This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Data Restore Trojan and Browser Redirect Infection

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys, I was infected with a Data Restore trojan on Friday. I tried fixing it myself by running RFIX and then doing a MalwareBytes Anti-Malware (logfile pasted at bottom of this post) scan. I also ran Windows Defender and deleted 1 thing that it found as well as Microsoft Security Essentials and deleted/quaranted a few things that it found (Exact details at bottom of this post).

At this point I've gotten rid of the Data Restore and the task manager blocker but I am still getting browser redirects and my assistant informed me that randomly this morning while I was away from the office sounds of a porno started playing on my computer. She said there were no browsers open or anything but just the sound of a porn video playing.

I've run OTL and for some reason it doesn't give me the extras.txt only the OTL.txt logfile. I've triple checked to make sure I followed the instructions on this site and I still only get the OTL.txt logfile.

Here are the results from OTL.txt:

OTL logfile created on: 10/12/2011 1:19:48 PM - Run 3
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\AustinGood\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.63 Gb Available Physical Memory | 40.86% Memory free
9.77 Gb Paging File | 6.61 Gb Available in Paging File | 67.71% Paging File free
Paging file location(s): c:\pagefile.sys 6000 10000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 586.40 Gb Total Space | 390.06 Gb Free Space | 66.52% Space Free | Partition Type: NTFS
Drive I: | 7.55 Gb Total Space | 5.98 Gb Free Space | 79.15% Space Free | Partition Type: FAT32

Computer Name: STUDY-PC | User Name: AustinGood | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\AustinGood\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
PRC - c:\xampp\mysql\bin\mysqld.exe ()
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
PRC - C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
PRC - C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
PRC - C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
PRC - C:\Windows\SysWOW64\ASTSRV.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\mHotkey.exe ()
PRC - C:\Windows\CNYHKey.exe (Creative)
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
PRC - C:\Windows\ChiFuncExt.exe (Chicony)
PRC - C:\Program Files (x86)\Portrait Displays\Pivot Software\Floater.exe ()
PRC - C:\Program Files (x86)\Portrait Displays\Pivot Software\wpCtrl.exe ()
PRC - C:\Windows\ModLEDKey.exe (Chicony)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Windows\mHotkey.exe ()
MOD - C:\Program Files (x86)\Portrait Displays\Pivot Software\Floater.exe ()
MOD - C:\Program Files (x86)\Portrait Displays\Pivot Software\wpCtrl.exe ()
MOD - C:\Program Files (x86)\Portrait Displays\Pivot Software\Winphook.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (Ati External Event Utility) – C:\Windows\SysNative\Ati2evxx.exe (ATI Technologies Inc.)
SRV:64bit: - (LPDSVC) – C:\Windows\SysNative\lpdsvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (yksvc) – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Secunia)
SRV - (mysql) – c:\xampp\mysql\bin\mysqld.exe ()
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (FileZilla Server) – c:\xampp\FileZillaFTP\FileZillaServer.exe (FileZilla Project)
SRV - (AffinegyService) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (QBCFMonitorService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (PDFProFiltSrvPP) – C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (BrYNSvc) – C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (astcc) – C:\Windows\SysWOW64\ASTSRV.EXE (Nalpeiron Ltd.)
SRV - (QBFCService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IntuitUpdateService) – C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (UpdateCenterService) – C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe (NVIDIA)
SRV - (nTuneService) – C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (DTSRVC) – C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
SRV - (PdiService) – C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\DRIVERS\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (PSI) – C:\Windows\SysNative\DRIVERS\psi_mf.sys (Secunia)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (swmsflt) – C:\Windows\SysNative\drivers\swmsflt.sys ()
DRV:64bit: - (RTL8187B) – C:\Windows\SysNative\DRIVERS\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\DRIVERS\agrsm64.sys (Agere Systems)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (yukonx64) – C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\DRIVERS\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\SysNative\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV:64bit: - (PdiPorts) – C:\Windows\SysNative\DRIVERS\PdiPorts.sys (Portrait Displays, Inc.)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\Drivers\RootMdm.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\DRIVERS\serscan.sys (Microsoft Corporation)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\DRIVERS\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (SWUMX80) Sierra Wireless USB MUX Driver (UMTS80) – C:\Windows\SysNative\DRIVERS\swumx80.sys (Sierra Wireless Inc.)
DRV:64bit: - (SWNC8U80) Sierra Wireless MUX NDIS Driver (UMTS80) – C:\Windows\SysNative\DRIVERS\swnc8u80.sys (Sierra Wireless Inc.)
DRV:64bit: - (AmdLLD64) – C:\Windows\SysNative\DRIVERS\AmdLLD64.sys (AMD, Inc.)
DRV - (NVR0FLASHDev) – C:\Windows\nvflsh64.sys (NVIDIA Corp.)
DRV - (NVR0Dev) – C:\Windows\nvoclk64.sys (NVIDIA Corp.)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…amp;m=dx4200-09
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…amp;m=dx4200-09
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…amp;m=dx4200-09

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE9MSE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?ocid=OIE9MSE
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 174.154.23.32:8080

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/09/16 15:02:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/30 11:15:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/21 17:02:49 | 000,000,000 | —D | M]

[2011/10/11 16:49:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/10/11 16:49:47 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/09/30 11:15:30 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/11 16:49:10 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/11 08:46:16 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Windows\system32\TVUAx\npTVUAx.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2010/12/22 11:59:08 | 000,001,245 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AMD_Display] File not found
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [BrStsWnd] C:\Program Files (x86)\Brownie\BrstsW64.exe (brother)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DT GWY] C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [EarthLink Installer] " /C File not found
O4 - HKLM..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [LchDrvKey] C:\Windows\LchDrvKey.exe ()
O4 - HKLM..\Run: [LedKey] C:\Windows\CNYHKey.exe (Creative)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PivotSoftware] C:\Program Files (x86)\Portrait Displays\Pivot Software\wpctrl.exe ()
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Smart Copy] "C:\Program Files (x86)\IOI\Smart Copy\ButtonMonitor.exe" -A File not found
O4 - HKCU..\Run: [nXBPpaqQtFIXr.exe] C:\ProgramData\nXBPpaqQtFIXr.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O8:64bit: - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O9 - Extra Button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files (x86)\iMacros\imacros.dll File not found
O9 - Extra 'Tools' menuitem : iMacros Web Automation - {0483894E-2422-45E0-8384-021AFF1AF3CD} - Reg Error: Value error. File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/x64/RACtrl.cab (Performance Viewer Activex Control)
O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} https://qbo.intuit.com/c28/v33.140/qboax10.cab (QuickBooks Online Edition Utilities Class v10)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8D59819B-2067-4A6B-84F4-7F84570E3C30} http://192.168.2.9/img/LinksysMLViewer.cab (LinksysMLViewer Control)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab (RIM AxLoader)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O16 - DPF: RemotePrintControlCab https://payrollapp.com/@57128e25-bfc9-4da2-…tControlCab.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6B246598-B8E6-4703-8960-9F176263D458}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BD38625B-63C6-4A92-B2D5-85C65B5FE397}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\intu-help-qb3 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.XVID - xvidvfw.dll ()
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.mjpg - C:\Windows\SysWow64\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/10/12 13:17:24 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Users\AustinGood\Desktop\OTL.exe
[2011/10/11 17:42:27 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/10/11 17:42:26 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/10/11 17:42:26 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/10/11 17:42:26 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/10/11 17:42:26 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/11 17:42:26 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/11 17:42:26 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/10/11 17:42:26 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/10/11 17:42:26 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/10/11 17:42:26 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/10/11 17:42:26 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/10/11 17:42:26 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/10/11 17:42:26 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/10/11 17:42:26 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/10/11 17:42:26 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/10/11 17:42:25 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/10/11 17:42:25 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/11 17:42:25 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/10/11 17:42:25 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/10/11 17:42:25 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/10/11 17:42:25 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/10/11 17:42:25 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/10/11 17:42:25 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/10/11 17:42:25 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/10/11 17:42:25 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/10/11 17:42:25 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\advpack.dll
[2011/10/11 17:42:25 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/10/11 17:42:25 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/10/11 17:42:25 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/10/11 17:42:25 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/11 17:42:25 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/10/11 17:42:25 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/10/11 17:42:25 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/10/11 17:42:24 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/11 17:42:24 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/11 17:42:24 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/10/11 17:42:24 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/11 17:42:24 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/10/11 17:42:24 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/10/11 17:42:24 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/10/11 17:42:24 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/10/11 17:42:24 | 000,145,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/10/11 17:42:24 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\advpack.dll
[2011/10/11 17:42:24 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/10/11 17:42:24 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/10/11 17:42:24 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/10/11 17:42:24 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/10/11 17:42:24 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/10/11 17:42:24 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/10/11 17:42:24 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/10/11 17:42:24 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/10/11 17:42:24 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/10/11 17:42:23 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/10/11 17:42:23 | 001,492,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/10/11 17:42:23 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/10/11 17:42:23 | 000,603,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/10/11 17:42:23 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/10/11 17:42:23 | 000,452,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/10/11 17:42:23 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/10/11 17:42:23 | 000,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/10/11 17:42:23 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/11 17:42:23 | 000,165,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2011/10/11 17:42:23 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/10/11 17:42:23 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/10/11 17:42:23 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/11 17:42:23 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/10/11 17:42:23 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/10/11 17:42:23 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/10/11 17:42:23 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/10/11 17:42:23 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/10/11 17:42:23 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/10/11 17:42:22 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/10/11 17:42:22 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/10/11 17:42:22 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/10/11 17:32:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2011/10/11 17:30:46 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/10/11 17:20:19 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/10/11 17:14:19 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/11 17:14:18 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/11 17:14:18 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/10/11 17:14:18 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/10/11 17:14:18 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/10/11 17:14:18 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/10/11 17:10:42 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/11 17:10:42 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/11 17:10:42 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/11 17:10:42 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/11 17:10:42 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/11 17:10:42 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/10/11 17:10:42 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/11 17:10:42 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/11 16:50:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/10/11 16:49:43 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/10/11 16:49:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/10/11 16:49:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/10/11 16:39:53 | 000,190,752 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysNative\javaws.exe
[2011/10/11 16:39:53 | 000,171,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysNative\javaw.exe
[2011/10/11 16:39:53 | 000,171,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysNative\java.exe
[2011/10/11 16:39:33 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/10/11 16:31:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apache HTTP Server 2.2
[2011/10/11 16:31:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apache Software Foundation
[2011/10/11 16:28:04 | 000,000,000 | —D | C] – C:\Users\AustinGood\Desktop\AdobeIllustrator_15.0.2
[2011/10/11 13:19:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/10/11 12:52:44 | 000,000,000 | —D | C] – C:\Users\AustinGood\AppData\Local\Secunia PSI
[2011/10/11 12:52:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Secunia
[2011/10/10 20:11:50 | 001,558,832 | —- | C] (Kaspersky Lab ZAO) – C:\Users\AustinGood\Desktop\TDSSKiller.exe
[2011/10/06 08:45:03 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2011/10/06 08:45:03 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2011/10/06 08:45:03 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2011/10/06 08:45:03 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2011/10/06 08:45:03 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_7.dll
[2011/10/06 08:45:03 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_7.dll
[2011/10/06 08:45:03 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2011/10/06 08:45:03 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2011/10/06 08:45:02 | 002,401,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_43.dll
[2011/10/06 08:45:02 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_43.dll
[2011/10/06 08:45:02 | 001,907,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_43.dll
[2011/10/06 08:45:02 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_43.dll
[2011/10/06 08:45:02 | 000,511,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_43.dll
[2011/10/06 08:45:02 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_43.dll
[2011/10/06 08:45:02 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2011/10/06 08:45:02 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2011/10/06 08:45:01 | 000,530,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_6.dll
[2011/10/06 08:45:01 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_6.dll
[2011/10/06 08:45:01 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_6.dll
[2011/10/06 08:45:01 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_6.dll
[2011/10/06 08:45:01 | 000,078,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_4.dll
[2011/10/06 08:45:01 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_4.dll
[2011/10/06 08:45:01 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_7.dll
[2011/10/06 08:45:01 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_7.dll
[2011/10/06 08:45:00 | 002,582,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_42.dll
[2011/10/06 08:45:00 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_42.dll
[2011/10/06 08:45:00 | 000,517,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_5.dll
[2011/10/06 08:45:00 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2011/10/06 08:45:00 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_5.dll
[2011/10/06 08:45:00 | 000,176,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_5.dll
[2011/10/06 08:44:25 | 005,554,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_42.dll
[2011/10/06 08:44:25 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_42.dll
[2011/10/06 08:44:24 | 002,475,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_42.dll
[2011/10/06 08:44:24 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_42.dll
[2011/10/06 08:44:24 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2011/10/06 08:44:24 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2011/10/06 08:44:24 | 000,285,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_42.dll
[2011/10/06 08:44:24 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_42.dll
[2011/10/06 08:44:23 | 005,425,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_41.dll
[2011/10/06 08:44:23 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_41.dll
[2011/10/06 08:44:23 | 002,430,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_41.dll
[2011/10/06 08:44:23 | 001,846,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_41.dll
[2011/10/06 08:44:23 | 000,520,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_41.dll
[2011/10/06 08:44:23 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_41.dll
[2011/10/06 08:44:22 | 002,605,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_40.dll
[2011/10/06 08:44:22 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_40.dll
[2011/10/06 08:44:22 | 000,521,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_4.dll
[2011/10/06 08:44:22 | 000,519,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_40.dll
[2011/10/06 08:44:22 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_4.dll
[2011/10/06 08:44:22 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_40.dll
[2011/10/06 08:44:22 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_4.dll
[2011/10/06 08:44:22 | 000,174,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_4.dll
[2011/10/06 08:44:22 | 000,073,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_3.dll
[2011/10/06 08:44:22 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2011/10/06 08:44:22 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_6.dll
[2011/10/06 08:44:22 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_6.dll
[2011/10/06 08:44:21 | 005,631,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_40.dll
[2011/10/06 08:44:21 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2011/10/06 08:44:20 | 000,518,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_3.dll
[2011/10/06 08:44:20 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_3.dll
[2011/10/06 08:44:20 | 000,074,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_2.dll
[2011/10/06 08:44:20 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_2.dll
[2011/10/06 08:44:19 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_3.dll
[2011/10/06 08:44:19 | 000,175,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_3.dll
[2011/10/06 08:44:18 | 000,513,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_2.dll
[2011/10/06 08:44:18 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2011/10/06 08:44:18 | 000,072,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_1.dll
[2011/10/06 08:44:18 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2011/10/06 08:44:18 | 000,025,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_5.dll
[2011/10/06 08:44:18 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_5.dll
[2011/10/06 08:44:17 | 001,942,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_39.dll
[2011/10/06 08:44:17 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2011/10/06 08:44:17 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_39.dll
[2011/10/06 08:44:17 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2011/10/06 08:44:17 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_2.dll
[2011/10/06 08:44:17 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_2.dll
[2011/10/06 08:44:16 | 004,992,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_39.dll
[2011/10/06 08:44:16 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2011/10/06 08:44:16 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_1.dll
[2011/10/06 08:44:16 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_1.dll
[2011/10/06 08:44:16 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_0.dll
[2011/10/06 08:44:16 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_0.dll
[2011/10/06 08:44:15 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_38.dll
[2011/10/06 08:44:15 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_38.dll
[2011/10/06 08:44:15 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_38.dll
[2011/10/06 08:44:15 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_38.dll
[2011/10/06 08:44:15 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_1.dll
[2011/10/06 08:44:15 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_1.dll
[2011/10/06 08:44:15 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_4.dll
[2011/10/06 08:44:15 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_4.dll
[2011/10/06 08:44:14 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_38.dll
[2011/10/06 08:44:14 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_38.dll
[2011/10/06 08:44:12 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2011/10/06 08:44:12 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2011/10/06 08:44:11 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2011/10/06 08:44:11 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2011/10/06 08:44:11 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2011/10/06 08:44:11 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2011/10/06 08:44:11 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2011/10/06 08:44:11 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2011/10/06 08:44:11 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2011/10/06 08:44:11 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2011/10/06 08:44:10 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2011/10/06 08:44:10 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2011/10/06 08:40:19 | 000,000,000 | —D | C] – C:\Windows\SysWow64\directx
[2011/09/21 17:06:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/09/21 17:05:39 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/09/21 17:05:35 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/09/21 17:05:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/09/21 17:02:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/09/18 15:15:41 | 000,000,000 | —D | C] – C:\Users\AustinGood\AppData\Local\TVU Networks
[2011/09/18 15:15:41 | 000,000,000 | —D | C] – C:\ProgramData\TVU Networks
[2011/09/18 15:15:07 | 000,000,000 | —D | C] – C:\Windows\SysWow64\TVUAx
[2011/09/15 18:57:04 | 000,000,000 | —D | C] – C:\Users\AustinGood\Documents\OneNote Notebooks
[2011/09/15 18:56:17 | 000,000,000 | —D | C] – C:\ProgramData\{B97DFD11-B924-4789-BD74-F21A0C10B0BF}
[2011/09/15 18:51:18 | 000,000,000 | —D | C] – C:\ProgramData\{2C9DBDBB-2D80-410C-8699-A38A9E6168ED}
[2011/09/15 18:51:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stamps.com
[2011/09/15 18:50:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Stamps.com Internet Postage
[2011/09/15 18:48:32 | 000,000,000 | —D | C] – C:\Users\AustinGood\AppData\Local\Seven Zip
[2011/09/13 15:17:53 | 000,000,000 | —D | C] – C:\Users\AustinGood\Documents\My PaperPort Documents
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/12 13:21:04 | 000,000,906 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/12 13:21:04 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/12 13:17:41 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Users\AustinGood\Desktop\OTL.exe
[2011/10/12 13:16:24 | 000,000,501 | —- | M] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\The Good Home Team - Shortcut (2).lnk
[2011/10/12 12:58:32 | 000,000,336 | —- | M] () – C:\Windows\BRCALIB.INI
[2011/10/12 12:47:41 | 000,002,617 | —- | M] () – C:\Users\AustinGood\Desktop\Microsoft Office Outlook 2007.lnk
[2011/10/12 12:30:10 | 000,000,479 | —- | M] () – C:\Windows\Brownie.ini
[2011/10/12 12:25:03 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2011/10/12 12:24:59 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/12 12:24:59 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/12 12:24:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/12 12:24:01 | 4294,107,136 | -HS- | M] () – C:\hiberfil.sys
[2011/10/11 17:52:56 | 000,000,935 | —- | M] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/10/11 17:49:24 | 005,026,336 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/11 17:42:43 | 000,008,798 | —- | M] () – C:\Windows\SysWow64\icrav03.rat
[2011/10/11 17:42:43 | 000,008,798 | —- | M] () – C:\Windows\SysNative\icrav03.rat
[2011/10/11 17:42:43 | 000,001,988 | —- | M] () – C:\Windows\SysWow64\ticrf.rat
[2011/10/11 17:42:43 | 000,001,988 | —- | M] () – C:\Windows\SysNative\ticrf.rat
[2011/10/11 17:42:27 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/10/11 17:42:26 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/10/11 17:42:26 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/10/11 17:42:26 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/10/11 17:42:26 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/11 17:42:26 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/11 17:42:26 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/10/11 17:42:26 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/10/11 17:42:26 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/10/11 17:42:26 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/10/11 17:42:26 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/10/11 17:42:26 | 000,072,822 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2011/10/11 17:42:26 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/10/11 17:42:26 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/10/11 17:42:26 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/10/11 17:42:26 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/10/11 17:42:25 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/10/11 17:42:25 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/11 17:42:25 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/10/11 17:42:25 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/10/11 17:42:25 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/10/11 17:42:25 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/10/11 17:42:25 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/10/11 17:42:25 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/10/11 17:42:25 | 000,123,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/10/11 17:42:25 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/10/11 17:42:25 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\advpack.dll
[2011/10/11 17:42:25 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/10/11 17:42:25 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/10/11 17:42:25 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/10/11 17:42:25 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/11 17:42:25 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/10/11 17:42:25 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/10/11 17:42:25 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/10/11 17:42:24 | 002,309,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/11 17:42:24 | 000,818,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/11 17:42:24 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/10/11 17:42:24 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/11 17:42:24 | 000,222,208 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/10/11 17:42:24 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/10/11 17:42:24 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/10/11 17:42:24 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/10/11 17:42:24 | 000,145,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/10/11 17:42:24 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\advpack.dll
[2011/10/11 17:42:24 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/10/11 17:42:24 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/10/11 17:42:24 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/10/11 17:42:24 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/10/11 17:42:24 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/10/11 17:42:24 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/10/11 17:42:24 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/10/11 17:42:24 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/10/11 17:42:24 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/10/11 17:42:23 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/10/11 17:42:23 | 001,492,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/10/11 17:42:23 | 000,697,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/10/11 17:42:23 | 000,603,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/10/11 17:42:23 | 000,534,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/10/11 17:42:23 | 000,452,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/10/11 17:42:23 | 000,448,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/10/11 17:42:23 | 000,282,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/10/11 17:42:23 | 000,237,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/11 17:42:23 | 000,165,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2011/10/11 17:42:23 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/10/11 17:42:23 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/10/11 17:42:23 | 000,096,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/11 17:42:23 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/10/11 17:42:23 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/10/11 17:42:23 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/10/11 17:42:23 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/10/11 17:42:23 | 000,072,822 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2011/10/11 17:42:23 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/10/11 17:42:23 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/10/11 17:42:22 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/10/11 17:42:22 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/10/11 17:42:22 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/10/11 17:32:34 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2011/10/11 17:32:14 | 000,852,178 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/10/11 17:32:14 | 000,696,072 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/10/11 17:32:14 | 000,142,018 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/10/11 17:22:33 | 000,848,962 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/11 17:12:50 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2011/10/11 17:07:52 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/11 16:49:10 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2011/10/11 16:49:10 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/10/11 16:49:10 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/10/11 16:49:10 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/10/11 16:39:36 | 000,525,544 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysNative\deployJava1.dll
[2011/10/11 16:39:36 | 000,190,752 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysNative\javaws.exe
[2011/10/11 16:39:36 | 000,171,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysNative\javaw.exe
[2011/10/11 16:39:36 | 000,171,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysNative\java.exe
[2011/10/11 16:31:18 | 000,001,247 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
[2011/10/11 14:56:47 | 000,000,501 | —- | M] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\The Good Home Team - Shortcut.lnk
[2011/10/11 13:19:34 | 000,001,987 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/10/11 13:19:34 | 000,001,971 | —- | M] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/11 12:56:10 | 000,000,862 | —- | M] () – C:\Users\AustinGood\Desktop\Mozilla Firefox.lnk
[2011/10/11 12:52:32 | 000,000,903 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/10/11 11:00:28 | 000,684,297 | —- | M] () – C:\Users\AustinGood\Desktop\unhide.exe
[2011/10/10 20:11:53 | 001,558,832 | —- | M] (Kaspersky Lab ZAO) – C:\Users\AustinGood\Desktop\TDSSKiller.exe
[2011/10/10 20:05:58 | 001,008,092 | —- | M] () – C:\Users\AustinGood\Desktop\iExplore.exe
[2011/10/06 09:55:15 | 000,087,456 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIRfsClientNP.dll
[2011/10/06 09:55:14 | 000,080,768 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIinit.dll
[2011/10/04 16:52:23 | 000,000,000 | —- | M] () – C:\Users\AustinGood\Documents\Nuance Image Printer Writer Port
[2011/09/21 17:06:03 | 000,001,656 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/09/19 10:08:38 | 000,000,855 | —- | M] () – C:\Windows\Brpfx04a.ini
[2011/09/16 15:03:01 | 000,001,891 | —- | M] () – C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2011/09/16 11:33:08 | 000,000,036 | —- | M] () – C:\Windows\SysWow64\f9t.dat
[2011/09/15 18:53:33 | 000,000,879 | —- | M] () – C:\Users\Public\Desktop\Stamps.com.lnk
[2011/09/15 10:32:29 | 000,002,539 | —- | M] () – C:\Users\AustinGood\Desktop\Microsoft Office Publisher 2007.lnk
[2011/09/13 17:09:17 | 000,001,721 | —- | M] () – C:\Users\Public\Desktop\REDX Lead Manager.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/12 13:16:24 | 000,000,501 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\The Good Home Team - Shortcut (2).lnk
[2011/10/11 17:52:39 | 000,000,941 | —- | C] () – C:\Users\AustinGood\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/10/11 17:42:26 | 000,072,822 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2011/10/11 17:42:23 | 000,072,822 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2011/10/11 17:32:34 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2011/10/11 17:30:52 | 000,001,810 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/10/11 17:12:50 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/10/11 16:31:18 | 000,001,247 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
[2011/10/11 14:56:47 | 000,000,501 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\The Good Home Team - Shortcut.lnk
[2011/10/11 13:19:34 | 000,001,987 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/10/11 13:19:34 | 000,001,971 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/11 13:16:35 | 000,000,906 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/11 13:16:22 | 000,000,902 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/11 12:56:10 | 000,000,862 | —- | C] () – C:\Users\AustinGood\Desktop\Mozilla Firefox.lnk
[2011/10/11 12:52:32 | 000,000,903 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/10/11 12:52:32 | 000,000,866 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2011/10/11 12:47:43 | 000,002,617 | —- | C] () – C:\Users\AustinGood\Desktop\Microsoft Office Outlook 2007.lnk
[2011/10/11 12:08:56 | 000,002,543 | —- | C] () – C:\Users\Public\Desktop\DocuSign Professional.lnk
[2011/10/11 12:08:56 | 000,002,531 | —- | C] () – C:\Users\Public\Desktop\TurboTax Business 2010.lnk
[2011/10/11 12:08:56 | 000,002,020 | —- | C] () – C:\Users\Public\Desktop\DocuSign Member Console.lnk
[2011/10/11 12:08:56 | 000,001,771 | —- | C] () – C:\Users\Public\Desktop\zipForm® 6.lnk
[2011/10/11 12:08:56 | 000,001,721 | —- | C] () – C:\Users\Public\Desktop\REDX Lead Manager.lnk
[2011/10/11 12:08:56 | 000,001,656 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/11 12:08:56 | 000,000,972 | —- | C] () – C:\Users\Public\Desktop\Pinnacle VideoSpin.lnk
[2011/10/11 12:08:56 | 000,000,932 | —- | C] () – C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2011/10/11 12:08:56 | 000,000,879 | —- | C] () – C:\Users\Public\Desktop\Stamps.com.lnk
[2011/10/11 12:08:56 | 000,000,850 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/11 12:08:55 | 000,001,891 | —- | C] () – C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2011/10/11 12:08:55 | 000,000,843 | —- | C] () – C:\Users\Public\Desktop\Avidemux 2.5.lnk
[2011/10/11 12:08:52 | 000,001,804 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/11 12:08:52 | 000,000,970 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/10/11 12:08:52 | 000,000,935 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/10/11 12:08:52 | 000,000,930 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/10/11 12:08:52 | 000,000,461 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Real Estate - Shortcut.lnk
[2011/10/11 12:08:52 | 000,000,461 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Real Estate - Shortcut (3).lnk
[2011/10/11 12:08:52 | 000,000,461 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Real Estate - Shortcut (2).lnk
[2011/10/11 12:08:52 | 000,000,258 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/10/11 12:08:52 | 000,000,240 | —- | C] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/10/11 12:08:45 | 000,001,194 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2011/10/11 12:08:39 | 000,002,449 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
[2011/10/11 12:08:39 | 000,002,437 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
[2011/10/11 12:08:39 | 000,001,950 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Photo Gallery.lnk
[2011/10/11 12:08:39 | 000,001,894 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetZero Internet.lnk
[2011/10/11 12:08:39 | 000,001,852 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Collaboration.lnk
[2011/10/11 12:08:39 | 000,001,830 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/10/11 12:08:39 | 000,001,803 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/10/11 12:08:39 | 000,001,770 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Calendar.lnk
[2011/10/11 12:08:39 | 000,001,768 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker.lnk
[2011/10/11 12:08:39 | 000,001,757 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Defender.lnk
[2011/10/11 12:08:39 | 000,001,743 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2011/10/11 12:08:39 | 000,001,743 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Contacts.lnk
[2011/10/11 12:08:39 | 000,001,738 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Journal.lnk
[2011/10/11 12:08:39 | 000,001,638 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sticky Notes.lnk
[2011/10/11 12:08:39 | 000,001,635 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EarthLink TotalAccess.lnk
[2011/10/11 12:08:39 | 000,001,630 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/10/11 12:08:39 | 000,001,435 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CS5.lnk
[2011/10/11 12:08:39 | 000,001,312 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2011/10/11 12:08:39 | 000,001,150 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.lnk
[2011/10/11 12:08:39 | 000,001,059 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.lnk
[2011/10/11 12:08:39 | 000,001,009 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady 7.0.lnk
[2011/10/11 12:08:39 | 000,001,004 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 7.0.lnk
[2011/10/11 12:08:39 | 000,000,966 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk
[2011/10/11 12:08:39 | 000,000,866 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2011/10/11 12:08:39 | 000,000,862 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/10/11 12:08:39 | 000,000,813 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn.lnk
[2011/10/11 11:00:30 | 000,684,297 | —- | C] () – C:\Users\AustinGood\Desktop\unhide.exe
[2011/10/10 20:05:53 | 001,008,092 | —- | C] () – C:\Users\AustinGood\Desktop\iExplore.exe
[2011/09/19 10:09:21 | 000,000,000 | —- | C] () – C:\Users\AustinGood\Documents\Nuance Image Printer Writer Port
[2011/09/15 18:50:12 | 000,000,036 | —- | C] () – C:\Windows\SysWow64\f9t.dat
[2011/09/06 10:11:32 | 000,000,855 | —- | C] () – C:\Windows\Brpfx04a.ini
[2011/09/06 10:11:32 | 000,000,159 | —- | C] () – C:\Windows\brpcfx.ini
[2011/09/06 10:11:09 | 000,000,336 | —- | C] () – C:\Windows\BRCALIB.INI
[2011/09/06 10:09:24 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2011/09/06 10:09:24 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2011/09/06 10:09:15 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\BRTCPCON.DLL
[2011/08/26 13:51:40 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2011/06/05 16:33:19 | 000,645,632 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/06/05 16:33:19 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/03/18 15:40:23 | 000,197,956 | —- | C] () – C:\Windows\SysWow64\mlfcache.dat
[2010/12/17 18:26:20 | 000,003,619 | —- | C] () – C:\Windows\cdplayer.ini
[2010/12/17 18:22:05 | 000,001,302 | —- | C] () – C:\ProgramData\ss.ini
[2010/11/23 18:39:17 | 000,023,744 | —- | C] () – C:\Documents and Settings\ReleaseEngineer.MACROVISION\Application Data\Comma Separated Values (Windows).ADR
[2010/09/05 19:21:26 | 000,000,335 | —- | C] () – C:\Windows\mozregistry.dat
[2010/04/22 14:26:16 | 000,033,998 | —- | C] () – C:\Windows\MAXLINK.INI
[2010/01/25 12:58:06 | 000,462,848 | —- | C] () – C:\Windows\SysWow64\ractrlkeyhook.dll
[2010/01/06 12:09:10 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2010/01/06 12:08:48 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2010/01/06 12:08:27 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/10/07 15:59:25 | 000,000,411 | —- | C] () – C:\Windows\ODBCINST.INI
[2009/09/11 10:52:10 | 000,000,091 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2009/09/09 18:29:40 | 000,000,062 | —- | C] () – C:\Windows\Personal Logger.INI
[2009/07/29 15:49:06 | 000,000,256 | —- | C] () – C:\Windows\SysWow64\pool.bin
[2009/07/23 17:25:40 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\libssl32.dll
[2009/06/29 15:25:01 | 000,016,384 | —- | C] () – C:\Windows\SysWow64\FileOps.exe
[2009/06/17 11:13:30 | 000,508,224 | —- | C] () – C:\Windows\SysWow64\ICCProfiles.dll
[2009/05/19 13:04:39 | 000,000,098 | —- | C] () – C:\Users\AustinGood\AppData\Local\fusioncache.dat
[2009/05/19 12:34:51 | 000,852,178 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/05/07 14:22:27 | 000,000,072 | —- | C] () – C:\Windows\SysWow64\bd2170w.dat
[2009/05/07 14:05:05 | 000,000,114 | —- | C] () – C:\Windows\SysWow64\brlmw03a.ini
[2009/05/06 16:52:35 | 000,000,472 | —- | C] () – C:\Windows\BRWMARK.INI
[2009/05/06 16:50:14 | 000,000,012 | —- | C] () – C:\Windows\BRVIDEO.INI
[2009/05/06 16:50:14 | 000,000,000 | —- | C] () – C:\Windows\brmx2001.ini
[2009/05/06 16:49:25 | 000,000,479 | —- | C] () – C:\Windows\Brownie.ini
[2009/04/17 10:38:56 | 000,199,834 | —- | C] () – C:\Users\AustinGood\AppData\Local\adCenterExcelAddin.config
[2009/03/02 01:46:51 | 000,000,248 | —- | C] () – C:\Windows\wininit.ini
[2009/02/27 18:10:08 | 000,122,880 | —- | C] () – C:\Users\AustinGood\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/25 21:32:17 | 000,000,680 | —- | C] () – C:\Users\AustinGood\AppData\Local\d3d9caps.dat
[2009/02/25 21:29:29 | 000,000,732 | —- | C] () – C:\Users\AustinGood\AppData\Local\d3d9caps64.dat
[2009/02/25 20:05:04 | 000,002,304 | —- | C] () – C:\Windows\SysWow64\Machnm32.sys
[2009/02/24 09:45:14 | 000,000,662 | —- | C] () – C:\Windows\nsreg.dat
[2009/01/19 06:16:35 | 000,581,120 | —- | C] () – C:\Windows\mHotkey.exe
[2009/01/19 06:16:35 | 000,294,912 | —- | C] () – C:\Windows\PIC.dll
[2009/01/19 06:16:35 | 000,036,864 | —- | C] () – C:\Windows\LchDrvKey.exe
[2009/01/19 06:16:35 | 000,000,870 | —- | C] () – C:\Windows\mhotkey_reg.ini
[2009/01/19 06:09:20 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2008/11/03 15:56:52 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/11/03 15:19:12 | 003,107,788 | —- | C] () – C:\Windows\SysWow64\atiumdva.dat
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/06/05 09:58:26 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/04/12 00:38:10 | 000,114,688 | —- | C] () – C:\Windows\SysWow64\myodbc3i.exe
[2008/04/12 00:38:10 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\myodbc3m.exe
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/12/11 04:09:11 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\IPPCallAnalysis5.dll
[2007/01/26 01:04:12 | 000,138,752 | —- | C] () – C:\Windows\SysWow64\mase32.dll
[2007/01/26 01:04:12 | 000,027,648 | —- | C] () – C:\Windows\SysWow64\ma32.dll
[2006/11/02 10:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2005/03/29 00:58:20 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\ssleay32.dll
[2005/03/29 00:58:10 | 000,847,872 | —- | C] () – C:\Windows\SysWow64\libeay32.dll
[1998/12/08 19:09:44 | 000,338,944 | —- | C] () – C:\Windows\SysWow64\lffpx7.dll
[1998/12/08 19:09:44 | 000,122,880 | —- | C] () – C:\Windows\SysWow64\LFKODAK.DLL
[1998/12/08 19:09:44 | 000,088,576 | —- | C] () – C:\Windows\SysWow64\lffpx90n.dll
[1996/04/01 12:00:00 | 000,000,200 | —- | C] () – C:\Windows\SysWow64\CAPTURE2.INI

========== LOP Check ==========

[2011/10/12 10:07:50 | 000,032,570 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/03/03 20:51:35 | 000,001,024 | —- | M] () – C:\.rnd
[2009/05/25 14:28:09 | 000,000,020 | -HS- | M] () – C:\ArcDeviceInfo
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/11/03 15:21:30 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2011/07/07 14:41:58 | 000,000,264 | —- | M] () – C:\dscript.log
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/10/12 12:24:01 | 4294,107,136 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/11/03 16:39:31 | 000,000,165 | —- | M] () – C:\Labelprint.log
[2008/11/03 16:43:39 | 000,000,106 | —- | M] () – C:\ms.log
[2005/09/23 03:39:38 | 000,894,976 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/10/12 12:23:59 | 1996,488,703 | -HS- | M] () – C:\pagefile.sys
[2008/04/08 16:46:34 | 000,007,163 | —- | M] () – C:\pdiports.cat
[2008/04/08 16:46:14 | 000,002,853 | —- | M] () – C:\pdiports64.inf
[2009/02/25 20:04:28 | 000,000,173 | —- | M] () – C:\pdisdk.log
[2009/02/25 20:05:05 | 000,000,184 | —- | M] () – C:\pivot.log
[2009/01/19 06:11:50 | 000,000,838 | —- | M] () – C:\RHDSetup.log
[2011/10/10 20:07:41 | 000,000,262 | —- | M] () – C:\rkill.log
[2010/01/29 16:06:23 | 000,026,503 | —- | M] () – C:\spi.scanning.log
[2011/10/10 20:15:15 | 000,139,870 | —- | M] () – C:\TDSSKiller.2.6.7.0_10.10.2011_20.12.45_log.txt
[2011/10/11 12:46:13 | 000,001,904 | —- | M] () – C:\TDSSKiller.2.6.7.0_11.10.2011_12.46.09_log.txt
[2011/10/11 12:47:10 | 000,070,870 | —- | M] () – C:\TDSSKiller.2.6.7.0_11.10.2011_12.46.25_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/05/03 15:27:17 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 22:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2009/09/09 11:59:07 | 000,944,892 | —- | M] () – C:\Program Files (x86)\dtmf_input.txt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/10/11 17:52:56 | 000,000,574 | -HS- | M] () – C:\Users\AustinGood\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/06/20 17:30:13 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\AustinGood\Desktop\HiJackThis.exe
[2011/10/10 20:05:58 | 001,008,092 | —- | M] () – C:\Users\AustinGood\Desktop\iExplore.exe
[2011/10/12 13:17:41 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Users\AustinGood\Desktop\OTL.exe
[2011/10/10 20:11:53 | 001,558,832 | —- | M] (Kaspersky Lab ZAO) – C:\Users\AustinGood\Desktop\TDSSKiller.exe
[2011/10/11 11:00:28 | 000,684,297 | —- | M] () – C:\Users\AustinGood\Desktop\unhide.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:DFC5A2B2

< End of report >


I then ran Hijackthis and came up with the following hijackthis.txt logfile:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:43:30 PM, on 10/12/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\MHotKey.exe
C:\Windows\CNYHKey.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\wpCtrl.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\floater.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\ModLedKey.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
C:\Windows\ChiFuncExt.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\AustinGood\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…amp;m=dx4200-09
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…amp;m=dx4200-09
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 174.154.23.32:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [LchDrvKey] LchDrvKey.exe
O4 - HKLM\..\Run: [LedKey] CNYHKey.exe
O4 - HKLM\..\Run: [Smart Copy] "C:\Program Files (x86)\IOI\Smart Copy\ButtonMonitor.exe" -A
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files (x86)\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [DT GWY] "C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe" -GWY
O4 - HKLM\..\Run: [BrStsWnd] "C:\Program Files (x86)\Brownie\BrstsW64.exe" Autorun
O4 - HKLM\..\Run: [EarthLink Installer] " /C
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [InstaLAN] "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort12reminder] "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFHook] C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe
O4 - HKLM\..\Run: [PDF5 Registry Controller] C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe
O4 - HKLM\..\Run: [ControlCenter4] "C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe" /autorun
O4 - HKLM\..\Run: [BrStsMon00] "C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [nXBPpaqQtFIXr.exe] C:\ProgramData\nXBPpaqQtFIXr.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: Open with PDF Viewer Plus - res://C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files (x86)\iMacros\imacros.dll (file missing)
O9 - Extra 'Tools' menuitem: iMacros Web Automation - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files (x86)\iMacros\imacros.dll (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: iMacros 7 - {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: iMacros Web Automation - {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: RemotePrintControlCab - https://payrollapp.com/@57128e25-bfc9-4da2-…tControlCab.CAB
O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} (QuickBooks Online Edition Utilities Class v10) - https://qbo.intuit.com/c28/v33.140/qboax10.cab
O16 - DPF: {8D59819B-2067-4A6B-84F4-7F84570E3C30} (LinksysMLViewer Control) - http://192.168.2.9/img/LinksysMLViewer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} (RIM AxLoader) - http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apache2.2 - Apache Software Foundation - C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\ASTSRV.EXE
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - c:\xampp\FileZillaFTP\FileZillaServer.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - c:\xampp\mysql\bin\mysqld.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)

–
End of file - 14268 bytes

Here is the DDS Log:

.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 18:17:26.02 on Fri 10/14/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.1962 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\taskeng.exe
C:\Windows\MHotKey.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
C:\Windows\system32\agr64svc.exe
C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\Windows\SysWOW64\ASTSRV.EXE
C:\Windows\ChiFuncExt.exe
C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
C:\Windows\System32\svchost.exe -k LPDService
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
c:\xampp\mysql\bin\mysqld.exe
C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Windows\system32\RUNDLL32.EXE
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\mobsync.exe
C:\Windows\CNYHKey.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\wpCtrl.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\floater.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
C:\Windows\ModLedKey.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Browny02\BrYNSvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\explorer.exe
C:\Windows\sysWow64\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\AustinGood\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer, optimized for Bing and MSN
mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&s;=1&o;=vp64&d;=0109&m;=dx4200-09
mDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&s;=1&o;=vp64&d;=0109&m;=dx4200-09
uInternet Settings,ProxyServer = [removed]:8080
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - No File
TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
uRun: [nXBPpaqQtFIXr.exe] C:\ProgramData\nXBPpaqQtFIXr.exe
mRun: [LchDrvKey] LchDrvKey.exe
mRun: [LedKey] CNYHKey.exe
mRun: [Smart Copy] "C:\Program Files (x86)\IOI\Smart Copy\ButtonMonitor.exe" -A
mRun: [PivotSoftware] "C:\Program Files (x86)\Portrait Displays\Pivot Software\wpctrl.exe"
mRun: [DT GWY] "C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe" -GWY
mRun: [AMD_Display]
mRun: [BrStsWnd] "C:\Program Files (x86)\Brownie\BrstsW64.exe" Autorun
mRun: [EarthLink Installer] " /C
mRun: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
mRun: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [InstaLAN] "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: []
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
mRun: [IndexSearch] "C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe"
mRun: [PaperPort PTD] "C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe"
mRun: [PPort12reminder] "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
mRun: [PDFHook] C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe
mRun: [PDF5 Registry Controller] C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe
mRun: [ControlCenter4] "C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe" /autorun
mRun: [BrStsMon00] "C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
IE: {0483894E-2422-45E0-8384-021AFF1AF3CD} - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files (x86)\iMacros\imacros.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
IE: {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - {A310506F-6BA4-48c4-8887-1F462277AA12} - mscoree.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\OFFICE11\REFIEBAR.DLL
DPF: RemotePrintControlCab - hxxps://payrollapp.com/@57128e25-bfc9-4da2-9796-f1b16cc899b9/checkprintingassistant/RemotePrintControlCab.CAB
DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} - hxxps://qbo.intuit.com/c28/v33.140/qboax10.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {8D59819B-2067-4A6B-84F4-7F84570E3C30} - hxxp://192.168.2.9/img/LinksysMLViewer.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
TCP: {6B246598-B8E6-4703-8960-9F176263D458} = 192.168.2.1
Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\System32\mscoree.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
TB-X64: {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - No File
TB-X64: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
TB-X64: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
mRun-x64: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\AUSTIN~1\AppData\Roaming\Mozilla\Firefox\Profiles\sr36ypo5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ccar.net/
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn\components\WCFirefoxExtn.dll
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Windows\system32\TVUAx\npTVUAx.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2011-4-18 189440]
R2 Apache2.2;Apache2.2;C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe [2011-9-9 20549]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-9-30 375176]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2008-7-24 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2009-3-3 72216]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-12 2255464]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP;C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-3-9 144672]
R2 PdiService;Portrait Displays SDK Service;C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2009-2-25 90112]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-8-3 379496]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx64coinst,serviceStartProc –> RUNDLL32.EXE ykx64coinst,serviceStartProc [?]
R3 AmdLLD64;AMD Low Level Device Driver;C:\Windows\System32\drivers\AmdLLD64.sys [2009-3-30 39424]
R3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2011-9-6 245760]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2011-4-18 40832]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2011-4-27 84864]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\System32\drivers\RTL8187B.sys [2009-6-10 417280]
R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk60x64.sys [2008-8-5 392192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-11 136176]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-11 136176]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);C:\Windows\System32\drivers\swnc8u80.sys [2008-1-10 196608]
S3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);C:\Windows\System32\drivers\swumx80.sys [2008-1-10 191744]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\System32\drivers\WSDPrint.sys [2008-1-20 22528]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2010-1-6 89920]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-10-14 22:31:31 25160 —-a-w- C:\Windows\System32\drivers\hitmanpro35.sys
2011-10-14 22:30:57 ——– d—–w- C:\PROGRA~3\Hitman Pro
2011-10-14 15:05:21 69000 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{3FA51595-E152-4926-9943-9F0E0E284007}\offreg.dll
2011-10-13 23:07:00 9049936 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{3FA51595-E152-4926-9943-9F0E0E284007}\mpengine.dll
2011-10-12 23:10:53 9049936 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-12 22:48:50 61544 —-a-w- C:\Windows\System32\nvshext.dll
2011-10-12 22:48:49 836200 —-a-w- C:\Windows\System32\easyupdatusapiu64.dll
2011-10-12 22:47:55 ——– d—–w- C:\PROGRA~3\NVIDIA Corporation
2011-10-12 22:42:40 ——– d—–w- C:\Program Files\NVIDIA Corporation
2011-10-12 21:46:18 ——– d—–w- C:\Program Files\iPod
2011-10-12 21:46:16 ——– d—–w- C:\Program Files\iTunes
2011-10-12 21:46:16 ——– d—–w- C:\Program Files (x86)\iTunes
2011-10-11 22:59:09 917840 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{7165CBA6-90D6-44CE-8CA8-891F0CF62415}\gapaengine.dll
2011-10-11 22:32:05 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client
2011-10-11 22:30:46 ——– d—–w- C:\Program Files\Microsoft Security Client
2011-10-11 22:27:29 9049936 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{B812DACB-7357-4398-947B-0FF498600BE2}\mpengine.dll
2011-10-11 22:14:19 332288 —-a-w- C:\Windows\System32\oleacc.dll
2011-10-11 22:14:19 238080 —-a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-11 22:14:18 847360 —-a-w- C:\Windows\System32\oleaut32.dll
2011-10-11 22:14:18 735744 —-a-w- C:\Windows\System32\UIAutomationCore.dll
2011-10-11 22:14:18 563712 —-a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-11 22:14:18 555520 —-a-w- C:\Windows\SysWow64\UIAutomationCore.dll
2011-10-11 22:14:18 4096 —-a-w- C:\Windows\SysWow64\oleaccrc.dll
2011-10-11 22:14:18 4096 —-a-w- C:\Windows\System32\oleaccrc.dll
2011-10-11 22:14:06 2764288 —-a-w- C:\Windows\System32\win32k.sys
2011-10-11 22:14:04 2409784 —-a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2011-10-11 22:14:04 2409784 —-a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
2011-10-11 22:10:42 73216 —-a-w- C:\Windows\System32\MSDvbNP.ax
2011-10-11 22:10:42 69632 —-a-w- C:\Windows\SysWow64\Mpeg2Data.ax
2011-10-11 22:10:42 57856 —-a-w- C:\Windows\SysWow64\MSDvbNP.ax
2011-10-11 22:10:42 375808 —-a-w- C:\Windows\System32\psisdecd.dll
2011-10-11 22:10:42 293376 —-a-w- C:\Windows\SysWow64\psisdecd.dll
2011-10-11 22:10:42 289792 —-a-w- C:\Windows\System32\psisrndr.ax
2011-10-11 22:10:42 217088 —-a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-11 22:10:42 100352 —-a-w- C:\Windows\System32\Mpeg2Data.ax
2011-10-11 21:31:05 ——– d—–w- C:\Program Files (x86)\Apache Software Foundation
2011-10-11 17:52:44 ——– d—–w- C:\Users\AUSTIN~1\AppData\Local\Secunia PSI
2011-10-11 17:52:28 ——– d—–w- C:\Program Files (x86)\Secunia
2011-10-06 13:44:25 5554512 —-a-w- C:\Windows\System32\d3dcsx_42.dll
2011-10-06 13:40:29 ——– d—–w- C:\Windows\msdownld.tmp
2011-10-06 13:40:19 ——– d—–w- C:\Windows\SysWow64\directx
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2011-09-21 22:02:49 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2011-09-18 20:15:41 ——– d—–w- C:\Users\AUSTIN~1\AppData\Local\TVU Networks
2011-09-18 20:15:41 ——– d—–w- C:\PROGRA~3\TVU Networks
2011-09-18 20:15:07 ——– d—–w- C:\Windows\SysWow64\TVUAx
2011-09-15 23:56:17 ——– d—–w- C:\PROGRA~3\{B97DFD11-B924-4789-BD74-F21A0C10B0BF}
2011-09-15 23:53:43 ——– d—–w- C:\Users\AUSTIN~1\AppData\Roaming\Stamps.com Internet Postage
2011-09-15 23:51:18 ——– d—–w- C:\PROGRA~3\{2C9DBDBB-2D80-410C-8699-A38A9E6168ED}
2011-09-15 23:50:12 ——– d—–w- C:\Program Files (x86)\Stamps.com Internet Postage
2011-09-15 23:48:32 ——– d—–w- C:\Users\AUSTIN~1\AppData\Local\Seven Zip
.
==================== Find3M ====================
.
2011-10-11 22:07:52 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-11 21:49:10 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2011-10-11 21:39:36 525544 —-a-w- C:\Windows\System32\deployJava1.dll
2011-10-06 14:55:15 87456 —-a-w- C:\Windows\System32\LMIRfsClientNP.dll
2011-10-06 14:55:14 80768 —-a-w- C:\Windows\System32\LMIinit.dll
2011-08-31 22:00:50 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-03 08:31:54 311912 —-a-w- C:\Windows\SysWow64\nvStreaming.exe
.
============= FINISH: 18:26:20.90 ===============



As promised here is the logfile from the MBAM scan I did:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4230

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

10/11/2011 10:48:18 AM
mbam-log-2011-10-11 (10-48-18).txt

Scan type: Full scan (C:\|)
Objects scanned: 416376
Time elapsed: 2 hour(s), 55 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Zugo (Adware.Zugo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


I couldn't find out how to pull a log file of Microsoft Security Essentials but here is what the history shows:

Trojan Downloader:Java/Rexec.F was REMOVED on 10/11/11
Items:
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\7bc15c8a-39ec4910
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\7bc15c8a-57a25655
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\7bc15c8a-64a89bab
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\7bc15c8a-70ae6f81
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\7bc15c8a-7c7c4dd9

Expoit:Java/CVE-2010-0840.JU was REMOVED on 10/11/11
Items:
containerfile:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\737e5dcc-20646c76
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\737e5dcc-20646c76->buildService/MapYandex.class

Expoit:Java/CVE-2010-0840.MQ was REMOVED on 10/11/11
Items:
containerfile:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\4a5c3582-7bb3dca5
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\4a5c3582-7bb3dca5->support/IO.class
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\4a5c3582-7bb3dca5->support/Pipe.class
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\4a5c3582-7bb3dca5->support/Socket.class

Expoit:Java/CVE-2010-0840.BV was REMOVED on 10/11/11
Items:
containerfile:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\15a8472c-4ff01431
file:C:\Users\AustinGood\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\15a8472c-4ff01431->glass/flying.class

Program:Win32/PowerRegScheduler was ALLOWED on 10/12/11
Items:
containerfile:C:\Program Files (x86)\Adobe\Photoshop 7.0\Third Party Products\Corel\KPT effects_Trial.exe
file:C:\Program Files (x86)\Adobe\Photoshop 7.0\Third Party Products\Corel\KPT effects_Trial.exe->(CABSfx)->\data1.cab->(ishld#0138)->[RSRCEmb]


Program:Win32/PowerRegScheduler was QUARANTINED on 10/12/11
Items:
containerfile:C:\Program Files (x86)\Adobe\Photoshop 7.0\Third Party Products\Corel\KPT effects_Trial.exe
file:C:\Program Files (x86)\Adobe\Photoshop 7.0\Third Party Products\Corel\KPT effects_Trial.exe->(CABSfx)->\data1.cab->(ishld#0138)->[RSRCEmb]

Please let me know what else you need from me in order to properly help get rid of this for good and thank you sooooo much!
:welcome:

You have the uTorrent Toolbar installed, this is most likely how you infected your computer, your downloading files from unknown sources bypassing your Antivirus and Firewall, not all but the greater percentage of them are infected, this is how malware writers infect your system. You would be doing yourself a big favor by uninstalling it via Programs and Features in the Control Panel and staying away from any forum of File Sharing

Lets see if a rootkit is involved here.



Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI