This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I stepped in it bad... please help I am dead in the water

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I can usually resolve my problems. I learned to use Malwarebytes, AdAware, and Hijackthis several years ago. However this time something really messed me up. I was online and suddenly the internet stopped working. I tried rebooting and I reset the modem and router. I checked the two other computers on the home network and they are working fine, so something wrecked my machine. It is an HP Pavilion dm4 1165dx. It runs Windows 7 64bit and I am using ie8.
I cannot get online, whatever this is has disabled my wifi radio. It has disabled Norton 360 live. The computer detects no networks.
I tried a system restore and it did restore to earlier this AM but it didn't fix anything. I tried rebooting and hitting esc then I tried to boot Windows from the repair disk I made when I got the computer. It would not work, it says if I have installed some external hardware like a camera or external drive I need to disconnect it and try again, there is nothing connected. I cannot seem to get past this. It did a quick scan and a complete scan with Norton and neither scan found anything wrong. I scanned with Malwarebytes and it found no problems. I scanned with Hijackthis and noticed a bunch of entries with "missing file" listed in the entry. I will include the hijhackthis log here. I copied it to a CD-ROM and will try to post it on this computer (a different laptop).
I checked under programs "turn windows features on or off and these programs are listed as off with whatever subs are under them:
>indexing service
>internet information services
>internet information services Hostable Web Core
>Microsoft Message Queue (MSMQ) Server
>RIP Listener
> Simple Network Management Protocol (SMNP)
>Simple TCIP services (i.e. echo, daytime etc)
>Tablet PC Components
>Telnet Client
>Telnet Server
>TFTP Client
>Windows Process Activation Service
>Windows TIFF IFilter

I don't know if any of that is helpful but thanks for any help. Thankfully, I do a default backup every couple of weeks using the Norton backup.

Here is the Hijackthis logfile… I was not able to update it before I ran it and I apologize if I didn't include something but I cannot get online or do much of anything on the hacked computer.
Thank you so much for the help!!!
Julien


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:44:30 PM, on 9/27/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files (x86)\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\wner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: EgisPBIE - {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisPBIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files (x86)\MasterWriter 2.0\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [VitaKeyTSR] C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe /run
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files (x86)\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\wner\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download all by YouTube Robot - C:\Program Files (x86)\YouTubeRobot\downall.htm
O8 - Extra context menu item: Download by YouTube Robot - C:\Program Files (x86)\YouTubeRobot\downlink.htm
O8 - Extra context menu item: Download with Xilisoft Download YouTube Video - C:\Program Files (x86)\Xilisoft\Download YouTube Video\upod_link.HTM
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted Zone: *.line6.net
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://w4s.work4sure.com/c/ge/w4sgeen9.exe
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s…el_4.4.24.0.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} (SysInfo Class) - http://content.systemrequirementslab.com.s…ri_4.4.26.0.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: CinemaNow Service - CinemaNow, Inc. - C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Red Bend Device Management Service (DMAgent) - Red Bend Ltd. - C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EgisTec Service - Egis Technology Inc. - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NIHardwareService - Native Instruments GmbH - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: USB MIDI Series Audio Device Monitor (USBMIDIAudioDevMon) - M-Audio - C:\Program Files (x86)\M-Audio\USB MIDI Series\AudioDevMon.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Intel® PROSet/Wireless WiMAX Service (WiMAXAppSrv) - Intel® Corporation - C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 13018 bytes
OK…. I am a dummie. I think I am OK and I just had a bad case of "user error". Finally I noticed that the F12 (wireless combo button) was red… I hit it, turned the wireless back on, had Norton fix all the problems and everything looks OK. I can get online but I am still spooked. I slightly tweak W7 for lower latency to use the computer as a DAW with Cakewalk Sonar X1. I would still like someone to take a look at my Hijackthis filelog and I will run it and post another one with the computer working, in case it is different. Sorry for being a doofus but I still appreciate any help and thatk anyone for taking a look. I will come back on the other computer and post another reply with a new logfile for comparison… and again, thanks for taking a quick look and letting me know if anything looks wrong. Julien
I still see a lot of entries with "file missing" and that concerns me. Is it a problem?
Thank you so much.

Julien


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:25:26 PM, on 9/27/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files (x86)\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
C:\Users\wner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: EgisPBIE - {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisPBIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files (x86)\MasterWriter 2.0\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [VitaKeyTSR] C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe /run
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files (x86)\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\wner\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download all by YouTube Robot - C:\Program Files (x86)\YouTubeRobot\downall.htm
O8 - Extra context menu item: Download by YouTube Robot - C:\Program Files (x86)\YouTubeRobot\downlink.htm
O8 - Extra context menu item: Download with Xilisoft Download YouTube Video - C:\Program Files (x86)\Xilisoft\Download YouTube Video\upod_link.HTM
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted Zone: *.line6.net
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://w4s.work4sure.com/c/ge/w4sgeen9.exe
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s…el_4.4.24.0.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} (SysInfo Class) - http://content.systemrequirementslab.com.s…ri_4.4.26.0.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: CinemaNow Service - CinemaNow, Inc. - C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Red Bend Device Management Service (DMAgent) - Red Bend Ltd. - C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EgisTec Service - Egis Technology Inc. - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NIHardwareService - Native Instruments GmbH - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: USB MIDI Series Audio Device Monitor (USBMIDIAudioDevMon) - M-Audio - C:\Program Files (x86)\M-Audio\USB MIDI Series\AudioDevMon.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Intel® PROSet/Wireless WiMAX Service (WiMAXAppSrv) - Intel® Corporation - C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12958 bytes
"file missing" is not a problem, HJT doesn't "see" the files as you are running Win7 64bit system, it's not really designed to run on that system.

I don't see anything obvious in the log, but then, it doesn't do an indepth scan.

If you want to run DDS and aswMBR, I can look over the logs just to make certain




Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
Thanks, I am not sure if I have anything blocking scripts but I disabled panicware popup blocker. I am putting the second (smaler) logfile first. It looks like a lot of stuff, I am not sure if the original HJT logfile is included in the post or not ao I am going to post it as it is. Thanks again, Julien aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-28 10:04:00 —————————– 10:04:00.959 OS Version: Windows x64 6.1.7601 Service Pack 1 10:04:00.959 Number of processors: 4 586 0x2505 10:04:00.959 ComputerName: WNER-HP UserName: wner 10:04:02.550 Initialize success 10:04:24.843 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 10:04:24.843 Disk 0 Vendor: ST950042 0006 Size: 476940MB BusType: 3 10:04:24.858 Disk 0 MBR read successfully 10:04:24.858 Disk 0 MBR scan 10:04:24.858 Disk 0 unknown MBR code 10:04:24.858 Service scanning 10:04:25.919 Modules scanning 10:04:25.919 Disk 0 trace - called modules: 10:04:25.919 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll 10:04:25.919 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80052a6790] 10:04:25.919 3 CLASSPNP.SYS[fffff88001c0143f] -> nt!IofCallDriver -> [0xfffffa8005146b10] 10:04:25.919 5 hpdskflt.sys[fffff88001f81189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004f9d050] 10:04:25.935 Scan finished successfully 10:04:41.582 Disk 0 MBR has been saved successfully to "C:\Users\wner\Desktop\MBR.dat" 10:04:41.582 The log file has been saved successfully to "C:\Users\wner\Desktop\aswMBR.txt" . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 Run by [removed] at 9:59:19 on 2011-09-28 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3894.2108 [GMT -4:00] . AV: Norton Security Suite *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\IDT\WDM\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Hpservice.exe C:\Windows\system32\vcsFPService.exe C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\IDT\WDM\AESTSr64.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\M-Audio\USB MIDI Series\AudioDevMon.exe C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files (x86)\Panicware\Pop-Up Stopper Free Edition\PSFree.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10v_ActiveX.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\servicing\TrustedInstaller.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL BHO: EgisPBIE Class: {7b51ccbe-4af9-44a6-bdab-d7f7e4c4e6f9} - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisPBIE.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - C:\Program Files (x86)\MasterWriter 2.0\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll uRun: [PopUpStopperFreeEdition] "C:\Program Files (x86)\Panicware\Pop-Up Stopper Free Edition\PSFree.exe" uRun: [Google Update] "C:\Users\wner\AppData\Local\Google\Update\GoogleUpdate.exe" /c mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d mRun: [VitaKeyTSR] C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe /run mRun: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Download all by YouTube Robot - C:\Program Files (x86)\YouTubeRobot\downall.htm IE: Download by YouTube Robot - C:\Program Files (x86)\YouTubeRobot\downlink.htm IE: Download with Xilisoft Download YouTube Video - C:\Program Files (x86)\Xilisoft\Download YouTube Video\upod_link.HTM IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll Trusted Zone: line6.net DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - hxxp://w4s.work4sure.com/c/ge/w4sgeen9.exe DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.4.26.0.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{EF3376CF-B65E-4AB4-AD6E-E1D62C3EEACA} : DhcpNameServer = 192.168.1.1 Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll LSA: Notification Packages = EgisPwdFilter EgisDSPwdFilter mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll BHO-X64: Symantec NCO BHO - No File BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL BHO-X64: Symantec Intrusion Prevention - No File BHO-X64: EgisPBIE Class: {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} - C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisPBIE.dll BHO-X64: EgisPBIE - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO-X64: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files (x86)\MasterWriter 2.0\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO-X64: JQSIEStartDetectorImpl - No File TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun-x64: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" mRun-x64: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d mRun-x64: [VitaKeyTSR] C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe /run mRun-x64: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS –> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [?] R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS –> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [?] R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110920.001\BHDrvx64.sys [2011-9-26 1152632] R1 DVMIO;DeviceVM IO Service;C:\Windows\system32\DRIVERS\dvmio.sys –> C:\Windows\system32\DRIVERS\dvmio.sys [?] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110927.030\IDSviA64.sys [2011-9-28 488568] R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS –> C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [?] R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\N360x64\0501000.01D\SYMNETS.SYS –> C:\Windows\system32\Drivers\N360x64\0501000.01D\SYMNETS.SYS [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-7-13 89600] R2 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2010-6-12 400368] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664] R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2010-6-7 408576] R2 EgisTec Service;EgisTec Service;C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe [2010-6-8 697712] R2 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2010-6-8 646000] R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-6-21 85560] R2 HP Wireless Assistant Service;HP Wireless Assistant Service;C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-6-18 103992] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-5-21 103992] R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe –> C:\Windows\system32\Hpservice.exe [?] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-3 13336] R2 N360;Norton Security Suite;C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccsvchst.exe [2011-6-3 130008] R2 NIHardwareService;NIHardwareService;C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2011-4-7 5352960] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264] R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-11-3 2533400] R2 USBMIDIAudioDevMon;USB MIDI Series Audio Device Monitor;C:\Program Files (x86)\M-Audio\USB MIDI Series\AudioDevMon.exe [2010-4-13 1636872] R2 vcsFPService;Validity VCS Fingerprint Service;C:\Windows\System32\vcsFPService.exe [2010-2-23 1799472] R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2010-6-7 911872] R3 bpenum;bpenum;C:\Windows\system32\DRIVERS\bpenum.sys –> C:\Windows\system32\DRIVERS\bpenum.sys [?] R3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\Windows\system32\DRIVERS\bpmp.sys –> C:\Windows\system32\DRIVERS\bpmp.sys [?] R3 bpusb;bpusb;C:\Windows\system32\Drivers\bpusb.sys –> C:\Windows\system32\Drivers\bpusb.sys [?] R3 clwvd;HP Webcam Splitter;C:\Windows\system32\DRIVERS\clwvd.sys –> C:\Windows\system32\DRIVERS\clwvd.sys [?] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-7-27 136824] R3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?] R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys –> C:\Windows\system32\DRIVERS\Impcd.sys [?] R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys –> C:\Windows\system32\DRIVERS\IntcDAud.sys [?] R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys –> C:\Windows\system32\DRIVERS\NETwNs64.sys [?] R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys –> C:\Windows\system32\DRIVERS\Sftfslh.sys [?] R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys –> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?] R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys –> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?] R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys –> C:\Windows\system32\DRIVERS\Sftvollh.sys [?] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys –> C:\Windows\system32\DRIVERS\vwifimp.sys [?] R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys –> C:\Windows\system32\DRIVERS\WDKMD.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 AmUStor;AM USB Stroage Driver;C:\Windows\system32\drivers\AmUStor.SYS –> C:\Windows\system32\drivers\AmUStor.SYS [?] S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys –> C:\Windows\system32\DRIVERS\fssfltr.sys [?] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840] S3 L6TPortB;Service - Line 6 TonePort UX2;C:\Windows\system32\Drivers\L6TPortB64.sys –> C:\Windows\system32\Drivers\L6TPortB64.sys [?] S3 MAUSBMIDI;Service for M-Audio USB MIDI Series;C:\Windows\system32\DRIVERS\MAudioUSBMIDI.sys –> C:\Windows\system32\DRIVERS\MAudioUSBMIDI.sys [?] S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-3-5 340240] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETw5s64.sys –> C:\Windows\system32\DRIVERS\NETw5s64.sys [?] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys –> C:\Windows\system32\DRIVERS\netw5v64.sys [?] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RDID1110;OCTA-CAPTURE;C:\Windows\system32\Drivers\rdwm1110.sys –> C:\Windows\system32\Drivers\rdwm1110.sys [?] S3 rspAux;rspAux;C:\Windows\system32\DRIVERS\rspAux64.sys –> C:\Windows\system32\DRIVERS\rspAux64.sys [?] S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS –> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?] S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS –> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS –> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 US122;US122 Driver;C:\Windows\system32\Drivers\US122x64.sys –> C:\Windows\system32\Drivers\US122x64.sys [?] S3 US122DL;US122 Firmware Downloader;C:\Windows\system32\Drivers\US122DLx64.sys –> C:\Windows\system32\Drivers\US122DLx64.sys [?] S3 US122WdmService;US122 Wdm Audio;C:\Windows\system32\Drivers\US122Wdmx64.sys –> C:\Windows\system32\Drivers\US122Wdmx64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys –> C:\Windows\system32\DRIVERS\yk62x64.sys [?] S3 ZOOM_R16MTR;ZOOM R16_R24 Audio Interface;C:\Windows\system32\Drivers\zmr16usbaudio.sys –> C:\Windows\system32\Drivers\zmr16usbaudio.sys [?] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2011-09-28 13:17:26 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2B738EC8-C986-4FAF-AAD8-4581E5F7E3C7}\offreg.dll 2011-09-28 13:17:24 9049936 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2B738EC8-C986-4FAF-AAD8-4581E5F7E3C7}\mpengine.dll 2011-09-28 00:01:49 ——– d—–w- C:\Users\wner\AppData\Local\{3AEA3672-04A8-48DA-A58F-AA664420DD40} 2011-09-28 00:01:31 ——– d—–w- C:\Users\wner\AppData\Local\{E1AF4C80-D94F-4138-9063-DC67CC3C3B36} 2011-09-26 20:36:26 ——– d—–w- C:\Users\wner\AppData\Local\{2FA9DE3B-E167-46F3-8DD1-5E7402B8B5FB} 2011-09-26 20:36:03 ——– d—–w- C:\Users\wner\AppData\Local\{49E9263E-BF98-417F-BC48-441905092E58} 2011-09-25 20:45:45 ——– d—–w- C:\Users\wner\AppData\Local\{65B6C936-1B08-4530-BA09-64F60CABC21A} 2011-09-25 20:45:34 ——– d—–w- C:\Users\wner\AppData\Local\{3E421741-2FB2-4BD8-9842-871416138A9A} 2011-09-24 15:14:41 ——– d—–w- C:\Users\wner\AppData\Local\{6E6D3DA2-0B5B-4286-BB3D-B4B291265B86} 2011-09-24 15:14:30 ——– d—–w- C:\Users\wner\AppData\Local\{55160276-C21D-4B93-A90D-53E8A2E769F4} 2011-09-24 01:29:58 ——– d—–w- C:\Users\wner\AppData\Local\{302979AE-379A-47E8-87C8-4EF75B3CCD73} 2011-09-24 01:29:35 ——– d—–w- C:\Users\wner\AppData\Local\{A0188919-E77A-464B-B0A2-9A21FB204AD3} 2011-09-23 13:29:08 ——– d—–w- C:\Users\wner\AppData\Local\{149007E5-53FA-4125-878D-9386A9AA646A} 2011-09-23 13:28:57 ——– d—–w- C:\Users\wner\AppData\Local\{EDAEECC5-63B2-4091-A6E2-B260BA6A97BF} 2011-09-23 01:09:51 ——– d—–w- C:\Users\wner\AppData\Local\{F9BA3590-F970-4356-AABA-6EF0965434D0} 2011-09-23 01:09:28 ——– d—–w- C:\Users\wner\AppData\Local\{21774CC1-9891-43C8-9634-2DEC0D07ABAF} 2011-09-22 13:08:49 ——– d—–w- C:\Users\wner\AppData\Local\{DC7CA58C-2644-4FEB-8AEA-872AA0482995} 2011-09-22 13:08:38 ——– d—–w- C:\Users\wner\AppData\Local\{0AE149DA-864D-4CD6-909E-A8DD4B035546} 2011-09-21 23:46:08 ——– d—–w- C:\Users\wner\AppData\Local\{AF2C3FCA-869E-4F05-9F58-E670E5C41602} 2011-09-21 23:45:46 ——– d—–w- C:\Users\wner\AppData\Local\{F5274A57-CD75-46A4-911B-128502F37C0E} 2011-09-21 11:45:19 ——– d—–w- C:\Users\wner\AppData\Local\{D26416DB-8662-4983-A570-0F5C7773E3B8} 2011-09-21 11:45:08 ——– d—–w- C:\Users\wner\AppData\Local\{50BF8721-04CD-4ED3-A6BD-486C89C18DB6} 2011-09-20 15:20:33 ——– d—–w- C:\Users\wner\AppData\Local\{01D4886B-A8C4-430D-9707-E129368004A2} 2011-09-20 15:20:22 ——– d—–w- C:\Users\wner\AppData\Local\{087F0679-CE58-4CA7-AB46-5DB9D2225525} 2011-09-19 22:09:30 ——– d—–w- C:\Users\wner\AppData\Local\{51AFE83C-48D3-4AC1-A92F-7BF095387798} 2011-09-19 22:09:19 ——– d—–w- C:\Users\wner\AppData\Local\{91926045-A4F0-4B5F-A25B-7CB40C5BA14B} 2011-09-19 04:06:10 ——– d—–w- C:\Users\wner\AppData\Local\{C7F5CECB-B836-40B9-9807-9756C14DD227} 2011-09-19 04:05:59 ——– d—–w- C:\Users\wner\AppData\Local\{353D973F-AED0-4723-8888-D1E3C4ACD61B} 2011-09-18 23:02:30 ——– d—–w- C:\Users\wner\AppData\Roaming\FLV Blaster 2011-09-18 22:07:37 ——– d—–w- C:\ProgramData\{D3B41B92-9BC2-43EB-916A-4FA9E8191837} 2011-09-18 12:45:20 ——– d—–w- C:\Users\wner\AppData\Local\Xilisoft 2011-09-18 12:45:10 ——– d—–w- C:\Users\wner\AppData\Roaming\Xilisoft 2011-09-18 12:44:57 ——– d—–w- C:\ProgramData\Xilisoft 2011-09-18 12:44:57 ——– d—–w- C:\Program Files (x86)\Xilisoft 2011-09-18 12:25:39 829781 —-a-w- C:\Windows\SysWow64\xvidcore.dll 2011-09-18 12:25:39 ——– d—–w- C:\Program Files (x86)\ffdshow 2011-09-18 12:25:37 389120 —-a-w- C:\Windows\SysWow64\actskn43.ocx 2011-09-18 12:25:37 ——– d—–w- C:\Program Files (x86)\YouTubeRobot 2011-09-18 12:18:21 ——– d—–w- C:\Users\wner\AppData\Roaming\GetRightToGo 2011-09-18 12:05:57 ——– d—–w- C:\Users\wner\AppData\Local\{9F76439A-3679-4C1B-9DC8-DE50ACF1916E} 2011-09-18 12:05:46 ——– d—–w- C:\Users\wner\AppData\Local\{20A4F641-1D52-4B95-AF72-CF6426A70B23} 2011-09-17 14:10:46 ——– d—–w- C:\Users\wner\AppData\Local\{5B6541AB-9157-44F6-94B8-7CBC6C2314FE} 2011-09-17 14:10:35 ——– d—–w- C:\Users\wner\AppData\Local\{5E0DABAF-272E-495C-9806-756DE57D8A25} 2011-09-16 21:05:27 ——– d—–w- C:\Program Files\iPod 2011-09-16 21:05:26 ——– d—–w- C:\Program Files\iTunes 2011-09-16 21:05:26 ——– d—–w- C:\Program Files (x86)\iTunes 2011-09-16 21:04:57 ——– d—–w- C:\Program Files\Bonjour 2011-09-16 21:04:57 ——– d—–w- C:\Program Files (x86)\Bonjour 2011-09-15 20:42:57 ——– d—–w- C:\Program Files (x86)\Kodak 2011-09-15 13:22:20 ——– d—–w- C:\Users\wner\AppData\Local\{97D6824F-4A18-4D0D-BC37-AFE999B46281} 2011-09-15 13:22:09 ——– d—–w- C:\Users\wner\AppData\Local\{BADAC940-C483-4162-8608-F41AA3DD0D64} 2011-09-15 00:45:48 ——– d—–w- C:\Users\wner\AppData\Local\{D12EC824-0268-4679-A010-AB4834495E91} 2011-09-15 00:45:37 ——– d—–w- C:\Users\wner\AppData\Local\{FF14392E-EC3A-4A37-A5D1-45B0FCC26556} 2011-09-14 00:55:27 ——– d—–w- C:\Users\wner\AppData\Local\{069BFE1E-4F48-4725-AB73-9969FA008D18} 2011-09-14 00:55:16 ——– d—–w- C:\Users\wner\AppData\Local\{C25618AE-DC23-4F4A-BC9B-BCCB3D1865D1} 2011-09-13 12:40:44 49152 —-a-r- C:\Users\wner\AppData\Roaming\Microsoft\Installer\{16F124E1-F72B-4314-8DC6-640A7760FA49}\_810BE3EDCB93_4694_AEE0_8930B5E82C36.exe 2011-09-13 12:40:44 ——– d—–w- C:\Program Files (x86)\Minelab 2011-09-13 01:25:47 ——– d—–w- C:\Users\wner\AppData\Local\{E0818756-03FA-4861-A68E-FE7B58914BDB} 2011-09-13 01:25:24 ——– d—–w- C:\Users\wner\AppData\Local\{3D6D7A98-2BC3-4E84-9751-34B2A3EFEE40} 2011-09-12 13:24:58 ——– d—–w- C:\Users\wner\AppData\Local\{7848CE02-7B4C-4D42-A101-65376961E20C} 2011-09-12 13:24:35 ——– d—–w- C:\Users\wner\AppData\Local\{B35411C4-977A-42DF-9EFC-7F6B1357BD4C} 2011-09-12 01:24:08 ——– d—–w- C:\Users\wner\AppData\Local\{C99E35D6-50E0-4688-A710-1729C8116B7B} 2011-09-12 01:23:57 ——– d—–w- C:\Users\wner\AppData\Local\{8AEC7C6F-51BC-4456-B9BA-E9405DC8C267} 2011-09-10 01:47:32 ——– d—–w- C:\Users\wner\AppData\Local\{A3D48250-25A0-4019-AFDD-7CD089EC63A3} 2011-09-10 01:47:21 ——– d—–w- C:\Users\wner\AppData\Local\{CB84EEA8-DE1D-4CAF-A668-6064CA61DECD} 2011-09-09 11:13:11 ——– d—–w- C:\Users\wner\AppData\Local\{313871DB-7A62-4ADA-89DB-D7A25FC1E875} 2011-09-09 11:12:49 ——– d—–w- C:\Users\wner\AppData\Local\{8AE697FF-9FFE-4DA2-9659-C545ACF9E05F} 2011-09-08 21:11:52 ——– d—–w- C:\Users\wner\AppData\Local\{55753F95-881F-4CB5-AD8D-1A5618BD2683} 2011-09-08 21:11:41 ——– d—–w- C:\Users\wner\AppData\Local\{49425F76-E732-4B4F-A6A2-5D8049E6F230} 2011-09-08 00:09:44 ——– d—–w- C:\Users\wner\AppData\Local\{020B9E5F-F2B1-4963-9E67-25CDDC51DAF7} 2011-09-08 00:09:33 ——– d—–w- C:\Users\wner\AppData\Local\{60F54AB4-7670-498C-8856-DA1F16FA76AC} 2011-09-07 11:18:17 ——– d—–w- C:\Users\wner\AppData\Local\{256EC4D7-00D7-4969-9C4C-CA20C26D8CE2} 2011-09-07 11:18:06 ——– d—–w- C:\Users\wner\AppData\Local\{0F09206B-5785-4C4B-A807-8D1911EE09B1} 2011-09-06 21:37:21 ——– d—–w- C:\Users\wner\AppData\Local\{402D7727-D441-4901-86DD-CC241BC574AC} 2011-09-06 21:37:10 ——– d—–w- C:\Users\wner\AppData\Local\{7FC6C43C-FFEA-47E2-8404-7E4D118E4720} 2011-09-05 16:11:16 45056 —-a-r- C:\Users\wner\AppData\Roaming\Microsoft\Installer\{147567F0-8575-4BE0-B5B3-62706C67FA5A}\ARPPRODUCTICON.exe 2011-09-05 16:07:37 ——– d—–w- C:\Program Files\Toontrack 2011-09-05 14:17:00 ——– d—–w- C:\Users\wner\AppData\Local\{594B74F5-8EBD-48C5-A0F9-A202C487E5F0} 2011-09-05 14:16:49 ——– d—–w- C:\Users\wner\AppData\Local\{E6157AD3-F878-4D40-A858-97F4654373B8} 2011-09-04 04:08:56 ——– d—–w- C:\Users\wner\AppData\Local\{DB45817E-459B-4BE8-9CB4-CF09C5F38E68} 2011-09-04 04:08:45 ——– d—–w- C:\Users\wner\AppData\Local\{785AD367-5BA1-4CFF-9ABA-1B3F8B535304} 2011-09-04 02:02:55 499712 —-a-w- C:\Windows\msvcp71.dll 2011-09-04 02:02:55 348160 —-a-w- C:\Windows\msvcr71.dll 2011-09-04 01:25:45 8862544 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2011-09-03 13:29:00 ——– d—–w- C:\Users\wner\AppData\Local\{F7BA1095-75B0-4440-B0CA-52BFAE6BA83C} 2011-09-03 13:28:38 ——– d—–w- C:\Users\wner\AppData\Local\{60B4B01C-AC6C-4B6B-A0A3-D7235124C91D} 2011-09-02 23:04:46 64 —-a-w- C:\Windows\System32\msvcsv60.dll 2011-09-02 19:50:44 ——– d—–w- C:\Windows\Repair 2011-09-02 19:50:41 ——– d—–w- C:\Users\wner\AppData\Roaming\iS3 2011-09-02 13:30:02 ——– d—–w- C:\Users\wner\AppData\Local\{B8CAA5DE-FF3E-40F0-A904-67B80B4E2BAF} 2011-09-02 13:29:51 ——– d—–w- C:\Users\wner\AppData\Local\{85082FAF-D903-433B-89B7-FC8E740100CF} 2011-09-02 02:12:44 ——– d—–w- C:\Users\wner\AppData\Roaming\4Front 2011-09-01 16:39:53 ——– d—–w- C:\Users\wner\AppData\Local\{97BBD34F-6CE3-472F-911C-7630D4FD3E59} 2011-09-01 16:39:40 ——– d—–w- C:\Users\wner\AppData\Local\{7AE064D7-8BA6-4CA6-96C7-8C4181576ADB} 2011-08-31 02:01:31 ——– d—–w- C:\Users\wner\AppData\Local\{12FA252E-7D83-44D9-98D1-3CAD816BDF18} 2011-08-31 02:01:19 ——– d—–w- C:\Users\wner\AppData\Local\{583E77E7-C648-4F11-B0CE-91EB8B62415B} 2011-08-30 21:37:52 ——– d—–w- C:\ProgramData\Toontrack 2011-08-30 12:28:13 ——– d—–w- C:\Users\wner\AppData\Local\{0D9F8CC3-60B9-451D-8334-30A19B783CD3} 2011-08-30 12:28:02 ——– d—–w- C:\Users\wner\AppData\Local\{5632A9CE-EF8B-4CDE-A673-BD2F0EE6AE1E} 2011-08-29 20:55:13 ——– d—–w- C:\Users\wner\AppData\Local\{86A8825D-7E9E-4E7B-85F3-72DF9A082433} 2011-08-29 20:55:01 ——– d—–w- C:\Users\wner\AppData\Local\{073E6E9D-F725-402F-9803-501AE1BB1413} . ==================== Find3M ==================== . 2011-09-04 02:20:36 64 —-a-w- C:\Users\wner\AppData\Roaming\msregsvv.dll 2011-09-04 02:15:25 64 —-a-w- C:\Windows\SysWow64\msvcsv60.dll 2011-08-17 12:39:08 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-07-22 05:22:26 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2011-07-22 04:54:18 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-07-20 00:39:27 722680 —-a-w- C:\Program Files (x86)\unins001.exe 2011-07-19 09:05:24 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-07-16 05:41:50 362496 —-a-w- C:\Windows\System32\wow64win.dll 2011-07-16 05:41:49 243200 —-a-w- C:\Windows\System32\wow64.dll 2011-07-16 05:41:49 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2011-07-16 05:39:10 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2011-07-16 05:37:12 421888 —-a-w- C:\Windows\System32\KernelBase.dll 2011-07-16 04:29:19 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2011-07-16 04:26:00 44032 —-a-w- C:\Windows\apppatch\acwow64.dll 2011-07-16 04:25:37 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2011-07-16 04:24:23 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2011-07-16 04:24:22 272384 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2011-07-16 02:21:44 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2011-07-16 02:21:41 2048 —-a-w- C:\Windows\SysWow64\user.exe 2011-07-16 02:17:19 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2011-07-16 02:17:19 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 02:17:19 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 02:17:19 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2011-07-12 15:34:00 96104 —-a-w- C:\Windows\System32\dns-sd.exe 2011-07-12 15:34:00 85864 —-a-w- C:\Windows\System32\dnssd.dll 2011-07-12 15:34:00 61288 —-a-w- C:\Windows\System32\jdns_sd.dll 2011-07-12 15:34:00 212840 —-a-w- C:\Windows\System32\dnssdX.dll 2011-07-12 15:20:54 83816 —-a-w- C:\Windows\SysWow64\dns-sd.exe 2011-07-12 15:20:54 73064 —-a-w- C:\Windows\SysWow64\dnssd.dll 2011-07-12 15:20:54 50536 —-a-w- C:\Windows\SysWow64\jdns_sd.dll 2011-07-12 15:20:54 178536 —-a-w- C:\Windows\SysWow64\dnssdX.dll 2011-07-09 05:26:20 2048 —-a-w- C:\Windows\System32\tzres.dll 2011-07-09 04:29:46 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2011-07-09 02:46:28 288768 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-07-08 21:45:12 386168 —-a-w- C:\Windows\System32\drivers\N360x64\0501000.01D\symnets.sys 2011-07-06 23:52:42 41272 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-07-06 23:52:42 25912 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-07-05 22:37:00 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2011-07-05 22:37:00 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2011-05-30 14:02:58 707299 —-a-w- C:\Program Files (x86)\unins000.exe . ============= FINISH: 10:00:03.44 ===============
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-28 10:04:00 —————————– 10:04:00.959 OS Version: Windows x64 6.1.7601 Service Pack 1 10:04:00.959 Number of processors: 4 586 0x2505 10:04:00.959 ComputerName: WNER-HP UserName: wner 10:04:02.550 Initialize success 10:04:24.843 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 10:04:24.843 Disk 0 Vendor: ST950042 0006 Size: 476940MB BusType: 3 10:04:24.858 Disk 0 MBR read successfully 10:04:24.858 Disk 0 MBR scan 10:04:24.858 Disk 0 unknown MBR code 10:04:24.858 Service scanning 10:04:25.919 Modules scanning 10:04:25.919 Disk 0 trace - called modules: 10:04:25.919 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll 10:04:25.919 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80052a6790] 10:04:25.919 3 CLASSPNP.SYS[fffff88001c0143f] -> nt!IofCallDriver -> [0xfffffa8005146b10] 10:04:25.919 5 hpdskflt.sys[fffff88001f81189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004f9d050] 10:04:25.935 Scan finished successfully 10:04:41.582 Disk 0 MBR has been saved successfully to "C:\Users\wner\Desktop\MBR.dat" 10:04:41.582 The log file has been saved successfully to "C:\Users\wner\Desktop\aswMBR.txt" aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-28 10:18:55 —————————– 10:18:55.577 OS Version: Windows x64 6.1.7601 Service Pack 1 10:18:55.577 Number of processors: 4 586 0x2505 10:18:55.577 ComputerName: WNER-HP UserName: wner 10:18:59.852 Initialize success 10:19:39.102 AVAST engine defs: 11092800 10:19:45.233 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 10:19:45.248 Disk 0 Vendor: ST950042 0006 Size: 476940MB BusType: 3 10:19:45.248 Disk 0 MBR read successfully 10:19:45.264 Disk 0 MBR scan 10:19:45.264 Disk 0 unknown MBR code 10:19:45.264 Service scanning 10:19:46.340 Modules scanning 10:19:46.340 Disk 0 trace - called modules: 10:19:46.340 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll 10:19:46.340 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80052a6790] 10:19:46.340 3 CLASSPNP.SYS[fffff88001c0143f] -> nt!IofCallDriver -> [0xfffffa8005146b10] 10:19:46.356 5 hpdskflt.sys[fffff88001f81189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004f9d050] 10:19:51.223 AVAST engine scan C:\Windows 10:19:54.296 AVAST engine scan C:\Windows\system32 10:21:43.933 AVAST engine scan C:\Windows\system32\drivers 10:22:00.110 AVAST engine scan C:\Users\wner 10:25:46.264 Disk 0 MBR has been saved successfully to "C:\Users\wner\Desktop\MBR.dat" 10:25:46.264 The log file has been saved successfully to "C:\Users\wner\Desktop\aswMBR.txt"
All of these type of folders

"C:\Users\wner\AppData\Local\{E0818756-03FA-4861-A68E-FE7B58914BDB}"

are likely all empty

(you will need to show hidden files and folders to see them)

they can be safely deleted as long as they are empty


Nothing obvious in the logs, but run the following online scan just to be certain



Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Thank you Catbyte, I will take a look at the files this weekend while football is on… and I will run the scan. I appreciate your helping me even though my problem was user error. I will remember and I will make a donation and recommend WTT whenever I get the chance. Julien

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI