This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Found Trj/CI.A but can't remove it

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Been trying all the software to try and get rid of this.

Makes mouse stop, freeze, and stutter.
Also a key logger.

Please help me get rid of this.

Thanks
jringo




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:11:48 PM, on 8/21/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe
C:\Users\Dad\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Trend Micro NSC BHO - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1081\TmIEPlg.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: TmBpIeBHO - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: MemberPluginBHO - {C3E5E149-27B7-49D1-8420-B02AC52AF663} - C:\Program Files\MemberPlugin\MemberPlugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Ashampoo Anti-Malware Guard] "C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe"
O4 - HKLM\..\Run: [Quick Heal Core UI] "C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\strtupap.exe"
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab
O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - C:\Program Files\Common Files\BinarySense\hlAPP.dll
O18 - Protocol: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll
O18 - Protocol: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1081\TmIEPlg.dll
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O18 - Protocol: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Ashampoo Anti-Malware Service (AAMWService) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe
O23 - Service: Ashampoo Anti-Malware WSC Service (AAMW_WSC_Service_Vista) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_Vista.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Trend Micro Solution Platform (Amsp) - Trend Micro Inc. - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Core Mail Protection - Unknown owner - C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\EMLPROXY.EXE (file missing)
O23 - Service: Core Scanning Server - Unknown owner - C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE (file missing)
O23 - Service: Core Scanning ServerEx - Unknown owner - C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE (file missing)
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HDDlife HDD Access service - BinarySense, Inc. - C:\Program Files\Common Files\BinarySense\hldasvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NitroPDFDriverCreatorReadSpool (NitroDriverReadSpool) - Nitro PDF Software - C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE
O23 - Service: Online Protection System - Unknown owner - C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\opssvc.exe (file missing)
O23 - Service: Quick Update Service - Unknown owner - C:\PROGRA~1\QUICKH~1\QUICKH~1\quhlpsvc.exe (file missing)
O23 - Service: Quick Heal Helper Service WSC (ScanWscS) - Unknown owner - C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCANWSCS.EXE (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

–
End of file - 7626 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, jringo

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hello there,

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
OTL log
GMER log
Checkup log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
OTL.Txt

OTL logfile created on: 8/22/2011 11:02:15 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\Dad\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.17 Gb Available Physical Memory | 66.84% Memory free
6.50 Gb Paging File | 5.34 Gb Available in Paging File | 82.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.65 Gb Total Space | 26.88 Gb Free Space | 27.53% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 196.17 Gb Free Space | 21.06% Space Free | Partition Type: NTFS
Drive E: | 1299.61 Gb Total Space | 191.50 Gb Free Space | 14.74% Space Free | Partition Type: NTFS
Drive I: | 7.41 Gb Total Space | 0.11 Gb Free Space | 1.47% Space Free | Partition Type: FAT32

Computer Name: DAD-PC | User Name: Dad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Dad\Desktop\OTL.com (OldTimer Tools)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe (Trend Micro Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe (Trend Micro Inc.)
PRC - C:\Program Files\Common Files\BinarySense\hldasvc.exe (BinarySense, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe ()
PRC - C:\Windows\System32\NLSSRV32.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe (Nitro PDF Software)
PRC - C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_Vista.exe ()
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Trend Micro\AMSP\boost_date_time-vc80-mt-1_36.dll ()
MOD - C:\Program Files\Trend Micro\AMSP\boost_thread-vc80-mt-1_36.dll ()
MOD - C:\Program Files\K-Lite Codec Pack\Filters\Haali\splitter.ax ()
MOD - C:\Program Files\K-Lite Codec Pack\Filters\Haali\mkzlib.dll ()
MOD - C:\Program Files\K-Lite Codec Pack\Filters\Haali\mkunicode.dll ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\K-Lite Codec Pack\Filters\mmmpcdmx.ax ()


========== Win32 Services (SafeList) ==========

SRV - (ScanWscS) – File not found
SRV - (Quick Update Service) – File not found
SRV - (Online Protection System) – File not found
SRV - (Core Scanning ServerEx) – File not found
SRV - (Core Scanning Server) – File not found
SRV - (Core Mail Protection) – File not found
SRV - (TeamViewer6) – C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (Amsp) – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe (Trend Micro Inc.)
SRV - (HDDlife HDD Access service) – C:\Program Files\Common Files\BinarySense\hldasvc.exe (BinarySense, Inc.)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (AAMWService) – C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe ()
SRV - (nlsX86cc) – C:\Windows\System32\NLSSRV32.EXE (Nalpeiron Ltd.)
SRV - (NitroDriverReadSpool) – C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe (Nitro PDF Software)
SRV - (AAMW_WSC_Service_Vista) – C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_Vista.exe ()
SRV - (FsUsbExService) – C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)


========== Driver Services (SafeList) ==========

DRV - (mscank) – C:\Windows\system32\DRIVERS\mscank.sys (Quick Heal Technologies (P) Ltd.)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (catflt) – C:\Windows\System32\drivers\catflt.sys (Quick Heal Technologies (P) Ltd.)
DRV - (EMLSS) – C:\Windows\System32\drivers\EMLTDI.SYS (Quick Heal Technologies (P) Ltd.)
DRV - (wsnfmp) – C:\Windows\System32\drivers\wsnf.sys (Quick Heal Technologies (P) Ltd.)
DRV - (wsnf) – C:\Windows\System32\drivers\wsnf.sys (Quick Heal Technologies (P) Ltd.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (ggc) – C:\Windows\System32\drivers\ggc.sys (Quick Heal Technologies (P) Ltd.)
DRV - (tmwfp) – C:\Windows\System32\drivers\tmwfp.sys (Trend Micro Inc.)
DRV - (tmcomm) – C:\Windows\System32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmlwf) – C:\Windows\System32\drivers\tmlwf.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\Windows\System32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (tmactmon) – C:\Windows\System32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) – C:\Windows\System32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (AnyDVD) – C:\Windows\System32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (vmbus) – C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (Lbd) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ASW3Scan) – C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS32.sys ()
DRV - (AAMWRegFilter) – C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter32.sys ()
DRV - (FsUsbExDisk) – C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (31135822) – C:\Windows\system32\DRIVERS\31135822.sys (Kaspersky Lab)
DRV - (setup_9.0.0.722_05.06.2011_18-48drv) – C:\Windows\System32\drivers\3113582.sys (Kaspersky Lab)
DRV - (31135821) – C:\Windows\System32\drivers\31135821.sys (Kaspersky Lab)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (pavboot) – C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (AmdLLD) – C:\Windows\System32\drivers\AmdLLD.sys (AMD, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.inbox.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {22181a4d-af90-4ca3-a569-faed9118d6bc}:3.1.0.1163
FF - prefs.js..extensions.enabledItems: {2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}:2.3.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.7
FF - prefs.js..extensions.enabledItems: [removed]:3.0.122
FF - prefs.js..extensions.enabledItems: {340c2bbc-ce74-4362-90b5-7c26312808ef}:1.7
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: [removed]:0.2.8
FF - prefs.js..extensions.enabledItems: {9c514b53-75f2-4ef2-92fb-53afc819ed8a}:1.1
FF - prefs.js..extensions.enabledItems: [removed]:2.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1
FF - prefs.js..extensions.enabledItems: {cd617375-6743-4ee8-bac4-fbf10f35729e}:2.8.7
FF - prefs.js..extensions.enabledItems: {22C7F6C6-8D67-4534-92B5-529A0EC09405}:6.5.0.1234


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security, S.L.)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Dad\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Dad\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2011/03/07 23:18:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1081\firefoxextension\ [2011/08/16 04:38:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/17 20:23:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/17 20:23:55 | 000,000,000 | —D | M]

[2011/07/31 08:37:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Dad\AppData\Roaming\Mozilla\Extensions
[2011/08/22 22:47:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions
[2011/07/31 09:15:33 | 000,000,000 | —D | M] (Delicious Bookmarks) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}
[2011/07/31 21:24:17 | 000,000,000 | —D | M] (Firefox Sync) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}
[2011/07/31 22:45:03 | 000,000,000 | —D | M] (EpicImageHosting) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\{9c514b53-75f2-4ef2-92fb-53afc819ed8a}
[2011/08/19 04:25:25 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/08/01 05:12:30 | 000,000,000 | —D | M] ("RightToClick") – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}
[2011/07/31 22:45:07 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/07/31 09:15:31 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2011/08/19 04:25:21 | 000,000,000 | —D | M] (Adblock Plus Pop-up Addon) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\[removed]
[2011/08/01 05:12:30 | 000,000,000 | —D | M] (DownThemAll! AntiContainer) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\[removed]
[2011/07/31 09:15:30 | 000,000,000 | —D | M] ("MemberPlugin") – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\[removed]
[2011/08/05 20:07:57 | 000,000,000 | —D | M] (Google Translator for Firefox) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\jorllf9g.default\extensions\[removed]
[2011/07/24 09:15:13 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/07 00:38:32 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/03/07 05:47:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/24 09:15:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/08/16 04:38:28 | 000,000,000 | —D | M] (Trend Micro NSC Firefox Extension) – C:\PROGRAM FILES\TREND MICRO\AMSP\MODULE\20004\1.5.1464\6.6.1081\FIREFOXEXTENSION
[2011/03/07 23:18:26 | 000,000,000 | —D | M] (Trend Micro Toolbar) – C:\PROGRAM FILES\TREND MICRO\TITANIUM\UIFRAMEWORK\TOOLBAR\FIREFOXEXTENSION
[2011/03/17 18:29:27 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/17 18:29:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/03/07 00:37:36 | 000,002,046 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fcmdSrchddr.xml

O1 HOSTS File: ([2011/08/21 08:29:32 | 000,000,808 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1081\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O2 - BHO: (MemberPluginBHO Class) - {C3E5E149-27B7-49D1-8420-B02AC52AF663} - C:\Program Files\MemberPlugin\MemberPlugin.dll (Edward Hibbert ([removed]))
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [Ashampoo Anti-Malware Guard] C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe (Ashampoo Development GmbH & Co. KG)
O4 - HKLM..\Run: [Quick Heal Core UI] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\hddlife {BD758015-47D9-477A-8873-4B688A2BC0E2} - C:\Program Files\Common Files\BinarySense\hlAPP.dll (BinarySense, Inc.)
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1081\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2011/01/24 18:39:55 | 000,000,000 | —D | M] - E:\Autodesk – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: UxTuneUp - C:\Windows\System32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.X264 - C:\Windows\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/08/22 22:59:22 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\Dad\Desktop\OTL.com
[2011/08/22 21:44:24 | 000,000,000 | —D | C] – C:\Program Files\TeamViewer
[2011/08/22 21:42:23 | 003,179,864 | —- | C] (TeamViewer GmbH) – C:\Users\Dad\Desktop\TeamViewer_Setup_en.exe.part
[2011/08/21 06:40:43 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/08/21 00:48:15 | 000,034,112 | —- | C] (Quick Heal Technologies (P) Ltd.) – C:\Windows\System32\drivers\mscank.sys
[2011/08/21 00:48:11 | 000,029,384 | —- | C] (Quick Heal Technologies (P) Ltd.) – C:\Windows\System32\drivers\EMLTDI.SYS
[2011/08/21 00:42:43 | 000,000,000 | —D | C] – C:\Windows\System32\gprodat
[2011/08/21 00:42:23 | 000,046,664 | —- | C] (Quick Heal Technologies (P) Ltd.) – C:\Windows\System32\drivers\ggc.sys
[2011/08/19 19:03:39 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Ashampoo
[2011/08/19 18:56:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
[2011/08/19 18:56:19 | 000,000,000 | —D | C] – C:\Program Files\Ashampoo
[2011/08/18 20:31:10 | 000,000,000 | —D | C] – C:\Users\Dad\DoctorWeb
[2011/08/18 19:52:46 | 000,000,000 | —D | C] – C:\Users\Dad\Desktop\fix_files
[2011/08/18 19:50:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/08/18 19:50:31 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/08/18 19:46:50 | 003,447,576 | —- | C] (Piriform Ltd) – C:\Users\Dad\Desktop\ccsetup309.exe
[2011/08/18 18:19:49 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\Windows\System32\drivers\pavboot.sys
[2011/08/18 18:19:07 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2011/08/17 05:06:23 | 000,000,000 | —D | C] – C:\Users\Dad\Documents\Simply Super Software
[2011/08/17 05:05:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2011/08/17 05:05:00 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ztvcabinet.dll
[2011/08/17 05:04:59 | 000,000,000 | —D | C] – C:\Program Files\Trojan Remover
[2011/08/17 05:04:59 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Simply Super Software
[2011/08/17 05:04:59 | 000,000,000 | —D | C] – C:\ProgramData\Simply Super Software
[2011/08/14 21:10:42 | 000,000,000 | —D | C] – C:\Users\Dad\Desktop\xraypc
[2011/08/14 21:10:07 | 015,338,952 | —- | C] (Microsoft Corporation) – C:\Users\Dad\Desktop\windows-kb890830-v3.22.exe
[2011/08/12 17:26:20 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/08/12 17:26:19 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/08/12 17:26:19 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/08/12 17:26:19 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/08/12 17:26:18 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/08/12 17:20:17 | 003,912,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/08/12 17:20:16 | 003,967,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/08/12 17:20:15 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2011/08/12 17:20:14 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2011/08/12 17:20:14 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2011/08/12 17:20:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/12 17:20:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/12 17:20:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2011/08/12 17:20:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2011/08/12 17:20:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/12 17:20:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/12 17:20:13 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2011/08/12 17:20:13 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/12 17:20:13 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2011/08/12 17:20:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/12 17:20:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/12 17:20:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2011/08/12 17:20:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2011/08/12 17:20:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/12 17:20:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2011/08/12 17:20:12 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcjt32.dll
[2011/08/12 17:20:12 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccu32.dll
[2011/08/12 17:20:12 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccr32.dll
[2011/08/12 17:20:11 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbctrac.dll
[2011/08/12 17:20:11 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2011/08/07 13:46:46 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Samsung
[2011/08/06 14:50:18 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Boilsoft
[2011/08/06 14:21:00 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Nitro PDF
[2011/08/05 17:54:45 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\HandBrake
[2011/08/05 17:12:21 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2011/08/01 05:21:32 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Nero
[2011/08/01 05:20:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Bitdefender
[2011/08/01 05:19:15 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\QuickScan
[2011/08/01 05:03:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
[2011/08/01 05:03:06 | 000,000,000 | —D | C] – C:\Program Files\Nero
[2011/08/01 04:52:51 | 000,000,000 | —D | C] – C:\Users\Dad\Desktop\Words You Should Know In High School
[2011/07/31 12:17:09 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\IrfanView
[2011/07/31 08:37:15 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Mozilla
[2011/07/31 08:34:47 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\PC Suite
[2011/07/31 08:05:14 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\TuneUp Software
[2011/07/31 00:46:13 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\WinRAR
[2011/07/31 00:14:58 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Vso
[2011/07/31 00:12:28 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Media Player Classic
[2011/07/30 23:43:09 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Macromedia
[2011/07/30 23:43:06 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Adobe
[2011/07/30 23:42:58 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Megaupload
[2011/07/30 23:39:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\SUPERAntiSpyware.com
[2011/07/30 23:39:21 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\WinMount
[2011/07/30 21:22:43 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/07/29 18:38:41 | 000,000,000 | —D | C] – C:\Program Files\MakeMKV
[2011/07/24 09:20:55 | 000,000,000 | —D | C] – C:\Program Files\JDownloader
[2011/07/24 09:15:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/07/24 09:15:10 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/07/24 09:15:10 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/07/24 09:15:10 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe

========== Files - Modified Within 30 Days ==========

[2011/08/22 22:59:28 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Dad\Desktop\OTL.com
[2011/08/22 22:52:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-550122737-1337959243-2265725943-1001UA.job
[2011/08/22 22:46:45 | 000,879,225 | —- | M] () – C:\Users\Dad\Desktop\SecurityCheck.exe
[2011/08/22 22:45:35 | 000,302,592 | —- | M] () – C:\Users\Dad\Desktop\GMER.exe
[2011/08/22 22:42:17 | 000,675,834 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/08/22 22:42:17 | 000,126,904 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/08/22 22:40:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/22 22:33:57 | 000,014,544 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/22 22:33:57 | 000,014,544 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/22 22:33:24 | 000,000,876 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/22 22:28:55 | 000,000,302 | -HS- | M] () – C:\Windows\tasks\JRIUWDMI.job
[2011/08/22 22:28:53 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/08/22 22:28:50 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/08/22 21:44:29 | 000,001,120 | —- | M] () – C:\Users\Public\Desktop\TeamViewer 6.lnk
[2011/08/22 21:42:31 | 003,179,864 | —- | M] (TeamViewer GmbH) – C:\Users\Dad\Desktop\TeamViewer_Setup_en.exe.part
[2011/08/22 17:52:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-550122737-1337959243-2265725943-1001Core.job
[2011/08/22 04:34:50 | 000,001,057 | —- | M] () – C:\Users\Dad\AppData\Roaming\vso_ts_preview.xml
[2011/08/21 18:14:57 | 000,002,644 | —- | M] () – C:\Users\Dad\Desktop\hijackthis.zip
[2011/08/21 18:10:49 | 000,001,242 | —- | M] () – C:\Users\Dad\Desktop\HOSTS.lnk
[2011/08/21 17:51:15 | 000,000,040 | -HS- | M] () – C:\ProgramData\.zreglib
[2011/08/21 08:29:32 | 000,000,808 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/08/21 00:52:21 | 000,034,112 | —- | M] (Quick Heal Technologies (P) Ltd.) – C:\Windows\System32\drivers\mscank.sys
[2011/08/21 00:50:19 | 000,006,305 | —- | M] () – C:\Windows\regact.dat
[2011/08/21 00:18:26 | 000,668,252 | —- | M] () – C:\Users\Dad\Desktop\jchiggins_51.pdf
[2011/08/21 00:11:02 | 000,013,721 | —- | M] () – C:\Users\Dad\Desktop\Sears CF Rifles.pdf
[2011/08/20 23:27:43 | 000,350,138 | —- | M] () – C:\Users\Dad\Desktop\JC HIGGINS MODEL 51L BOLT ACTION 30-06 RIFLE.pdf
[2011/08/19 18:56:47 | 000,001,216 | —- | M] () – C:\Users\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Anti-Malware.lnk
[2011/08/19 18:56:46 | 000,001,192 | —- | M] () – C:\Users\Public\Desktop\Ashampoo Anti-Malware.lnk
[2011/08/19 16:47:22 | 000,001,122 | —- | M] () – C:\Users\Dad\Desktop\ActiveScan.zip
[2011/08/18 20:09:40 | 074,975,912 | —- | M] () – C:\Users\Dad\Desktop\drweb-cureit.exe
[2011/08/18 19:52:53 | 000,259,390 | —- | M] () – C:\Users\Dad\Desktop\fix.htm
[2011/08/18 19:52:19 | 000,000,145 | —- | M] () – C:\Users\Dad\Desktop\Fix.url
[2011/08/17 20:11:20 | 000,001,085 | —- | M] () – C:\Users\Dad\Desktop\The Woman 2011 DVDSCR x264 mp3 mitu420 - Shortcut.lnk
[2011/08/17 20:10:52 | 000,001,103 | —- | M] () – C:\Users\Dad\Desktop\Something Borrowed 2011 BRRip XviD-3LT0N - Shortcut.lnk
[2011/08/17 05:05:02 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Trojan Remover.lnk
[2011/08/15 17:15:12 | 000,001,049 | —- | M] () – C:\Users\Dad\Desktop\Earth Girls Are Easy 1988 DvDRiP - Shortcut.lnk
[2011/08/15 17:12:11 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/08/14 21:11:09 | 015,338,952 | —- | M] (Microsoft Corporation) – C:\Users\Dad\Desktop\windows-kb890830-v3.22.exe
[2011/08/14 00:31:29 | 000,000,016 | —- | M] () – C:\Windows\popcinfo.dat
[2011/08/06 15:25:00 | 000,248,005 | —- | M] () – C:\Users\Dad\Desktop\MyHealthMedia - Welcome to Blue Health AssessmentSM.pdf
[2011/08/06 14:21:30 | 000,855,279 | —- | M] () – C:\Users\Dad\Desktop\MyHealthMedia - HealthMedia® BREATHE™.pdf
[2011/08/06 14:16:30 | 002,946,907 | —- | M] () – C:\Users\Dad\Desktop\cravings_takeaction.pdf
[2011/08/05 17:15:54 | 000,388,240 | —- | M] () – C:\Users\Dad\Desktop\1.jdc
[2011/07/31 23:21:01 | 000,001,338 | —- | M] () – C:\Users\Dad\Desktop\Nero Multimedia Suite 10.6.11300 - Shortcut.lnk
[2011/07/31 22:05:40 | 000,001,644 | —- | M] () – C:\Users\Dad\Documents\Firefox Sync Key.html
[2011/07/30 08:24:23 | 000,000,635 | —- | M] () – C:\Users\Dad\Desktop\E B.lnk
[2011/07/26 13:26:41 | 003,447,576 | —- | M] (Piriform Ltd) – C:\Users\Dad\Desktop\ccsetup309.exe

========== Files Created - No Company Name ==========

[2011/08/22 22:46:42 | 000,879,225 | —- | C] () – C:\Users\Dad\Desktop\SecurityCheck.exe
[2011/08/22 22:45:34 | 000,302,592 | —- | C] () – C:\Users\Dad\Desktop\GMER.exe
[2011/08/22 21:44:29 | 000,001,132 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 6.lnk
[2011/08/22 21:44:29 | 000,001,120 | —- | C] () – C:\Users\Public\Desktop\TeamViewer 6.lnk
[2011/08/21 18:14:57 | 000,002,644 | —- | C] () – C:\Users\Dad\Desktop\hijackthis.zip
[2011/08/21 18:10:49 | 000,001,242 | —- | C] () – C:\Users\Dad\Desktop\HOSTS.lnk
[2011/08/21 00:50:19 | 000,006,305 | —- | C] () – C:\Windows\regact.dat
[2011/08/21 00:18:26 | 000,668,252 | —- | C] () – C:\Users\Dad\Desktop\jchiggins_51.pdf
[2011/08/21 00:11:02 | 000,013,721 | —- | C] () – C:\Users\Dad\Desktop\Sears CF Rifles.pdf
[2011/08/20 23:27:40 | 000,350,138 | —- | C] () – C:\Users\Dad\Desktop\JC HIGGINS MODEL 51L BOLT ACTION 30-06 RIFLE.pdf
[2011/08/19 18:56:47 | 000,001,216 | —- | C] () – C:\Users\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Anti-Malware.lnk
[2011/08/19 18:56:46 | 000,001,192 | —- | C] () – C:\Users\Public\Desktop\Ashampoo Anti-Malware.lnk
[2011/08/19 16:47:22 | 000,001,122 | —- | C] () – C:\Users\Dad\Desktop\ActiveScan.zip
[2011/08/18 20:07:14 | 074,975,912 | —- | C] () – C:\Users\Dad\Desktop\drweb-cureit.exe
[2011/08/18 19:52:44 | 000,259,390 | —- | C] () – C:\Users\Dad\Desktop\fix.htm
[2011/08/18 19:51:57 | 000,000,145 | —- | C] () – C:\Users\Dad\Desktop\Fix.url
[2011/08/18 18:18:29 | 000,180,352 | —- | C] () – C:\Users\Dad\Desktop\activescan2_en.exe
[2011/08/17 20:11:20 | 000,001,085 | —- | C] () – C:\Users\Dad\Desktop\The Woman 2011 DVDSCR x264 mp3 mitu420 - Shortcut.lnk
[2011/08/17 20:10:52 | 000,001,103 | —- | C] () – C:\Users\Dad\Desktop\Something Borrowed 2011 BRRip XviD-3LT0N - Shortcut.lnk
[2011/08/17 05:05:02 | 000,001,067 | —- | C] () – C:\Users\Public\Desktop\Trojan Remover.lnk
[2011/08/17 05:05:00 | 000,162,304 | —- | C] () – C:\Windows\System32\ztvunrar36.dll
[2011/08/17 05:05:00 | 000,153,088 | —- | C] () – C:\Windows\System32\UNRAR3.dll
[2011/08/17 05:05:00 | 000,077,312 | —- | C] () – C:\Windows\System32\ztvunace26.dll
[2011/08/17 05:05:00 | 000,075,264 | —- | C] () – C:\Windows\System32\unacev2.dll
[2011/08/15 17:15:12 | 000,001,049 | —- | C] () – C:\Users\Dad\Desktop\Earth Girls Are Easy 1988 DvDRiP - Shortcut.lnk
[2011/08/12 18:27:23 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2011/08/06 15:25:00 | 000,248,005 | —- | C] () – C:\Users\Dad\Desktop\MyHealthMedia - Welcome to Blue Health AssessmentSM.pdf
[2011/08/06 14:21:30 | 000,855,279 | —- | C] () – C:\Users\Dad\Desktop\MyHealthMedia - HealthMedia® BREATHE™.pdf
[2011/08/06 14:16:29 | 002,946,907 | —- | C] () – C:\Users\Dad\Desktop\cravings_takeaction.pdf
[2011/07/31 23:21:07 | 000,001,338 | —- | C] () – C:\Users\Dad\Desktop\Nero Multimedia Suite 10.6.11300 - Shortcut.lnk
[2011/07/31 22:05:21 | 000,001,644 | —- | C] () – C:\Users\Dad\Documents\Firefox Sync Key.html
[2011/07/31 00:14:59 | 000,001,057 | —- | C] () – C:\Users\Dad\AppData\Roaming\vso_ts_preview.xml
[2011/07/30 08:24:40 | 000,000,635 | —- | C] () – C:\Users\Dad\Desktop\E B.lnk
[2011/07/29 17:47:10 | 000,000,900 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-550122737-1337959243-2265725943-1001UA.job
[2011/07/29 17:47:10 | 000,000,848 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-550122737-1337959243-2265725943-1001Core.job
[2011/07/24 09:21:37 | 000,001,912 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2011/07/24 09:21:37 | 000,001,891 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk
[2011/07/24 09:21:37 | 000,001,870 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2011/07/24 04:01:51 | 000,388,240 | —- | C] () – C:\Users\Dad\Desktop\1.jdc
[2011/06/13 01:18:37 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/06/13 01:18:37 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/06/11 09:24:28 | 000,076,288 | —- | C] () – C:\Windows\System32\haspvb32.dll
[2011/06/11 09:24:28 | 000,060,416 | —- | C] () – C:\Windows\System32\record.dll
[2011/05/07 22:09:05 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/04/20 01:21:02 | 000,037,376 | —- | C] () – C:\Windows\System32\atitmpxx.dll
[2011/04/03 17:45:32 | 000,016,968 | —- | C] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2011/03/26 17:25:28 | 000,157,696 | —- | C] () – C:\Windows\System32\_IS_VideoConverterContextMenu.dll
[2011/03/17 17:51:46 | 000,003,929 | —- | C] () – C:\Windows\System32\atipblag.dat
[2011/03/11 23:35:47 | 000,000,082 | —- | C] () – C:\Windows\SuperUtil.ini
[2011/03/11 05:56:51 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2011/03/11 05:55:21 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/03/10 05:22:33 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2011/03/08 19:51:41 | 000,135,680 | —- | C] () – C:\Users\Dad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/08 19:21:46 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/03/08 19:21:45 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/03/08 19:21:41 | 000,810,496 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/03/08 19:21:41 | 000,183,808 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/03/08 19:21:38 | 000,080,896 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/03/08 14:41:06 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2011/03/08 14:41:04 | 000,974,848 | —- | C] () – C:\Windows\System32\cis-2.4.dll
[2011/03/08 14:41:04 | 000,081,920 | —- | C] () – C:\Windows\System32\issacapi_bs-2.3.dll
[2011/03/08 14:41:04 | 000,065,536 | —- | C] () – C:\Windows\System32\issacapi_pe-2.3.dll
[2011/03/08 14:41:04 | 000,057,344 | —- | C] () – C:\Windows\System32\issacapi_se-2.3.dll
[2011/03/07 02:42:35 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/03/07 00:15:09 | 000,110,592 | —- | C] () – C:\Windows\System32\FsUsbExDevice.Dll
[2011/03/07 00:15:09 | 000,036,640 | —- | C] () – C:\Windows\System32\FsUsbExDisk.Sys
[2011/02/28 21:30:06 | 000,233,012 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2010/02/28 11:17:48 | 003,284,480 | —- | C] () – C:\Windows\System32\x264vfw.dll
[2009/09/16 18:27:58 | 000,508,224 | —- | C] () – C:\Windows\System32\ICCProfiles.dll
[2009/07/14 00:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,410,296 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,675,834 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,126,904 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2011/07/03 16:08:31 | 000,001,920 | —- | M] () – C:\aaw7boot.log
[2011/03/07 00:15:00 | 000,002,006 | —- | M] () – C:\aqua_bitmap.cpp
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2011/03/31 19:23:13 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/03/07 02:39:47 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/08/22 22:28:50 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/04/23 09:07:09 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/04/23 09:07:09 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/08/22 22:28:51 | 3488,079,872 | -HS- | M] () – C:\pagefile.sys
[2011/05/15 12:02:52 | 000,066,506 | —- | M] () – C:\TDSSKiller.2.5.1.0_15.05.2011_12.02.00_log.txt
[2011/03/31 19:23:20 | 000,206,312 | RHS- | M] () – C:\XELDZ

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 08:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/08 18:07:06 | 000,000,221 | -HS- | M] () – C:\Users\Dad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/06/28 04:13:32 | 000,180,352 | —- | M] () – C:\Users\Dad\Desktop\activescan2_en.exe
[2011/07/26 13:26:41 | 003,447,576 | —- | M] (Piriform Ltd) – C:\Users\Dad\Desktop\ccsetup309.exe
[2011/08/18 20:09:40 | 074,975,912 | —- | M] () – C:\Users\Dad\Desktop\drweb-cureit.exe
[2011/08/22 22:45:35 | 000,302,592 | —- | M] () – C:\Users\Dad\Desktop\GMER.exe
[2011/06/13 09:45:01 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Dad\Desktop\HijackThis.exe
[2010/12/07 18:05:04 | 002,486,352 | —- | M] (Trend Micro Inc.) – C:\Users\Dad\Desktop\RootkitBuster.exe
[2011/08/22 22:46:45 | 000,879,225 | —- | M] () – C:\Users\Dad\Desktop\SecurityCheck.exe
[2011/08/14 21:11:09 | 015,338,952 | —- | M] (Microsoft Corporation) – C:\Users\Dad\Desktop\windows-kb890830-v3.22.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-13 03:08:54

========== Alternate Data Streams ==========

@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:2BE9FEFC
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:CB0AACC9

< End of report >
Extras.Txt

OTL Extras logfile created on: 8/22/2011 11:02:15 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\Dad\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.17 Gb Available Physical Memory | 66.84% Memory free
6.50 Gb Paging File | 5.34 Gb Available in Paging File | 82.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.65 Gb Total Space | 26.88 Gb Free Space | 27.53% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 196.17 Gb Free Space | 21.06% Space Free | Partition Type: NTFS
Drive E: | 1299.61 Gb Total Space | 191.50 Gb Free Space | 14.74% Space Free | Partition Type: NTFS
Drive I: | 7.41 Gb Total Space | 0.11 Gb Free Space | 1.47% Space Free | Partition Type: FAT32

Computer Name: DAD-PC | User Name: Dad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02FCAA8F-59D3-4198-822E-135C61EE4F0B}" = NeroKwikMedia Help (CHM)
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{11B22822-B350-45BA-AF0F-2EA9A3050126}" = EpicSnapr
"{16987E99-C95C-4513-9239-7B44A0A71DB5}" = Nero SoundTrax 10 Help (CHM)
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1DA193D3-BEC6-4FEF-89E3-D8F739216BFB}_is1" = Ashampoo Anti-Malware 1.21
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F7D9F37-C39C-486C-BDF8-8F440FFB3352}" = Nero Kwik Media
"{23BE4DF2-293D-4077-82F4-1FD8C269277C}" = TuneUp Utilities Language Pack (en-US)
"{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{253AD5C7-94ED-44BF-AA0C-890A80817A87}_is1" = Boilsoft Video Splitter 6.03
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 26
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{329411A0-19F3-4740-874F-17400B126F27}" = Nero Vision 10 Help (CHM)
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{34610DE0-3C13-42CA-8E32-01FFA38AB6E8}" = PC Connectivity Solution
"{353FE16B-30FE-469A-BF55-B978F4218003}" = iTunes
"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40007E5C-19C8-4A25-AD70-A99D77D0A7DA}" = Active Boot Disk
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{58CB9A9A-1EFB-4EA8-B50C-3097E754AC21}" = High-Definition Video Playback
"{5F548A02-80BC-404D-BAE6-F05F9BF6B449}" = Nero DiscCopyGadget 10 Help (CHM)
"{607169F0-07F6-4797-99D2-D5E7C4715E20}" = Mega Manager
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{68AB6930-5BFF-4FF6-923B-516A91984FE6}" = Nero BackItUp 10
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{729D2F8A-A0D8-46CF-9957-BDAAAE9EEDB6}" = Internet Explorer Member Plugin
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{75DEED91-7B14-49DC-A5F3-B60E633AC4A5}" = Quick Heal AntiVirus Pro
"{7A295D8F-484B-4FFB-89AB-C1FD497591FE}" = Nero WaveEditor 10 Help (CHM)
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{82EF29B1-9B60-4142-A155-0599216DD053}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7C5B1ECD-FE93-4FB2-A51A-06451BA49969}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00D1-0409-0000-0000000FF1CE}" = Microsoft Access database engine 2010 (English)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{92EC1A84-7FFC-42DF-A8F6-79C21C4765A5}" = Nero DiscCopy Gadget 10
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
"{9B31BCFA-673F-492E-881B-8DE6D2BCE60F}" = Duplicate File Detective 4
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C4C5A48-E352-4BBA-9D2F-8E7CB85CC63A}" = HDDlife Pro 3.1
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium Maximum Security
"{ABBD4BA9-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro™ Titanium™ Maximum Security
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B93DCF58-AA57-41EC-8D69-B05C66C6312D}_is1" = SUPER © v2011.build.48 (April 23, 2011) version v2011.build.48
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C82185E8-C27B-4EF4-2011-4444BC2C2B6D}" = Microsoft Streets & Trips 2011
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D17111CB-C992-42A9-9D56-C19395102AAA}" = Garmin WebUpdater
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.0.10.324
"{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}" = Nero Recode 10 Help (CHM)
"{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
"{E1FB15E4-E0EC-4C56-8D47-FFF7204C4F0B}" = Nitro PDF Professional
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"1489-3350-5074-6281" = JDownloader 0.9
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"ABC Amber CHM Viewer" = ABC Amber CHM Viewer
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AnyDVD" = AnyDVD
"AviSynth" = AviSynth 2.5
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"Boilsoft Video Joiner_is1" = Boilsoft Video Joiner 5.32
"BurnAware Professional_is1" = BurnAware Professional 3.2
"CCleaner" = CCleaner
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"DAEMON Tools Lite" = DAEMON Tools Lite
"DVD Shrink_is1" = DVD Shrink 3.2
"FairUse Wizard 2" = FairUse Wizard 2
"GoldWave v5.58" = GoldWave v5.58
"HandBrake" = HandBrake 0.9.5
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"IrfanView" = IrfanView (remove only)
"iSkysoft Video Converter_is1" = iSkysoft Video Converter(Build [removed])
"KLiteCodecPack_is1" = K-Lite Codec Pack 7.0.0 (Full)
"MakeMKV" = MakeMKV v1.6.12
"MeGUI" = MeGUI (remove only)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MKVtoolnix" = MKVtoolnix 4.3.0
"Mozilla Firefox (3.6.20)" = Mozilla Firefox (3.6.20)
"Odin Data Recovery Professional_is1" = Odin Data Recovery Professional 6.5.2
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Project Blackout" = Project Blackout
"Quick Heal AntiVirus Pro" = Quick Heal AntiVirus Pro
"Space Plasma 3D Screensaver" = Space Plasma 3D Screensaver (remove only)
"TeamViewer 6" = TeamViewer 6
"Trojan Remover_is1" = Trojan Remover 6.8.2
"TTCO_is1" = Terrorist Takedown Covert Operations
"TuneUp Utilities 2011" = TuneUp Utilities 2011
"uTorrent" = µTorrent
"WinMount Retail zoo_is1" = WinMount V3.5.0114
"WinRAR archiver" = WinRAR archiver
"ZD Soft Screen Recorder" = ZD Soft Screen Recorder 4.1.3.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/18/2011 8:06:22 PM | Computer Name = Dad-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service SAMSUNG KiesAllShare Service since QueryServiceConfig API failed System
Error: The system cannot find the file specified. .

Error - 8/19/2011 6:25:59 PM | Computer Name = Dad-PC | Source = Application Error | ID = 1000
Description = Faulting application name: plugin-container.exe, version: 1.9.2.4232,
time stamp: 0x4e39c2c8 Faulting module name: ntdll.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x000477b2 Faulting
process id: 0xd38 Faulting application start time: 0x01cc5e49981e1e75 Faulting application
path: C:\Program Files\Mozilla Firefox\plugin-container.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: 3633bed4-cab2-11e0-ac12-00241d8ccdd3

Error - 8/21/2011 12:37:16 AM | Computer Name = Dad-PC | Source = Application Error | ID = 1000
Description = Faulting application name: DllHost.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc6b7 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7b96e Exception code: 0xc0000374 Fault offset: 0x000c37b7 Faulting process
id: 0x384 Faulting application start time: 0x01cc5fbbdab411c6 Faulting application
path: C:\Windows\system32\DllHost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: 3edbda5e-cbaf-11e0-aa2b-00241d8ccdd3

Error - 8/21/2011 1:11:27 AM | Computer Name = Dad-PC | Source = System Restore | ID = 8193
Description =

Error - 8/21/2011 8:38:21 AM | Computer Name = Dad-PC | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.1.7601.17567 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: a88 Start
Time: 01cc5ffccd488c51 Termination Time: 19 Application Path: C:\Windows\Explorer.EXE

Report
Id: 4ec129e1-cbf2-11e0-89ea-00241d8ccdd3

Error - 8/21/2011 2:36:18 PM | Computer Name = Dad-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TuneUpUtilitiesService32.exe, version:
10.0.3010.11, time stamp: 0x4d5e6578 Faulting module name: RPCRT4.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7b9a2 Exception code: 0xc0020043 Fault offset: 0x000622d3 Faulting
process id: 0x68c Faulting application start time: 0x01cc6028cb56839a Faulting application
path: C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe Faulting
module path: C:\Windows\system32\RPCRT4.dll Report Id: 75486991-cc24-11e0-89bc-00241d8ccdd3

Error - 8/21/2011 5:49:41 PM | Computer Name = Dad-PC | Source = Application Error | ID = 1000
Description = Faulting application name: ConvertXtoDvd.exe, version: 4.0.10.324,
time stamp: 0x4b8fc849 Faulting module name: ConvertXtoDvd.exe, version: 4.0.10.324,
time stamp: 0x4b8fc849 Exception code: 0xc0000005 Fault offset: 0x0061bb0e Faulting
process id: 0x570 Faulting application start time: 0x01cc60294439de62 Faulting application
path: C:\Program Files\VSO\ConvertX\4\ConvertXtoDvd.exe Faulting module path: C:\Program
Files\VSO\ConvertX\4\ConvertXtoDvd.exe Report Id: 79039a4d-cc3f-11e0-89bc-00241d8ccdd3

Error - 8/22/2011 10:10:58 PM | Computer Name = Dad-PC | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.1.7601.17567 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1198 Start
Time: 01cc6138336b822e Termination Time: 3 Application Path: C:\Windows\Explorer.EXE

Report
Id:

Error - 8/22/2011 11:00:50 PM | Computer Name = Dad-PC | Source = Application Error | ID = 1000
Description = Faulting application name: AAMW_Guard.exe, version: 1.0.0.0, time
stamp: 0x4c76843c Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0x00000000 Fault offset: 0x00000000 Faulting process id: 0xdb4 Faulting application
start time: 0x01cc613d0ab28edf Faulting application path: C:\Program Files\Ashampoo\Ashampoo
Anti-Malware\AAMW_Guard.exe Faulting module path: unknown Report Id: 1b0ac8bd-cd34-11e0-9bc5-00241d8ccdd3

Error - 8/22/2011 11:01:00 PM | Computer Name = Dad-PC | Source = Application Error | ID = 1000
Description = Faulting application name: AAMW_Guard.exe, version: 1.0.0.0, time
stamp: 0x4c76843c Faulting module name: ntdll.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x000470d2 Faulting process
id: 0xdb4 Faulting application start time: 0x01cc613d0ab28edf Faulting application
path: C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe Faulting module
path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 2108d683-cd34-11e0-9bc5-00241d8ccdd3

[ System Events ]
Error - 8/22/2011 10:28:56 PM | Computer Name = Dad-PC | Source = Service Control Manager | ID = 7000
Description = The Core Scanning ServerEx service failed to start due to the following
error: %%2

Error - 8/22/2011 10:28:56 PM | Computer Name = Dad-PC | Source = Service Control Manager | ID = 7000
Description = The Online Protection System service failed to start due to the following
error: %%2

Error - 8/22/2011 10:28:56 PM | Computer Name = Dad-PC | Source = Service Control Manager | ID = 7000
Description = The Quick Update Service service failed to start due to the following
error: %%2

Error - 8/22/2011 10:28:56 PM | Computer Name = Dad-PC | Source = Service Control Manager | ID = 7000
Description = The Quick Heal Helper Service WSC service failed to start due to the
following error: %%2

Error - 8/22/2011 10:29:00 PM | Computer Name = Dad-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SuperMounter

Error - 8/22/2011 10:31:25 PM | Computer Name = Dad-PC | Source = bowser | ID = 8003
Description =

Error - 8/22/2011 10:33:33 PM | Computer Name = Dad-PC | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Provider
Host service which failed to start because of the following error: %%1058

Error - 8/22/2011 10:43:23 PM | Computer Name = Dad-PC | Source = bowser | ID = 8003
Description =

Error - 8/22/2011 10:55:26 PM | Computer Name = Dad-PC | Source = bowser | ID = 8003
Description =

Error - 8/22/2011 11:07:25 PM | Computer Name = Dad-PC | Source = bowser | ID = 8003
Description =


< End of report >
GMER.txt

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-23 04:24:14
Windows 6.1.7601 Service Pack 1 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-3 ST31500341AS rev.CC1H
Running: GMER.exe; Driver: C:\Users\Dad\AppData\Local\Temp\uwldapow.sys


—- System - GMER 1.0.15 —-

SSDT 86840B00 ZwCreateKey
SSDT 86874A60 ZwCreateMutant
SSDT 8683F600 ZwCreateProcess
SSDT 8683F900 ZwCreateProcessEx
SSDT 86874E20 ZwCreateSymbolicLinkObject
SSDT 868743A0 ZwCreateThread
SSDT 86874580 ZwCreateThreadEx
SSDT 8683FC00 ZwCreateUserProcess
SSDT 86841100 ZwDeleteKey
SSDT 86841A00 ZwDeleteValueKey
SSDT 86875000 ZwDuplicateObject
SSDT 86874760 ZwLoadDriver
SSDT 8683FF00 ZwOpenProcess
SSDT 86874020 ZwOpenSection
SSDT 86840200 ZwOpenThread
SSDT 86841400 ZwRenameKey
SSDT 86841700 ZwRestoreKey
SSDT 86874C40 ZwSetSystemInformation
SSDT 86840E00 ZwSetValueKey
SSDT 86840500 ZwTerminateProcess
SSDT 86840800 ZwTerminateThread
SSDT 868741C0 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKey + 13D1 81A4D349 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81A86D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11BF 81A8DE74 4 Bytes [00, 0B, 84, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 81A8DE84 4 Bytes [60, 4A, 87, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11E3 81A8DE98 8 Bytes [00, F6, 83, 86, 00, F9, 83, …]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11FF 81A8DEB4 12 Bytes [20, 4E, 87, 86, A0, 43, 87, …]
.text ntkrnlpa.exe!KeRemoveQueueEx + 121B 81A8DED0 4 Bytes [00, FC, 83, 86]
.text …
.text sptd.sys 8ACA0000 8 Bytes [8E, 6A, E2, 81, A0, 47, E2, …]
.text sptd.sys 8ACA0009 23 Bytes [47, E2, 81, 34, E2, E2, 81, …]
.text sptd.sys 8ACA0024 4 Bytes [44, C5, DC, 8A]
.text sptd.sys 8ACA002C 96 Bytes [85, 74, BD, 81, D8, 7E, A4, …]
.text sptd.sys 8ACA008D 91 Bytes [B5, A4, 81, 15, 65, A4, 81, …]
.text …
.sptd2 C:\Windows\System32\Drivers\sptd.sys entry point in ".sptd2" section [0x8AD7A0AD]
? C:\Windows\System32\Drivers\sptd.sys The process cannot access the file because it is being used by another process.
PAGE PCIIDEX.SYS!DllUnload 8AED7606 5 Bytes JMP 843271C8
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9062B000, 0x38CD55, 0xE8000020]
.text USBPORT.SYS!DllUnload 8FE4FDB9 5 Bytes JMP 854B91C8
.text a4njgpbs.SYS 8FEEC000 52 Bytes [A0, 47, E2, 81, 44, 68, E2, …]
.text a4njgpbs.SYS 8FEEC035 11 Bytes [00, 00, 00, A0, 7E, A4, 81, …]
.text a4njgpbs.SYS 8FEEC041 149 Bytes [0E, A5, 81, 27, 8D, AB, 81, …]
.text a4njgpbs.SYS 8FEEC0D7 32 Bytes [00, 00, 00, 00, 00, 00, 00, …]
.text a4njgpbs.SYS 8FEEC0F8 659 Bytes [48, 0F, 00, 00, 00, 00, 00, …]
.text …

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 84C041E8
Device \FileSystem\fastfat \FatCdrom 86E031E8
Device \Driver\usbuhci \Device\USBPDO-0 854BB1E8
Device \Driver\usbuhci \Device\USBPDO-1 854BB1E8
Device \Driver\usbuhci \Device\USBPDO-2 854BB1E8
Device \Driver\usbehci \Device\USBPDO-3 854B6430
Device \Driver\usbuhci \Device\USBPDO-4 854BB1E8

AttachedDevice \Driver\tdx \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)

Device \Driver\usbuhci \Device\USBPDO-5 854BB1E8
Device \Driver\usbuhci \Device\USBPDO-6 854BB1E8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device \Driver\usbehci \Device\USBPDO-7 854B6430

AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device \Driver\cdrom \Device\CdRom0 85306430
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 84C021E8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-3 84C021E8
Device \Driver\atapi \Device\Ide\IdePort0 84C021E8
Device \Driver\atapi \Device\Ide\IdePort1 84C021E8
Device \Driver\atapi \Device\Ide\IdePort2 84C021E8
Device \Driver\atapi \Device\Ide\IdeDeviceP3T1L0-6 84C021E8
Device \Driver\atapi \Device\Ide\IdePort3 84C021E8
Device \Driver\atapi \Device\Ide\IdePort4 84C021E8
Device \Driver\atapi \Device\Ide\IdePort5 84C021E8
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-4 84C021E8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device \Driver\cdrom \Device\CdRom1 85306430
Device \Driver\cdrom \Device\CdRom2 85306430

AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device \Driver\PCI_PNP4211 \Device\00000067 sptd.sys
Device \Driver\PCI_PNP4211 \Device\00000067 sptd.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export 8542D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{175133B5-D132-493E-9E4E-9DAD88EA3C5A} 8542D1E8
Device \Driver\USBSTOR \Device\00000087 86F6D1E8
Device \Driver\USBSTOR \Device\00000088 86F6D1E8

AttachedDevice \Driver\tdx \Device\Udp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)

Device \Driver\ACPI_HAL \Device\0000005f halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBFDO-0 854BB1E8
Device \Driver\usbuhci \Device\USBFDO-1 854BB1E8
Device \Driver\usbuhci \Device\USBFDO-2 854BB1E8
Device \Driver\usbehci \Device\USBFDO-3 854B6430
Device \Driver\usbuhci \Device\USBFDO-4 854BB1E8
Device \Driver\usbuhci \Device\USBFDO-5 854BB1E8
Device \Driver\usbuhci \Device\USBFDO-6 854BB1E8
Device \Driver\usbehci \Device\USBFDO-7 854B6430
Device \Driver\a4njgpbs \Device\Scsi\a4njgpbs1 855241E8
Device \Driver\a4njgpbs \Device\Scsi\a4njgpbs1Port6Path0Target0Lun0 855241E8
Device \FileSystem\fastfat \Fat 86E031E8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD7 0xA1 0x6C 0xA6 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x9B 0x86 0xC0 0x7C …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x0B 0xB6 0x20 0xEB …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD7 0xA1 0x6C 0xA6 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x9B 0x86 0xC0 0x7C …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x0B 0xB6 0x20 0xEB …

—- Files - GMER 1.0.15 —-

File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00111.log 1048576 bytes

—- EOF - GMER 1.0.15 —-
checkup.txt

Results of screen317's Security Check version 0.99.18
Windows 7 Service Pack 1 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Quick Heal AntiVirus Pro
Trend Micro Titanium Maximum Security
Trend Micro™ Titanium™ Maximum Security
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
SUPERAntiSpyware
Trojan Remover 6.8.2
TuneUp Utilities 2011
TuneUp Utilities Language Pack (en-US)
TuneUp Utilities 2011
CCleaner
Java™ 6 Update 26
Out of date Java installed!
Adobe Flash Player 10.3.183.5
````````````````````````````````
Process Check:
objlist.exe by Laurent

Trend Micro AMSP coreServiceShell.exe
Trend Micro AMSP coreFrameworkHost.exe
``````````End of Log````````````

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI