17 22:27:22.0048 4632 Tosrfhid (87700714f25131ed21901d617b8b321f) C:\Windows\system32\DRIVERS\Tosrfhid.sys 2011/07/17 22:27:22.0076 4632 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\Windows\system32\DRIVERS\tosrfnds.sys 2011/07/17 22:27:22.0183 4632 TosRfSnd (156d63f6898e4d95f2962f2b72862868) C:\Windows\system32\drivers\tosrfsnd.sys 2011/07/17 22:27:22.0226 4632 Tosrfusb (98c04a6432ce9c2ad328f57b9384d348) C:\Windows\system32\DRIVERS\tosrfusb.sys 2011/07/17 22:27:22.0296 4632 tos_sps32 (1ea5f27c29405bf49799feca77186da9) C:\Windows\system32\DRIVERS\tos_sps32.sys 2011/07/17 22:27:22.0455 4632 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/07/17 22:27:22.0501 4632 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/07/17 22:27:22.0597 4632 tunnel (6042505ff6fa9ac1ef7684d0e03b6940) C:\Windows\system32\DRIVERS\tunnel.sys 2011/07/17 22:27:22.0667 4632 TVALZ (792a8b80f8188aba4b2be271583f3e46) C:\Windows\system32\DRIVERS\TVALZ_O.SYS 2011/07/17 22:27:22.0717 4632 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 2011/07/17 22:27:22.0822 4632 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys 2011/07/17 22:27:22.0904 4632 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 2011/07/17 22:27:22.0943 4632 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 2011/07/17 22:27:23.0050 4632 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/07/17 22:27:23.0101 4632 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/07/17 22:27:23.0138 4632 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/07/17 22:27:23.0259 4632 usbaudio (292a25bb75a568ae2c67169ba2c6365a) C:\Windows\system32\drivers\usbaudio.sys 2011/07/17 22:27:23.0317 4632 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/07/17 22:27:23.0360 4632 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/07/17 22:27:23.0453 4632 usbehci (cebe90821810e76320155beba722fcf9) C:\Windows\system32\DRIVERS\usbehci.sys 2011/07/17 22:27:23.0501 4632 usbhub (cc6b28e4ce39951357963119ce47b143) C:\Windows\system32\DRIVERS\usbhub.sys 2011/07/17 22:27:23.0528 4632 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2011/07/17 22:27:23.0554 4632 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys 2011/07/17 22:27:23.0640 4632 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/07/17 22:27:23.0706 4632 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/07/17 22:27:23.0766 4632 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 2011/07/17 22:27:23.0848 4632 usb_rndisx (ee181a08e09db23cf4a49b46a1e66bb8) C:\Windows\system32\DRIVERS\usb8023x.sys 2011/07/17 22:27:23.0953 4632 UVCFTR (3b929a72aaea96dc0150d3a6da268c89) C:\Windows\system32\Drivers\UVCFTR_S.SYS 2011/07/17 22:27:24.0045 4632 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/07/17 22:27:24.0087 4632 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/07/17 22:27:24.0131 4632 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 2011/07/17 22:27:24.0158 4632 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 2011/07/17 22:27:24.0250 4632 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 2011/07/17 22:27:24.0297 4632 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/07/17 22:27:24.0342 4632 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys 2011/07/17 22:27:24.0380 4632 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys 2011/07/17 22:27:24.0472 4632 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 2011/07/17 22:27:24.0533 4632 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/07/17 22:27:24.0563 4632 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/07/17 22:27:24.0586 4632 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/07/17 22:27:24.0704 4632 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 2011/07/17 22:27:24.0790 4632 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2011/07/17 22:27:24.0939 4632 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys 2011/07/17 22:27:25.0064 4632 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/07/17 22:27:25.0149 4632 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/07/17 22:27:25.0246 4632 MBR (0x1B8) (5b5e648d12fcadc244c1ec30318e1eb9) \Device\Harddisk0\DR0 2011/07/17 22:27:25.0270 4632 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk1\DR1 2011/07/17 22:27:25.0288 4632 Boot (0x1200) (2803b46f5df18da091f65d4be594c259) \Device\Harddisk0\DR0\Partition0 2011/07/17 22:27:25.0306 4632 Boot (0x1200) (4fb4adb0a27f24879c1131c9be8e7897) \Device\Harddisk1\DR1\Partition0 2011/07/17 22:27:25.0320 4632 ================================================================================ 2011/07/17 22:27:25.0320 4632 Scan finished 2011/07/17 22:27:25.0320 4632 ================================================================================ 2011/07/17 22:27:25.0338 4656 Detected object count: 1 2011/07/17 22:27:25.0338 4656 Actual detected object count: 1 2011/07/17 22:27:34.0326 4656 HKLM\SYSTEM\ControlSet001\services\sptd - will be deleted after reboot 2011/07/17 22:27:34.0443 4656 HKLM\SYSTEM\ControlSet002\services\sptd - will be deleted after reboot 2011/07/17 22:27:34.0459 4656 C:\Windows\system32\Drivers\sptd.sys - will be deleted after reboot 2011/07/17 22:27:34.0459 4656 LockedFile.Multi.Generic(sptd) - User select action: Delete 2011/07/17 22:27:41.0581 2756 Deinitialize success
:thumbup:

You where infected with a Rootkit, not nice , make sure you reboot so it can complete its removal



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 11-07-18.01 - Eric 07/18/2011 7:50.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3070.1783 [GMT -4:00] Running from: d:\downloads\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\FREEzeFrog c:\programdata\pNjIbPl08200 c:\programdata\pNjIbPl08200\pNjIbPl08200 c:\programdata\pNjIbPl08200\pNjIbPl08200.exe c:\programdata\xp c:\programdata\xp\EBLib.dll c:\programdata\xp\TPwSav.sys c:\users\Eric\AppData\Roaming\FREEzeFrog c:\users\Eric\AppData\Roaming\Microsoft\Windows\Templates\58buw8x567u4lj0h5muh1i27tls0vo45a5 c:\users\Eric\AppData\Roaming\Microsoft\Windows\Templates\o0r8j32l2vfisvr2oo51y8dg2tk73a7d3r6dbrv6umfu c:\users\Eric\AppData\Roaming\Microsoft\Windows\Templates\w568slnqkb30e8664s56 c:\users\Eric\AppData\Roaming\MSA c:\users\Eric\AppData\Roaming\MSA\userid.dat c:\windows\QMDispatch.dll c:\windows\system32\ezGOSvc.dll c:\windows\system32\no c:\windows\system32\no\toscdspd.cpl.mui c:\windows\system32\SV c:\windows\system32\SV\toscdspd.cpl.mui D:\install.exe D:\Uninstall.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_ezGOSvc . . ((((((((((((((((((((((((( Files Created from 2011-06-18 to 2011-07-18 ))))))))))))))))))))))))))))))) . . 2011-07-18 11:58 . 2011-07-18 12:01 ——– d—–w- c:\users\Eric\AppData\Local\temp 2011-07-18 11:58 . 2011-07-18 11:58 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-07-15 11:07 . 2011-07-15 11:07 ——– d—–w- c:\users\Eric\AppData\Roaming\Malwarebytes 2011-07-15 11:07 . 2011-07-15 11:07 ——– d—–w- c:\programdata\Malwarebytes 2011-07-15 11:07 . 2011-07-06 23:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-07-15 11:07 . 2011-07-06 23:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-07-15 08:01 . 2011-06-07 15:55 7074640 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D8CF1E26-1F2A-4849-8736-1BE45F778946}\mpengine.dll 2011-07-11 23:03 . 2011-07-11 23:03 ——– d—–w- c:\programdata\eMule 2011-07-11 23:00 . 2011-07-11 23:00 ——– d—–w- c:\users\Eric\AppData\Local\eMule 2011-06-29 07:20 . 2011-04-29 14:54 276992 —-a-w- c:\windows\system32\schannel.dll 2011-06-23 12:55 . 2011-06-23 12:55 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-28 20:15 . 2011-06-01 20:57 718208 —-a-w- c:\windows\system32\ezGOSvcApp.exe 2011-05-24 23:14 . 2009-12-21 00:11 222080 ——w- c:\windows\system32\MpSigStub.exe 2011-05-02 15:58 . 2011-06-15 21:26 738816 —-a-w- c:\windows\system32\inetcomm.dll 2011-04-29 12:49 . 2011-06-15 21:26 146432 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-04-29 12:49 . 2011-06-15 21:26 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-04-29 12:49 . 2011-06-15 21:26 213504 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-04-29 12:49 . 2011-06-15 21:26 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-04-29 12:49 . 2011-06-15 21:26 105984 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-21 15:00 . 2011-06-15 21:27 833024 —-a-w- c:\windows\system32\wininet.dll 2011-04-21 14:57 . 2011-06-15 21:27 78336 —-a-w- c:\windows\system32\ieencode.dll 2011-04-21 13:28 . 2011-06-15 21:27 389632 —-a-w- c:\windows\system32\html.iec 2011-04-21 13:16 . 2011-06-15 21:26 273408 —-a-w- c:\windows\system32\drivers\afd.sys 2011-04-21 13:08 . 2011-06-15 21:27 1383424 —-a-w- c:\windows\system32\mshtml.tlb 2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-01-21 213816] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 —-a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 —-a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-18 431456] "HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704] "RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-01 13548064] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-01 92704] "Malwarebytes' Anti-Malware"="d:\malwarebytes' anti-malware\mbamgui.exe" [2011-07-06 449584] . c:\users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk.disabled [2010-11-22 931] OneNote 2007 Screen Clipper and Launcher.lnk.disabled [2010-1-16 1122] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth Manager.lnk.disabled [2010-1-16 821] Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-10-4 805392] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet "Steam"="c:\program files\Steam\Steam.exe" -silent "WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe "EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" -silent "Google Update"="c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe" /c "mscj"=c:\users\eric\appdata\roaming\msa\mscj.exe "mscjm"=c:\users\eric\appdata\roaming\msa\mscjm.exe "ehTray.exe"=c:\windows\ehome\ehTray.exe "ovnmryux"=c:\users\Eric\AppData\Local\Temp\etdowidmo\hokpyhpsjmo.exe "qmffpdbq"=c:\users\Eric\AppData\Local\Temp\stgowhckk\hpdfcoasjmo.exe "AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" "Bkumi"=rundll32.exe "c:\users\Eric\AppData\Local\axamikag.dll",Startup "Ppucoceqozuzeqi"=rundll32.exe "c:\users\Eric\AppData\Local\Qutmsv.dll",Startup "EADM"="c:\program files\Electronic Arts\EADM\EADMUI\EADMUI.exe" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" "SynTPStart"=c:\program files\Synaptics\SynTP\SynTPStart.exe "Windows Mobile-based device management"=%WINDIR%\WindowsMobile\wmdcBase.exe "Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide "SVPWUTIL"=c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" "ITSecMng"=%ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 Apache2.2;Apache2.2;d:\xampp\apache\bin\apache.exe [x] R3 CASprint;Sprint Con App Svc;c:\program files\Sprint\Sprint SmartView\ConAppsSvc.exe [x] R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832] R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys [2010-12-03 25600] R3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\DRIVERS\NwUsbCdFil.sys [2008-10-15 20480] R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2008-10-15 174336] R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960] S2 MBAMService;MBAMService;d:\malwarebytes' anti-malware\mbamservice.exe [2011-07-06 366640] S2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2009-04-26 443712] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr bthsvcs REG_MULTI_SZ BthServ . Contents of the 'Scheduled Tasks' folder . 2011-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2062461591-625251616-2414354262-1000Core.job - c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-28 01:23] . 2011-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2062461591-625251616-2414354262-1000UA.job - c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-28 01:23] . . ——- Supplementary Scan ——- . uStart Page = hxxp://yahoo.com/ uInternet Settings,ProxyOverride = IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\67d86y6d.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 50707 FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Move Media Player: [removed] - c:\users\Eric\AppData\Roaming\Move Networks FF - Ext: XULRunner: {A31FF884-CCFC-4884-8EB3-FD42EEBAA060} - c:\users\Eric\AppData\Local\{A31FF884-CCFC-4884-8EB3-FD42EEBAA060} FF - user.js: yahoo.homepage.dontask - true . - - - - ORPHANS REMOVED - - - - . ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) HKCU-Run-conhost - c:\users\Eric\AppData\Roaming\Microsoft\conhost.exe SafeBoot-21289254.sys AddRemove-Heroes of Might and Magic® III - c:\program files\3DO\Heroes3\Uninst.isu . . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-2062461591-625251616-2414354262-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:37,fb,13,71,61,20,9b,0c,28,58,1e,54,ae,97,aa,e6,5f,90,93,79,c8,97,59, 27,2e,67,54,f5,f9,29,67,19,13,8e,df,08,e9,fc,a7,81,df,17,71,8f,9d,36,a7,c9,\ "??"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb . [HKEY_USERS\S-1-5-21-2062461591-625251616-2414354262-1000\Software\SecuROM\License information*] "datasecu"=hex:78,98,84,31,93,a2,cc,c0,21,79,fb,59,c5,d7,e8,97,8a,41,fa,27,b7, 14,03,d3,a5,5b,8d,a8,18,61,d1,d1,8f,f5,0a,b5,a6,1f,91,1e,f3,02,ce,7d,4f,93,\ "rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(3344) c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe c:\windows\system32\rundll32.exe c:\windows\system32\WLANExt.exe c:\windows\system32\agrsmsvc.exe c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe c:\windows\system32\TODDSrv.exe c:\program files\Toshiba\Power Saver\TosCoSrv.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2011-07-18 08:08:26 - machine was rebooted ComboFix-quarantined-files.txt 2011-07-18 12:08 . Pre-Run: 17,058,594,816 bytes free Post-Run: 16,917,852,160 bytes free . - - End Of File - - 4F52B39CBB74390D241B13FBEA262B95
Hi,

You need to read through what I post, I asked if your browser was being redirected and you never answered, the instructions where to download Combofix to your desktop and you ran it from d:\downloads\ComboFix.exe, so redownload it to your desktop and delete the other one

Backup Your Registry with ERUNT:
  • Download erunt.zip to your Desktop from here:
    http://aumha.org/downloads/erunt.zip
  • Right-click erunt.zip, select Extract All… and follow the prompts to extract ERUNT to a new folder on your Desktop
  • Inside the new folder, double-click ERUNT.exe to start the program
  • OK all the prompts to back up your registry to the default location.
Note: to restore your registry, go to the backup folder and start ERDNT.exe





Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::


File::
c:\users\Eric\AppData\Local\axamikag.dll
c:\users\Eric\AppData\Local\Qutmsv.dll"

Registry:: 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ovnmryux"=-
"qmffpdbq"=-
"Bkumi"=-
"Ppucoceqozuzeqi"=-

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.
Hello,

I haven't had my browser redirected successfully, however, I believe the attempt has been made multiple times. I would get a fake malware removal item in my taskbar with a warning saying the computer was infected. Every time this happened I'd kill the processes that I knew to be fake and the attack would stop and then I would remove the proxy settings from my browsers (no page would load, but I was not actually sent to an unwanted website). This happened maybe once a week. It has not happened since I have been in contact with you, so I am not sure if I am still infected with whatever was causing it.
The processes included a 2nd csrss.exe, a 2nd rundll32.exe and possibly one or two others. If it happens again I'll take better note of what happens. Also, every time it has happened an Acro32 window attempts to open that takes up a lot of my system resources.

I apologize for the failure to follow directions, I will post again in a few minutes with the correct action taken.

ComboFix ran from desktop:

ComboFix 11-07-18.01 - Eric 07/18/2011 13:39:50.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3070.1799 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Eric\AppData\Local\{A31FF884-CCFC-4884-8EB3-FD42EEBAA060}
c:\users\Eric\AppData\Local\{A31FF884-CCFC-4884-8EB3-FD42EEBAA060}\chrome.manifest
c:\users\Eric\AppData\Local\{A31FF884-CCFC-4884-8EB3-FD42EEBAA060}\chrome\content\_cfg.js
c:\users\Eric\AppData\Local\{A31FF884-CCFC-4884-8EB3-FD42EEBAA060}\chrome\content\overlay.xul
c:\users\Eric\AppData\Local\{A31FF884-CCFC-4884-8EB3-FD42EEBAA060}\install.rdf
.
.
((((((((((((((((((((((((( Files Created from 2011-06-18 to 2011-07-18 )))))))))))))))))))))))))))))))
.
.
2011-07-18 17:45 . 2011-07-18 17:46 ——– d—–w- c:\users\Eric\AppData\Local\temp
2011-07-18 17:45 . 2011-07-18 17:45 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2011-07-18 17:45 . 2011-07-18 17:45 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-07-15 11:07 . 2011-07-15 11:07 ——– d—–w- c:\users\Eric\AppData\Roaming\Malwarebytes
2011-07-15 11:07 . 2011-07-15 11:07 ——– d—–w- c:\programdata\Malwarebytes
2011-07-15 11:07 . 2011-07-06 23:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-15 11:07 . 2011-07-06 23:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-07-15 08:01 . 2011-06-07 15:55 7074640 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D8CF1E26-1F2A-4849-8736-1BE45F778946}\mpengine.dll
2011-07-11 23:03 . 2011-07-11 23:03 ——– d—–w- c:\programdata\eMule
2011-07-11 23:00 . 2011-07-11 23:00 ——– d—–w- c:\users\Eric\AppData\Local\eMule
2011-06-29 07:20 . 2011-04-29 14:54 276992 —-a-w- c:\windows\system32\schannel.dll
2011-06-23 12:55 . 2011-06-23 12:55 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-28 20:15 . 2011-06-01 20:57 718208 —-a-w- c:\windows\system32\ezGOSvcApp.exe
2011-05-24 23:14 . 2009-12-21 00:11 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-05-02 15:58 . 2011-06-15 21:26 738816 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 12:49 . 2011-06-15 21:26 146432 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 12:49 . 2011-06-15 21:26 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-29 12:49 . 2011-06-15 21:26 213504 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-29 12:49 . 2011-06-15 21:26 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-29 12:49 . 2011-06-15 21:26 105984 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-21 15:00 . 2011-06-15 21:27 833024 —-a-w- c:\windows\system32\wininet.dll
2011-04-21 14:57 . 2011-06-15 21:27 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-04-21 13:28 . 2011-06-15 21:27 389632 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:16 . 2011-06-15 21:26 273408 —-a-w- c:\windows\system32\drivers\afd.sys
2011-04-21 13:08 . 2011-06-15 21:27 1383424 —-a-w- c:\windows\system32\mshtml.tlb
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-01-21 213816]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-18 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-01 13548064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-01 92704]
"Malwarebytes' Anti-Malware"="d:\malwarebytes' anti-malware\mbamgui.exe" [2011-07-06 449584]
.
c:\users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk.disabled [2010-11-22 931]
OneNote 2007 Screen Clipper and Launcher.lnk.disabled [2010-1-16 1122]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk.disabled [2010-1-16 821]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-10-4 805392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"Steam"="c:\program files\Steam\Steam.exe" -silent
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" -silent
"Google Update"="c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"mscj"=c:\users\eric\appdata\roaming\msa\mscj.exe
"mscjm"=c:\users\eric\appdata\roaming\msa\mscjm.exe
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"ovnmryux"=c:\users\Eric\AppData\Local\Temp\etdowidmo\hokpyhpsjmo.exe
"qmffpdbq"=c:\users\Eric\AppData\Local\Temp\stgowhckk\hpdfcoasjmo.exe
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
"Bkumi"=rundll32.exe "c:\users\Eric\AppData\Local\axamikag.dll",Startup
"Ppucoceqozuzeqi"=rundll32.exe "c:\users\Eric\AppData\Local\Qutmsv.dll",Startup
"EADM"="c:\program files\Electronic Arts\EADM\EADMUI\EADMUI.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
"SynTPStart"=c:\program files\Synaptics\SynTP\SynTPStart.exe
"Windows Mobile-based device management"=%WINDIR%\WindowsMobile\wmdcBase.exe
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"SVPWUTIL"=c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"ITSecMng"=%ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Apache2.2;Apache2.2;d:\xampp\apache\bin\apache.exe [x]
R3 CASprint;Sprint Con App Svc;c:\program files\Sprint\Sprint SmartView\ConAppsSvc.exe [x]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys [2010-12-03 25600]
R3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\DRIVERS\NwUsbCdFil.sys [2008-10-15 20480]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2008-10-15 174336]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S2 MBAMService;MBAMService;d:\malwarebytes' anti-malware\mbamservice.exe [2011-07-06 366640]
S2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2009-04-26 443712]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2062461591-625251616-2414354262-1000Core.job
- c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-28 01:23]
.
2011-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2062461591-625251616-2414354262-1000UA.job
- c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-28 01:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\67d86y6d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50707
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Move Media Player: [removed] - c:\users\Eric\AppData\Roaming\Move Networks
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-18 13:46
Windows 6.0.6001 Service Pack 1 NTFS
.
scanning hidden processes …
.
[0] 0x8B08458B
[0] 0x008B0002
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2062461591-625251616-2414354262-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:37,fb,13,71,61,20,9b,0c,28,58,1e,54,ae,97,aa,e6,5f,90,93,79,c8,97,59,
27,2e,67,54,f5,f9,29,67,19,13,8e,df,08,e9,fc,a7,81,df,17,71,8f,9d,36,a7,c9,\
"??"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_USERS\S-1-5-21-2062461591-625251616-2414354262-1000\Software\SecuROM\License information*]
"datasecu"=hex:78,98,84,31,93,a2,cc,c0,21,79,fb,59,c5,d7,e8,97,8a,41,fa,27,b7,
14,03,d3,a5,5b,8d,a8,18,61,d1,d1,8f,f5,0a,b5,a6,1f,91,1e,f3,02,ce,7d,4f,93,\
"rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-07-18 13:48:05
ComboFix-quarantined-files.txt 2011-07-18 17:48
ComboFix2.txt 2011-07-18 17:28
ComboFix3.txt 2011-07-18 12:08
.
Pre-Run: 17,004,396,544 bytes free
Post-Run: 16,959,119,360 bytes free
.
- - End Of File - - D83C2768D0BB91A689A7F4EAAD8F2FE4
ComboFix with CFScript applied:

ComboFix 11-07-18.01 - Eric 07/18/2011 14:00:55.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3070.1880 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Eric\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Eric\AppData\Local\axamikag.dll"
"c:\users\Eric\AppData\Local\Qutmsv.dll"
.
.
((((((((((((((((((((((((( Files Created from 2011-06-18 to 2011-07-18 )))))))))))))))))))))))))))))))
.
.
2011-07-18 18:06 . 2011-07-18 18:07 ——– d—–w- c:\users\Eric\AppData\Local\temp
2011-07-18 18:06 . 2011-07-18 18:06 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-07-15 11:07 . 2011-07-15 11:07 ——– d—–w- c:\users\Eric\AppData\Roaming\Malwarebytes
2011-07-15 11:07 . 2011-07-15 11:07 ——– d—–w- c:\programdata\Malwarebytes
2011-07-15 11:07 . 2011-07-06 23:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-15 11:07 . 2011-07-06 23:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-07-15 08:01 . 2011-06-07 15:55 7074640 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D8CF1E26-1F2A-4849-8736-1BE45F778946}\mpengine.dll
2011-07-11 23:03 . 2011-07-11 23:03 ——– d—–w- c:\programdata\eMule
2011-07-11 23:00 . 2011-07-11 23:00 ——– d—–w- c:\users\Eric\AppData\Local\eMule
2011-06-29 07:20 . 2011-04-29 14:54 276992 —-a-w- c:\windows\system32\schannel.dll
2011-06-23 12:55 . 2011-06-23 12:55 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-28 20:15 . 2011-06-01 20:57 718208 —-a-w- c:\windows\system32\ezGOSvcApp.exe
2011-05-24 23:14 . 2009-12-21 00:11 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-05-02 15:58 . 2011-06-15 21:26 738816 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 12:49 . 2011-06-15 21:26 146432 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 12:49 . 2011-06-15 21:26 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-29 12:49 . 2011-06-15 21:26 213504 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-29 12:49 . 2011-06-15 21:26 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-29 12:49 . 2011-06-15 21:26 105984 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-21 15:00 . 2011-06-15 21:27 833024 —-a-w- c:\windows\system32\wininet.dll
2011-04-21 14:57 . 2011-06-15 21:27 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-04-21 13:28 . 2011-06-15 21:27 389632 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:16 . 2011-06-15 21:26 273408 —-a-w- c:\windows\system32\drivers\afd.sys
2011-04-21 13:08 . 2011-06-15 21:27 1383424 —-a-w- c:\windows\system32\mshtml.tlb
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-01-21 213816]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-18 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-01 13548064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-01 92704]
"Malwarebytes' Anti-Malware"="d:\malwarebytes' anti-malware\mbamgui.exe" [2011-07-06 449584]
.
c:\users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk.disabled [2010-11-22 931]
OneNote 2007 Screen Clipper and Launcher.lnk.disabled [2010-1-16 1122]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk.disabled [2010-1-16 821]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-10-4 805392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"Steam"="c:\program files\Steam\Steam.exe" -silent
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" -silent
"Google Update"="c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"mscj"=c:\users\eric\appdata\roaming\msa\mscj.exe
"mscjm"=c:\users\eric\appdata\roaming\msa\mscjm.exe
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
"EADM"="c:\program files\Electronic Arts\EADM\EADMUI\EADMUI.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
"SynTPStart"=c:\program files\Synaptics\SynTP\SynTPStart.exe
"Windows Mobile-based device management"=%WINDIR%\WindowsMobile\wmdcBase.exe
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"SVPWUTIL"=c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"ITSecMng"=%ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Apache2.2;Apache2.2;d:\xampp\apache\bin\apache.exe [x]
R3 CASprint;Sprint Con App Svc;c:\program files\Sprint\Sprint SmartView\ConAppsSvc.exe [x]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys [2010-12-03 25600]
R3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\DRIVERS\NwUsbCdFil.sys [2008-10-15 20480]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2008-10-15 174336]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S2 MBAMService;MBAMService;d:\malwarebytes' anti-malware\mbamservice.exe [2011-07-06 366640]
S2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2009-04-26 443712]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2062461591-625251616-2414354262-1000Core.job
- c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-28 01:23]
.
2011-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2062461591-625251616-2414354262-1000UA.job
- c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-28 01:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\67d86y6d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50707
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Move Media Player: [removed] - c:\users\Eric\AppData\Roaming\Move Networks
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-18 14:07
Windows 6.0.6001 Service Pack 1 NTFS
.
scanning hidden processes …
.
[0] 0x65656220
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2062461591-625251616-2414354262-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:37,fb,13,71,61,20,9b,0c,28,58,1e,54,ae,97,aa,e6,5f,90,93,79,c8,97,59,
27,2e,67,54,f5,f9,29,67,19,13,8e,df,08,e9,fc,a7,81,df,17,71,8f,9d,36,a7,c9,\
"??"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_USERS\S-1-5-21-2062461591-625251616-2414354262-1000\Software\SecuROM\License information*]
"datasecu"=hex:78,98,84,31,93,a2,cc,c0,21,79,fb,59,c5,d7,e8,97,8a,41,fa,27,b7,
14,03,d3,a5,5b,8d,a8,18,61,d1,d1,8f,f5,0a,b5,a6,1f,91,1e,f3,02,ce,7d,4f,93,\
"rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(4972)
c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
Completion time: 2011-07-18 14:09:10
ComboFix-quarantined-files.txt 2011-07-18 18:09
ComboFix2.txt 2011-07-18 17:48
ComboFix3.txt 2011-07-18 17:28
ComboFix4.txt 2011-07-18 12:08
.
Pre-Run: 16,880,132,096 bytes free
Post-Run: 16,831,766,528 bytes free
.
- - End Of File - - C386963792347188A2A9F4397F6E238B
Hey,

Missed these, my bad not yours. Thanks for moving Combofix. What were removing is a backdoor trojan that has the capabilities to steal passwords and bank account numbers so keep an eye if you do any online banking, I would go to a known clean computer and change all your passwords for any important sites you frequent that have to do with banking or online shopping

Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Folder::


Folder::
c:\users\eric\appdata\roaming\msa

Registry:: 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"mscj"=-
"mscjm"=-

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.


Let me know how things are running now ?????

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI