This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

csrss.exe, winlogon.exe, and two rundll32.exe tasks

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was browsing quiz sites and one of them gave me the AV Antivirus virus. I think I cleared it from my files, but my task manager has some processes (listed in the title) that won't let me open, end process, or see the file location. I suspect that they came with the AV antivirus virus.. This is my DDS txt log. I hope I did this right. I have Malwarebytes and SuperAntiSpyware installed. SuperAntiSpyware, i think got rid of it but why are these tasks shown in my task manager? Do I have a keylogger?
Please help. This is my first time posting on here. :P

.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 19:19:45.96 on Sat 11/19/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6007.2651 [GMT -8:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
C:\Windows\system32\mfevtps.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Users\jellybean\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files\Common Files\McAfee\Core\mchost.exe
C:\Program Files\McAfee\VirusScan\mcods.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\mrt.exe
C:\Windows\system32\mrt.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\jellybean\Downloads\HiJackThis.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Users\jellybean\Downloads\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://my.att.net/
uDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&m;=dx4831&r;=17360310p106p0415v185k4401r266
uSearch Page = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch_dsl
uSearch Bar = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch_dsl
mDefault_Search_URL = hxxp://search.netzero.net/search?action=search&source;=minisearch_dsl
mDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&m;=dx4831&r;=17360310p106p0415v185k4401r266
mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&m;=dx4831&r;=17360310p106p0415v185k4401r266
mSearch Page = hxxp://search.netzero.net/search?action=search&source;=minisearch_dsl
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:62606
uSearchURL,(Default) = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch_dsl&mn;=87470779
mSearchAssistant = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch_dsl&mn;=87470779
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
mURLSearchHooks: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll
mURLSearchHooks: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111107164202.dll
BHO: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll
TB: {8E613EAF-E16E-415C-BD39-F71D6A3B5518} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Google Update] "C:\Users\jellybean\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Logitech Vid] "C:\Program Files (x86)\Logitech\Vid HD\Vid.exe" -bootmode
uRun: [cdloader] "C:\Users\jellybean\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [JMB36X IDE Setup] "C:\Windows\RaidTool\xInsIDE.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [EEventManager] "C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe"
mRun: [Gateway Photo Frame] "C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe" -A
mRun: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\GAMERS~1.LNK - C:\Program Files (x86)\GamersFirst\LIVE!\Live.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - C:\Users\jellybean\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111106235253.dll
BHO-X64: scriptproxy - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll
TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll
TB-X64: {8E613EAF-E16E-415C-BD39-F71D6A3B5518} - No File
TB-X64: {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB-X64: {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No File
mRun-x64: [IAAnotif] "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe"
mRun-x64: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\JELLYB~1\AppData\Roaming\Mozilla\Firefox\Profiles\g67v93s4.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=723823&p;=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 62606
FF - prefs.js: network.proxy.type - 1
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Users\jellybean\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\jellybean\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2011-3-13 639216]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\drivers\mfewfpk.sys [2011-11-5 283744]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-11-16 55856]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\System32\drivers\mfenlfk.sys [2011-11-3 75160]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-7-18 146816]
R2 Greg_Service;GRegService;C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe [2009-8-28 1150496]
R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-7 191000]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2011-11-3 355440]
R2 McNaiAnn;McAfee VirusScan Announcer;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2011-11-3 355440]
R2 McProxy;McAfee Proxy Service;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2011-11-3 355440]
R2 McShield;McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2011-11-3 200056]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2011-11-3 245352]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Windows\System32\mfevtps.exe [2011-11-3 158832]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-1-25 2314240]
R2 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2009-11-16 240160]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2009-11-16 283824]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-11-16 56344]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2009-11-16 233984]
R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2009-10-7 30232]
R3 LVUVC64;Logitech Webcam 120(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2010-4-3 6379288]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2011-11-3 190520]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\drivers\mfefirek.sys [2011-11-3 441840]
R3 mferkdet;McAfee Inc. mferkdet;C:\Windows\System32\drivers\mferkdet.sys [2011-11-3 94992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-1 135664]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]
S3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\drivers\cfwids.sys [2011-11-3 63056]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-1-30 48488]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-1 135664]
S3 nosGetPlusHelper;getPlus® Helper 3004;C:\Windows\System32\svchost.exe -k nosGetPlusHelper [2009-7-13 27136]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-30 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-9-28 51712]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-5-6 1255736]
.
=============== Created Last 30 ================
.
2011-11-20 03:00:09 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\TuneUp Software
2011-11-20 02:58:53 ——– d—–w- C:\PROGRA~3\TuneUp Software
2011-11-20 02:58:41 ——– d-sh–w- C:\PROGRA~3\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2011-11-20 02:45:38 ——– d—–w- C:\PROGRA~3\Webroot
2011-11-20 02:19:33 ——– d—–w- C:\PROGRA~3\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
2011-11-20 02:16:38 ——– dc-h–w- C:\PROGRA~3\~0
2011-11-20 02:05:22 ——– d—–w- C:\PROGRA~3\IObit
2011-11-20 02:05:20 ——– d—–w- C:\Program Files (x86)\IObit
2011-11-20 01:10:03 69000 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{23EEE84C-12CB-4FB4-8CA6-CA76832F3F4F}\offreg.dll
2011-11-20 01:09:57 8570192 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{23EEE84C-12CB-4FB4-8CA6-CA76832F3F4F}\mpengine.dll
2011-11-19 23:41:31 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\GetRightToGo
2011-11-19 22:18:22 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\SUPERAntiSpyware.com
2011-11-19 22:18:04 ——– d—–w- C:\PROGRA~3\!SASCORE
2011-11-19 22:18:02 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2011-11-19 22:18:02 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com
2011-11-19 01:14:44 ——– d—–w- C:\Windows\pss
2011-11-19 01:00:59 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-19 00:33:55 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\YwjUVelIBzNc1v2
2011-11-19 00:33:55 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\pF4pmH5sQ7E8R9Y
2011-11-18 16:18:32 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\v3pnG5aQHdKfLgq
2011-11-18 16:18:32 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\AjUCekIBrNx0v2b
2011-11-18 05:26:28 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\5C083
2011-11-18 05:25:56 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\UhTTXXqjUCe
2011-11-18 05:25:56 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\kGG55aQJJ6WK8R9
2011-11-18 05:25:56 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\7C35C
2011-11-18 05:25:51 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\ALLL9ggTXqjYekV
2011-11-18 05:25:50 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\YyyyxAA1uv
2011-11-18 02:42:35 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{4BA10DAF-267B-45F5-A9D4-3DA25DF160E1}
2011-11-18 02:42:21 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{5CDDD184-575A-4D0C-899B-665C0FF9C0D4}
2011-11-16 04:32:33 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{0E7F43D2-F896-4D16-B7DD-7A1AD19D6F1F}
2011-11-16 04:32:18 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{B1F03812-C733-4709-B023-16A86B53CCA6}
2011-11-15 02:55:57 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{435B87A1-975A-4052-A079-E209E2B18E81}
2011-11-15 02:55:35 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{1B032429-7406-4CDD-A1B7-BBE254811C8A}
2011-11-14 00:37:49 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{38E5AF4E-4009-431B-B4EF-CAE73B413BE8}
2011-11-14 00:37:27 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{0138FFC3-DE3D-4382-AB36-AF405A0F4042}
2011-11-13 19:35:04 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{0247DB32-1D31-4418-8DDE-5431A3110AE9}
2011-11-13 19:34:40 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{E22072AD-895F-4D4F-BEB2-185EBD61CACD}
2011-11-12 20:01:50 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{06ACD685-954E-4275-98F6-07D296265B28}
2011-11-12 20:01:38 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{6492CB06-9F3A-402A-8869-9A343A2B8261}
2011-11-12 07:33:47 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{90286628-F7A2-4D77-A4FC-AF0A4FE1026E}
2011-11-12 07:33:34 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{B2DEE17A-C336-4415-BC6F-6B592DDAE841}
2011-11-11 01:23:27 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{2AAC5308-B03C-4474-8146-FD56FEA02079}
2011-11-11 01:23:14 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{D036990A-D5DE-466F-ACAB-A9BB4904069F}
2011-11-09 22:54:53 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{CFF9ABB1-3B88-4D00-9EE2-236C47FBF3A7}
2011-11-09 22:54:39 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{A59C7A4F-01D6-4391-8CA7-6A15D89315FF}
2011-11-09 00:41:41 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{B8B9C5CE-6F91-451E-8792-BC46CF774814}
2011-11-09 00:41:19 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{CFDBB833-40CA-4ADF-A36E-98485DEA9788}
2011-11-09 00:16:12 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 00:16:12 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 00:16:12 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 00:16:11 3144704 —-a-w- C:\Windows\System32\win32k.sys
2011-11-08 00:42:02 24376 —-a-w- C:\Program Files (x86)\Mozilla Firefox\components\Scriptff.dll
2011-11-06 07:50:13 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{29224BFB-34AE-4906-8708-179CAC3F020A}
2011-11-06 07:49:58 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{46DB3B01-5FED-4286-ACCB-25BF0A913BED}
2011-11-06 03:52:51 281656 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-11-06 03:52:46 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\PunkBuster
2011-11-06 03:47:39 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation
2011-11-06 03:47:32 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2011-11-06 03:36:59 35840 —-a-w- C:\Windows\SysWow64\imgutil.dll
2011-11-06 03:31:58 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\Conduit
2011-11-06 03:31:58 ——– d—–w- C:\Program Files (x86)\XfireXO
2011-11-06 03:31:48 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\Xfire
2011-11-06 03:31:46 ——– d—–w- C:\PROGRA~3\Xfire
2011-11-06 03:31:45 ——– d—–w- C:\Program Files (x86)\Xfire
2011-11-06 03:31:24 ——– d—–w- C:\Users\JELLYB~1\AppData\Roaming\OpenCandy
2011-11-06 03:22:58 283744 —-a-w- C:\Windows\System32\drivers\mfewfpk.sys
2011-11-06 02:35:16 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\GamersFirst LIVE!
2011-11-06 02:34:20 ——– d—–w- C:\Program Files (x86)\GamersFirst
2011-11-04 02:25:05 ——– d—–w- C:\Program Files (x86)\McAfee.com
2011-11-04 02:24:50 9984 —-a-w- C:\Windows\System32\drivers\mfeclnk.sys
2011-11-04 02:24:50 ——– d—–w- C:\Program Files (x86)\Common Files\McAfee
2011-11-04 02:24:39 75160 —-a-w- C:\Windows\System32\drivers\mfenlfk.sys
2011-11-04 02:24:38 94992 —-a-w- C:\Windows\System32\drivers\mferkdet.sys
2011-11-04 02:24:38 63056 —-a-w- C:\Windows\System32\drivers\cfwids.sys
2011-11-04 02:24:38 441840 —-a-w- C:\Windows\System32\drivers\mfefirek.sys
2011-11-04 02:24:38 190520 —-a-w- C:\Windows\System32\drivers\mfeavfk.sys
2011-11-04 02:24:35 ——– d—–w- C:\Program Files\Common Files\McAfee
2011-11-04 02:24:34 ——– d—–w- C:\Program Files\McAfee.com
2011-11-04 02:24:34 ——– d—–w- C:\Program Files\McAfee
2011-11-04 02:24:33 ——– d—–w- C:\Program Files (x86)\McAfee
2011-11-04 02:17:50 158832 —-a-w- C:\Windows\System32\mfevtps.exe
2011-11-03 23:10:57 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{543FA25A-7BB7-4A1D-AF6D-C999481E38FB}
2011-11-03 23:10:44 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{5008F20E-C300-473E-8080-EE6AA0D530F5}
2011-11-02 01:17:14 737072 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2011-11-01 04:56:59 ——– d—–w- C:\Users\JELLYB~1\AppData\Local\{A41F6779-E6D8-4267-8AD3-B95DC77FF577}
.
==================== Find3M ====================
.
2011-11-20 02:49:28 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-06 03:52:51 281200 —-a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-11-06 03:36:57 89088 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2011-10-13 20:29:40 42392 —-a-w- C:\Windows\SysWow64\xfcodec.dll
2011-10-13 20:29:40 28056 —-a-w- C:\Windows\System32\xfcodec64.dll
2011-09-01 01:00:50 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-28 18:10:50 175616 —-a-w- C:\Windows\System32\msclmd.dll
2011-08-28 18:10:50 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll
2011-08-27 05:37:49 861696 —-a-w- C:\Windows\System32\oleaut32.dll
2011-08-27 05:37:48 331776 —-a-w- C:\Windows\System32\oleacc.dll
2011-08-27 04:26:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll
2011-08-27 04:26:27 233472 —-a-w- C:\Windows\SysWow64\oleacc.dll
.
============= FINISH: 19:21:28.82 ===============
Hi BubbleRap,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
===================================================

csrss.exe, winlogon.exe and rundll32.exe are all system processes. You cannot terminate them because they are required for Windows to run. Let's take a closer look at your system to see if you still have any remnants of the rogue antivirus.

===================================================
Download aswMBR.exe ( 1.8mb ) to your desktop.

Double click the aswMBR.exe to run it

[external image: Posted Image]
Click the "Scan" button to start scan

[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
Thank you for the response ^_^ , I used the download and this is what I got: aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-20 02:50:54 —————————– 02:50:54.843 OS Version: Windows x64 6.1.7601 Service Pack 1 02:50:54.843 Number of processors: 4 586 0x2502 02:50:54.844 ComputerName: JELLYBEAN-PC UserName: jellybean 02:50:56.483 Initialize success 02:51:11.686 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 02:51:11.689 Disk 0 Vendor: WDC_WD10 01.0 Size: 953869MB BusType: 3 02:51:11.705 Disk 0 MBR read successfully 02:51:11.708 Disk 0 MBR scan 02:51:11.712 Disk 0 Windows 7 default MBR code 02:51:11.715 Service scanning 02:51:13.877 Modules scanning 02:51:13.882 Disk 0 trace - called modules: 02:51:13.893 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 02:51:13.898 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80065c4060] 02:51:13.904 3 CLASSPNP.SYS[fffff88001bb143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006306050] 02:51:13.909 Scan finished successfully 02:52:11.156 Disk 0 MBR has been saved successfully to "C:\Users\jellybean\Desktop\MBR.dat" 02:52:11.172 The log file has been saved successfully to "C:\Users\jellybean\Desktop\aswMBR.txt"
Excellent! Thanks BubbleRap. Now I need you to do the following:

Please download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
I followed the instructions, but I think McAfee quarantined combofix upon rebooting so I waited to see if it would create a log, but it didnt so I closed it…. I am replying back from my laptop because my computer could not open ANY programs, including internet explorer. it said "Illegal operation attempted on a registry key that has been marked for deletion" for EVERYTHING that i try to open. Any idea how I can fix this? Oh, and I should also mention that the only tasks running in the task manager are now the csrss.exe, two rundll32.exe, winlogon.exe (all 4 of them are the suspected keyloggers/viruses) taskmgr.exe, taskhost.exe, explorer.exe, dwm.exe,and mcagent.exe. I really can't open anything and it's so frustrating. =/ if i didnt have my laptop , i wouldnt be able to reply to this lol
Hi BubbleRap,

ComboFix has this problem when run on some Windows 7 machines. You shouldn't worry about it. A restart should fix the problem. As for McAfee, did you disable it before running ComboFix? Did ComboFix run successfully before the restart? And was McAfee telling you that those processes are suspected keyloggers/viruses?

Please browse to C:\ and post ComboFix.txt if it exists.
Yes, a restart fixed this problem thank you. :) I disabled McAfee before running ComboFix smoothly, but I guess once my comp got rebooted McAfee enabled itself. McAfee suspected combofix was malware or something once i rebooted. I uninstalled McAfee and installed Avast because it has better reviews. As for the combofix.txt, i could not find it :( .
Yes, a restart fixed this problem thank you. :) I disabled McAfee before running ComboFix smoothly, but I guess once my comp got rebooted McAfee enabled itself. McAfee suspected combofix was malware or something once i rebooted. I uninstalled McAfee and installed Avast because it has better reviews. As for the combofix.txt, i could not find it :( .
Okay it worked , here is the combofix.txt: ComboFix 11-11-20.02 - jellybean 11/20/2011 16:33:53.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6007.4048 [GMT -8:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\TEMP\logishrd\LVPrcInj01.dll . . . . Failed to delete c:\windows\TEMP\logishrd\LVPrcInj02.dll . . . . Failed to delete . —- Previous Run ——- . C:\install.exe c:\users\AppData\EULA.txt c:\users\AppData\TDSSKiller.exe c:\users\jellybean\AppData\Roaming\jellybeanlog.dat . . ((((((((((((((((((((((((( Files Created from 2011-10-21 to 2011-11-21 ))))))))))))))))))))))))))))))) . . 2011-11-21 00:39 . 2011-11-21 00:39 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-11-21 00:18 . 2011-11-21 00:18 ——– d—–w- c:\program files (x86)\Common Files\Adobe 2011-11-21 00:08 . 2011-11-21 00:08 ——– d—–w- c:\users\jellybean\AppData\Roaming\CBS Interactive 2011-11-20 23:03 . 2011-09-06 21:38 301912 —-a-w- c:\windows\system32\drivers\aswSP.sys 2011-11-20 23:03 . 2011-09-06 21:36 24408 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-11-20 23:03 . 2011-09-06 21:36 42328 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2011-11-20 23:03 . 2011-09-06 21:36 58200 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2011-11-20 23:03 . 2011-09-06 21:38 601944 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-11-20 23:03 . 2011-09-06 21:36 65368 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-11-20 23:03 . 2011-09-06 21:45 254400 —-a-w- c:\windows\system32\aswBoot.exe 2011-11-20 23:03 . 2011-09-06 21:45 41184 —-a-w- c:\windows\avastSS.scr 2011-11-20 23:03 . 2011-09-06 21:45 199304 —-a-w- c:\windows\SysWow64\aswBoot.exe 2011-11-20 23:03 . 2011-11-20 23:03 ——– d—–w- c:\programdata\AVAST Software 2011-11-20 23:03 . 2011-11-20 23:03 ——– d—–w- c:\program files\AVAST Software 2011-11-20 03:00 . 2011-11-20 03:00 ——– d—–w- c:\users\jellybean\AppData\Roaming\TuneUp Software 2011-11-20 02:58 . 2011-11-20 03:08 ——– d—–w- c:\programdata\TuneUp Software 2011-11-20 02:58 . 2011-11-20 02:58 ——– d-sh–w- c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2011-11-20 02:49 . 2011-11-20 02:49 ——– d—–w- c:\windows\system32\Macromed 2011-11-20 02:45 . 2011-11-20 02:45 ——– d—–w- c:\programdata\Webroot 2011-11-20 02:19 . 2011-11-20 02:19 ——– d—–w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1} 2011-11-20 02:05 . 2011-11-20 02:05 ——– d—–w- c:\programdata\IObit 2011-11-20 02:05 . 2011-11-20 02:05 ——– d—–w- c:\program files (x86)\IObit 2011-11-20 01:20 . 2011-11-20 01:20 ——– d—–w- c:\users\AppData\tdsskiller 2011-11-20 01:09 . 2011-10-18 09:27 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{23EEE84C-12CB-4FB4-8CA6-CA76832F3F4F}\mpengine.dll 2011-11-19 23:41 . 2011-11-19 23:42 ——– d—–w- c:\users\jellybean\AppData\Roaming\GetRightToGo 2011-11-19 22:18 . 2011-11-19 22:18 ——– d—–w- c:\users\jellybean\AppData\Roaming\SUPERAntiSpyware.com 2011-11-19 22:18 . 2011-11-19 22:18 ——– d—–w- c:\programdata\!SASCORE 2011-11-19 22:18 . 2011-11-20 21:24 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-11-19 22:18 . 2011-11-19 22:18 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-11-19 01:00 . 2011-11-19 01:01 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-11-19 00:33 . 2011-11-19 22:56 ——– d—–w- c:\users\jellybean\AppData\Roaming\YwjUVelIBzNc1v2 2011-11-19 00:33 . 2011-11-19 00:33 ——– d—–w- c:\users\jellybean\AppData\Roaming\pF4pmH5sQ7E8R9Y 2011-11-18 16:18 . 2011-11-19 22:56 ——– d—–w- c:\users\jellybean\AppData\Roaming\v3pnG5aQHdKfLgq 2011-11-18 16:18 . 2011-11-18 16:18 ——– d—–w- c:\users\jellybean\AppData\Roaming\AjUCekIBrNx0v2b 2011-11-18 05:26 . 2011-11-19 02:14 ——– d—–w- c:\users\jellybean\AppData\Roaming\5C083 2011-11-18 05:25 . 2011-11-19 22:56 ——– d—–w- c:\users\jellybean\AppData\Roaming\UhTTXXqjUCe 2011-11-18 05:25 . 2011-11-18 05:26 ——– d—–w- c:\users\jellybean\AppData\Roaming\7C35C 2011-11-18 05:25 . 2011-11-18 05:25 ——– d—–w- c:\users\jellybean\AppData\Roaming\kGG55aQJJ6WK8R9 2011-11-18 05:25 . 2011-11-18 05:25 ——– d—–w- c:\users\jellybean\AppData\Roaming\ALLL9ggTXqjYekV 2011-11-18 05:25 . 2011-11-18 05:25 ——– d—–w- c:\users\jellybean\AppData\Roaming\YyyyxAA1uv 2011-11-09 00:16 . 2011-10-01 05:45 886784 —-a-w- c:\program files\Common Files\System\wab32.dll 2011-11-09 00:16 . 2011-10-01 04:37 708608 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll 2011-11-09 00:16 . 2011-09-29 16:29 1923952 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-09 00:16 . 2011-09-29 04:03 3144704 —-a-w- c:\windows\system32\win32k.sys 2011-11-06 03:52 . 2011-11-06 04:32 281656 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2011-11-06 03:52 . 2011-11-06 03:52 ——– d—–w- c:\users\jellybean\AppData\Local\PunkBuster 2011-11-06 03:47 . 2011-11-06 03:47 ——– d—–w- c:\program files (x86)\NVIDIA Corporation 2011-11-06 03:47 . 2011-11-06 03:47 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2011-11-06 03:36 . 2011-11-06 03:36 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2011-11-06 03:31 . 2011-11-06 03:31 ——– d—–w- c:\users\jellybean\AppData\Local\Conduit 2011-11-06 03:31 . 2011-11-14 07:52 ——– d—–w- c:\users\jellybean\AppData\Roaming\Xfire 2011-11-06 03:31 . 2011-11-13 19:36 ——– d—–w- c:\programdata\Xfire 2011-11-06 03:31 . 2011-11-06 19:11 ——– d—–w- c:\program files (x86)\Xfire 2011-11-06 03:31 . 2011-11-21 00:08 ——– d—–w- c:\users\jellybean\AppData\Roaming\OpenCandy 2011-11-06 02:35 . 2011-11-06 02:35 ——– d—–w- c:\users\jellybean\AppData\Local\GamersFirst LIVE! 2011-11-06 02:34 . 2011-11-06 03:31 ——– d—–w- c:\program files (x86)\GamersFirst 2011-11-04 02:24 . 2011-11-21 00:41 ——– d—–w- c:\program files\Common Files\McAfee 2011-11-04 02:24 . 2011-11-21 00:32 ——– d—–w- c:\program files (x86)\McAfee 2011-11-02 01:17 . 2011-11-02 01:17 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-20 02:49 . 2011-07-01 00:39 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-02 01:16 . 2010-04-30 02:35 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-11-02 01:16 . 2010-06-04 01:40 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2011-11-02 01:16 . 2010-04-30 02:34 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2011-10-13 20:29 . 2011-10-13 20:29 42392 —-a-w- c:\windows\SysWow64\xfcodec.dll 2011-10-13 20:29 . 2011-10-13 20:29 28056 —-a-w- c:\windows\system32\xfcodec64.dll 2011-09-17 00:26 . 2010-05-19 02:06 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2011-09-17 00:25 . 2010-05-19 02:05 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-09-17 00:25 . 2011-09-17 00:25 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2011-09-01 01:00 . 2011-01-30 22:57 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-28 18:10 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll 2011-08-28 18:10 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll 2011-08-27 05:37 . 2011-10-13 04:59 861696 —-a-w- c:\windows\system32\oleaut32.dll 2011-08-27 05:37 . 2011-10-13 04:59 331776 —-a-w- c:\windows\system32\oleacc.dll 2011-08-27 04:26 . 2011-10-13 04:59 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-08-27 04:26 . 2011-10-13 04:59 233472 —-a-w- c:\windows\SysWow64\oleacc.dll . . ((((((((((((((((((((((((((((( SnapShot@2011-11-20_21.43.17 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:54 . 2011-11-21 00:41 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-11-20 02:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-11-20 02:06 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-11-21 00:41 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-11-20 02:06 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-11-21 00:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-11-16 10:00 . 2011-11-20 22:43 39978 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-11-20 22:43 27534 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-03-22 02:31 . 2011-11-20 22:43 22774 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3996681575-678226163-2777997048-1000_UserData.bin - 2009-07-14 05:30 . 2011-11-04 02:24 86016 c:\windows\system32\DriverStore\infpub.dat + 2009-07-14 05:30 . 2011-11-20 23:00 86016 c:\windows\system32\DriverStore\infpub.dat + 2010-01-26 03:52 . 2011-11-21 00:32 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-01-26 03:52 . 2011-11-20 21:42 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-01-26 03:52 . 2011-11-21 00:32 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2010-01-26 03:52 . 2011-11-20 21:42 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-11-20 21:42 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-11-21 00:32 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:46 . 2011-11-21 00:24 94432 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2011-11-21 00:09 . 2011-11-21 00:09 28160 c:\windows\Installer\511a9c.msi + 2011-06-06 20:55 . 2011-06-06 20:55 73624 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\wow_helper.exe + 2011-06-06 20:55 . 2011-06-06 20:55 17304 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\ViewerPS.dll + 2011-06-06 20:55 . 2011-06-06 20:55 35736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\reader_sl.exe + 2011-06-06 20:55 . 2011-06-06 20:55 88992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlr.dll + 2011-06-06 20:55 . 2011-06-06 20:55 94608 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\eula.exe + 2011-06-06 20:55 . 2011-06-06 20:55 49064 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrotextextractor.exe + 2011-06-06 20:55 . 2011-06-06 20:55 17824 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32Info.exe + 2011-06-06 20:55 . 2011-06-06 20:55 63912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acroiehelpershim.dll + 2011-06-06 20:55 . 2011-06-06 20:55 64928 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroIEHelper.dll + 2011-06-06 20:55 . 2011-06-06 20:55 63384 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\Acrofx32.dll + 2010-03-22 03:36 . 2011-11-20 22:39 5884 c:\windows\system32\wdi\ERCQueuedResolutions.dat + 2011-11-21 00:41 . 2011-11-21 00:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-11-20 21:42 . 2011-11-20 21:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2011-11-21 00:41 . 2011-11-21 00:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-11-20 21:42 . 2011-11-20 21:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-11-21 00:41 . 2009-10-07 08:46 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll - 2011-11-20 21:42 . 2009-10-07 08:46 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll + 2011-11-21 00:41 . 2009-10-07 08:47 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll - 2011-11-20 21:42 . 2009-10-07 08:47 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll + 2009-07-14 05:30 . 2011-11-20 23:00 143360 c:\windows\system32\DriverStore\infstrng.dat - 2009-07-14 05:30 . 2011-11-04 02:24 143360 c:\windows\system32\DriverStore\infstrng.dat + 2009-07-14 05:30 . 2011-11-20 23:00 143360 c:\windows\system32\DriverStore\infstor.dat - 2009-07-14 05:30 . 2011-11-04 02:24 143360 c:\windows\system32\DriverStore\infstor.dat + 2009-07-14 05:01 . 2011-11-21 00:40 355584 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2011-11-20 21:42 355584 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-06-06 20:55 . 2011-06-06 20:55 249232 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\sqlite.dll + 2011-06-06 20:55 . 2011-06-06 20:55 394136 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\pdfshell.dll + 2011-06-06 20:55 . 2011-06-06 20:55 183696 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\nppdf32.dll + 2011-06-06 20:55 . 2011-06-06 20:55 104344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AiodLite.dll + 2011-06-06 20:55 . 2011-06-06 20:55 102808 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRdIF.dll + 2011-06-06 20:55 . 2011-06-06 20:55 755088 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroPDF.dll + 2011-06-06 20:55 . 2011-06-06 20:55 296344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrobroker.exe + 2011-06-06 20:55 . 2011-06-06 20:55 205720 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\a3dutils.dll + 2009-07-14 04:45 . 2011-11-21 00:24 7113171 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat - 2009-07-14 04:45 . 2011-11-20 21:22 7113171 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat - 2011-11-18 16:43 . 2011-11-20 11:00 2497566 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996681575-678226163-2777997048-1000-4096.dat + 2011-11-18 16:43 . 2011-11-21 00:40 2497566 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996681575-678226163-2777997048-1000-4096.dat + 2011-11-07 08:38 . 2011-11-21 00:40 1187442 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996681575-678226163-2777997048-1000-12288.dat + 2011-06-06 20:45 . 2011-06-06 20:45 2318848 c:\windows\Installer\5120c6.msi + 2010-07-15 02:10 . 2010-07-15 02:10 2818048 c:\windows\Installer\511a97.msi + 2011-06-06 20:55 . 2011-06-06 20:55 2215312 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\rt3d.dll + 2011-06-06 20:55 . 2011-06-06 20:55 6543768 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\authplay.dll + 2011-06-06 20:55 . 2011-06-06 20:55 1240992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AdobeCollabSync.exe + 2011-06-06 20:55 . 2011-06-06 20:55 1480600 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.exe + 2010-09-07 06:51 . 2011-11-21 00:40 16321252 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996681575-678226163-2777997048-1000-8192.dat - 2010-09-07 06:51 . 2011-11-20 21:42 16321252 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996681575-678226163-2777997048-1000-8192.dat + 2011-09-05 21:51 . 2011-09-05 21:51 13135872 c:\windows\Installer\5120c7.msp + 2011-06-06 20:55 . 2011-06-06 20:55 24731544 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.dll . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] 2011-01-17 23:54 175912 —-a-w- c:\program files (x86)\XfireXO\prxtbXfir.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] 2010-03-25 20:31 2355296 —-a-w- c:\program files (x86)\DVDVideoSoftTB\tbDVDV.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files (x86)\DVDVideoSoftTB\tbDVDV.dll" [2010-03-25 2355296] "{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files (x86)\XfireXO\prxtbXfir.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] . [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Logitech Vid"="c:\program files (x86)\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496] "cdloader"="c:\users\jellybean\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-20 5495680] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-21 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864] "Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-08-03 498160] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-09-08 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-11-11 421160] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "EEventManager"="c:\progra~2\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-12-04 665424] "Gateway Photo Frame"="c:\program files (x86)\Gateway Photo Frame\ButtonMonitor.exe" [2009-07-20 124416] "LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] . c:\users\jellybean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ CNET TechTracker.lnk - c:\users\jellybean\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe [2011-8-30 2620416] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ GamersFirst LIVE!.lnk - c:\program files (x86)\GamersFirst\LIVE!\Live.exe [2011-8-15 2589808] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy Software Installer.lnk - c:\program files\Best Buy Software Installer\Best Buy Software Installer.exe [2009-10-28 1132984] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 0120361321830016mcinstcleanup;McAfee Application Installer Cleanup (0120361321830016);c:\users\JELLYB~1\AppData\Local\Temp\012036~1.EXE [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 135664] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-01 183560] R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\softnyxGame\GunBoundIS\GameGuard\dump_wmimmc.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 135664] R3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 27136] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 X6va003;X6va003;c:\users\JELLYB~1\AppData\Local\Temp\0037042.tmp [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-11-20 140672] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 Greg_Service;GRegService;c:\program files (x86)\Gateway\Registration\GregHSRW.exe [2009-08-28 1150496] S2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 2314240] S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2009-07-04 240160] S3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [x] S3 LVUVC64;Logitech Webcam 120(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - ASWSNX . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper . Contents of the 'Scheduled Tasks' folder . 2011-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 08:22] . 2011-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 08:22] . 2011-11-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3996681575-678226163-2777997048-1000Core.job - c:\users\jellybean\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 19:31] . 2011-11-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3996681575-678226163-2777997048-1000UA.job - c:\users\jellybean\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 19:31] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 21:45 134384 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-28 8312352] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uStart Page = hxxp://my.att.net/ uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=dx4831&r=17360310p106p0415v185k4401r266 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uInternet Settings,ProxyServer = http=127.0.0.1:62606 uSearchURL,(Default) = hxxp://search.netzero.net/search?action=minisearch&source=minisearch_dsl&mn=87470779 IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Free YouTube to MP3 Converter - c:\users\jellybean\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\jellybean\AppData\Roaming\Mozilla\Firefox\Profiles\g67v93s4.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=723823&p= . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - (no file) AddRemove-Adobe AIR - c:\program files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe AddRemove-Free Audio CD Burner_is1 - c:\program files (x86)\DVDVideoSoft\Free Audio CD Burner\unins000.exe AddRemove-Uninstall_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\unins000.exe AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\bm_installer.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va003] "ImagePath"="\??\c:\users\JELLYB~1\AppData\Local\Temp\0037042.tmp" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3996681575-678226163-2777997048-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3996681575-678226163-2777997048-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe . ************************************************************************** . Completion time: 2011-11-20 16:57:43 - machine was rebooted ComboFix-quarantined-files.txt 2011-11-21 00:57 . Pre-Run: 903,158,808,576 bytes free Post-Run: 902,762,192,896 bytes free . - - End Of File - - 40073860253E0C83579BB4E38ED8F3C2
Hi BubbleRap,

You're doing great!


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Driver::
X6va003

File::
c:\users\JELLYB~1\AppData\Local\Temp\0037042.tmp

Folder::
c:\users\jellybean\AppData\Roaming\YwjUVelIBzNc1v2
c:\users\jellybean\AppData\Roaming\pF4pmH5sQ7E8R9Y
c:\users\jellybean\AppData\Roaming\v3pnG5aQHdKfLgq
c:\users\jellybean\AppData\Roaming\AjUCekIBrNx0v2b
c:\users\jellybean\AppData\Roaming\5C083
c:\users\jellybean\AppData\Roaming\UhTTXXqjUCe
c:\users\jellybean\AppData\Roaming\7C35C
c:\users\jellybean\AppData\Roaming\kGG55aQJJ6WK8R9
c:\users\jellybean\AppData\Roaming\ALLL9ggTXqjYekV
c:\users\jellybean\AppData\Roaming\YyyyxAA1uv

Dirlook::
c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
c:\users\AppData\tdsskiller
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste
The result log took forever to process so I closed it. I don't think anything was blocking access to ComboFix either. is the results log supposed to be in a specific file? Because i checked the file location through task manager and it said it was in "CF15184". Don't know if that is of any help
Hey, This is the most recent one I found of combofix.txt : ComboFix 11-11-20.02 - jellybean 11/20/2011 20:52:06.3.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6007.4061 [GMT -8:00] Running from: C:\Users\[removed]\Downloads\ComboFix.exe Command switches used :: C:\Users\jellybean\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FILE :: "c:\users\JELLYB~1\AppData\Local\Temp\0037042.tmp" ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) c:\users\jellybean\AppData\Roaming\5C083 c:\users\jellybean\AppData\Roaming\7C35C c:\users\jellybean\AppData\Roaming\7C35C\C083.C35 c:\users\jellybean\AppData\Roaming\AjUCekIBrNx0v2b c:\users\jellybean\AppData\Roaming\ALLL9ggTXqjYekV c:\users\jellybean\AppData\Roaming\kGG55aQJJ6WK8R9 c:\users\jellybean\AppData\Roaming\pF4pmH5sQ7E8R9Y c:\users\jellybean\AppData\Roaming\UhTTXXqjUCe c:\users\jellybean\AppData\Roaming\v3pnG5aQHdKfLgq c:\users\jellybean\AppData\Roaming\YwjUVelIBzNc1v2 c:\users\jellybean\AppData\Roaming\YyyyxAA1uv C:\Windows\TEMP\logishrd\LVPrcInj01.dll . . . . Failed to delete C:\Windows\TEMP\logishrd\LVPrcInj02.dll . . . . Failed to delete ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_X6VA003 ——-\Service_X6va003 ((((((((((((((((((((((((( Files Created from 2011-10-21 to 2011-11-21 ))))))))))))))))))))))))))))))) 2011-11-21 04:58:47 . 2011-11-21 04:58:47 ——– d—–w- C:\Users\Default\AppData\Local\temp 2011-11-21 00:18:23 . 2011-11-21 00:18:26 ——– d—–w- C:\Program Files (x86)\Common Files\Adobe 2011-11-21 00:08:27 . 2011-11-21 00:08:27 ——– d—–w- C:\Users\jellybean\AppData\Roaming\CBS Interactive 2011-11-20 23:03:51 . 2011-09-06 21:38:16 301912 —-a-w- C:\Windows\system32\drivers\aswSP.sys 2011-11-20 23:03:51 . 2011-09-06 21:36:14 24408 —-a-w- C:\Windows\system32\drivers\aswFsBlk.sys 2011-11-20 23:03:46 . 2011-09-06 21:36:41 42328 —-a-w- C:\Windows\system32\drivers\aswRdr.sys 2011-11-20 23:03:45 . 2011-09-06 21:36:41 58200 —-a-w- C:\Windows\system32\drivers\aswTdi.sys 2011-11-20 23:03:44 . 2011-09-06 21:38:18 601944 —-a-w- C:\Windows\system32\drivers\aswSnx.sys 2011-11-20 23:03:38 . 2011-09-06 21:36:30 65368 —-a-w- C:\Windows\system32\drivers\aswMonFlt.sys 2011-11-20 23:03:37 . 2011-09-06 21:45:17 254400 —-a-w- C:\Windows\system32\aswBoot.exe 2011-11-20 23:03:10 . 2011-09-06 21:45:29 41184 —-a-w- C:\Windows\avastSS.scr 2011-11-20 23:03:10 . 2011-09-06 21:45:29 199304 —-a-w- C:\Windows\SysWow64\aswBoot.exe 2011-11-20 23:03:03 . 2011-11-20 23:03:03 ——– d—–w- C:\ProgramData\AVAST Software 2011-11-20 23:03:03 . 2011-11-20 23:03:03 ——– d—–w- C:\Program Files\AVAST Software 2011-11-20 03:00:09 . 2011-11-20 03:00:09 ——– d—–w- C:\Users\jellybean\AppData\Roaming\TuneUp Software 2011-11-20 02:58:53 . 2011-11-20 03:08:13 ——– d—–w- C:\ProgramData\TuneUp Software 2011-11-20 02:58:41 . 2011-11-20 02:58:41 ——– d-sh–w- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2011-11-20 02:49:19 . 2011-11-20 02:49:19 ——– d—–w- C:\Windows\system32\Macromed 2011-11-20 02:45:38 . 2011-11-20 02:45:38 ——– d—–w- C:\ProgramData\Webroot 2011-11-20 02:19:33 . 2011-11-20 02:19:33 ——– d—–w- C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1} 2011-11-20 02:05:22 . 2011-11-20 02:05:22 ——– d—–w- C:\ProgramData\IObit 2011-11-20 02:05:20 . 2011-11-20 02:05:20 ——– d—–w- C:\Program Files (x86)\IObit 2011-11-20 01:20:40 . 2011-11-20 01:20:58 ——– d—–w- C:\Users\AppData\tdsskiller 2011-11-20 01:09:57 . 2011-10-18 09:27:56 8570192 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{23EEE84C-12CB-4FB4-8CA6-CA76832F3F4F}\mpengine.dll 2011-11-19 23:41:31 . 2011-11-19 23:42:50 ——– d—–w- C:\Users\jellybean\AppData\Roaming\GetRightToGo 2011-11-19 22:18:22 . 2011-11-19 22:18:22 ——– d—–w- C:\Users\jellybean\AppData\Roaming\SUPERAntiSpyware.com 2011-11-19 22:18:04 . 2011-11-19 22:18:04 ——– d—–w- C:\ProgramData\!SASCORE 2011-11-19 22:18:02 . 2011-11-20 21:24:10 ——– d—–w- C:\Program Files\SUPERAntiSpyware 2011-11-19 22:18:02 . 2011-11-19 22:18:02 ——– d—–w- C:\ProgramData\SUPERAntiSpyware.com 2011-11-19 01:00:59 . 2011-11-19 01:01:03 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-11-09 00:16:12 . 2011-10-01 05:45:21 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll 2011-11-09 00:16:12 . 2011-10-01 04:37:08 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll 2011-11-09 00:16:12 . 2011-09-29 16:29:28 1923952 —-a-w- C:\Windows\system32\drivers\tcpip.sys 2011-11-09 00:16:11 . 2011-09-29 04:03:32 3144704 —-a-w- C:\Windows\system32\win32k.sys 2011-11-06 03:52:51 . 2011-11-06 04:32:12 281656 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr 2011-11-06 03:52:46 . 2011-11-06 03:52:46 ——– d—–w- C:\Users\jellybean\AppData\Local\PunkBuster 2011-11-06 03:47:39 . 2011-11-06 03:47:39 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation 2011-11-06 03:47:32 . 2011-11-06 03:47:32 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard 2011-11-06 03:36:59 . 2011-11-06 03:36:59 35840 —-a-w- C:\Windows\SysWow64\imgutil.dll 2011-11-06 03:31:58 . 2011-11-06 03:31:58 ——– d—–w- C:\Users\jellybean\AppData\Local\Conduit 2011-11-06 03:31:48 . 2011-11-14 07:52:49 ——– d—–w- C:\Users\jellybean\AppData\Roaming\Xfire 2011-11-06 03:31:46 . 2011-11-13 19:36:13 ——– d—–w- C:\ProgramData\Xfire 2011-11-06 03:31:45 . 2011-11-06 19:11:50 ——– d—–w- C:\Program Files (x86)\Xfire 2011-11-06 03:31:24 . 2011-11-21 00:08:29 ——– d—–w- C:\Users\jellybean\AppData\Roaming\OpenCandy 2011-11-06 02:35:16 . 2011-11-06 02:35:19 ——– d—–w- C:\Users\jellybean\AppData\Local\GamersFirst LIVE! 2011-11-06 02:34:20 . 2011-11-06 03:31:24 ——– d—–w- C:\Program Files (x86)\GamersFirst 2011-11-04 02:24:35 . 2011-11-21 00:41:15 ——– d—–w- C:\Program Files\Common Files\McAfee 2011-11-04 02:24:33 . 2011-11-21 00:32:32 ——– d—–w- C:\Program Files (x86)\McAfee 2011-11-02 01:17:14 . 2011-11-02 01:17:14 737072 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2011-11-20 02:49:28 . 2011-07-01 00:39:14 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-02 01:16:48 . 2010-04-30 02:35:16 4283672 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-11-02 01:16:32 . 2010-06-04 01:40:20 42776 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2011-11-02 01:16:28 . 2010-04-30 02:34:21 539968 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2011-10-13 20:29:40 . 2011-10-13 20:29:40 42392 —-a-w- C:\Windows\SysWow64\xfcodec.dll 2011-10-13 20:29:40 . 2011-10-13 20:29:40 28056 —-a-w- C:\Windows\system32\xfcodec64.dll 2011-09-17 00:26:47 . 2010-05-19 02:06:11 4283672 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2011-09-17 00:25:47 . 2010-05-19 02:05:35 42776 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-09-17 00:25:33 . 2011-09-17 00:25:33 539968 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2011-09-01 01:00:50 . 2011-01-30 22:57:33 25416 —-a-w- C:\Windows\system32\drivers\mbam.sys 2011-08-28 18:10:50 . 2009-07-14 02:36:51 175616 —-a-w- C:\Windows\system32\msclmd.dll 2011-08-28 18:10:50 . 2009-07-14 02:36:51 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll 2011-08-27 05:37:49 . 2011-10-13 04:59:50 861696 —-a-w- C:\Windows\system32\oleaut32.dll 2011-08-27 05:37:48 . 2011-10-13 04:59:50 331776 —-a-w- C:\Windows\system32\oleacc.dll 2011-08-27 04:26:27 . 2011-10-13 04:59:50 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-27 04:26:27 . 2011-10-13 04:59:50 233472 —-a-w- C:\Windows\SysWow64\oleacc.dll (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) —- Directory of c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936} —- 2011-11-20 02:58:41 . 2011-11-20 02:58:45 23763968 —-a-w- c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}\{D3742F82-1C1A-4DCC-ABBD-0E831C0185CC}.msi —- Directory of c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1} —- 2011-11-20 02:19:33 . 2011-11-20 02:19:33 700 —-a-w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA}.native.bitness.log 2011-11-20 02:19:33 . 2011-11-20 02:19:33 592 —-a-w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA}.native.weight.log 2011-11-20 02:19:33 . 2011-11-20 02:19:33 8734 —-a-w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA}.native.data.log 2011-11-20 02:19:33 . 2011-11-20 02:19:33 1380 —-a-w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA}.native.elements.log —- Directory of c:\users\AppData\tdsskiller —- 2011-11-16 20:21:12 . 2011-11-20 01:20:58 1564976 —-a-w- c:\users\AppData\tdsskiller\TDSSKiller.exe 2011-01-01 09:14:00 . 2011-11-20 01:20:58 2254 —-a-w- c:\users\AppData\tdsskiller\eula.txt ((((((((((((((((((((((((((((( SnapShot_2011-11-21_00.42.09 ))))))))))))))))))))))))))))))))))))))))) - 2009-07-14 04:54:17 . 2011-11-21 00:41:27 32768 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54:17 . 2011-11-21 05:00:12 32768 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54:17 . 2011-11-21 05:00:12 49152 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54:17 . 2011-11-21 00:41:27 49152 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54:17 . 2011-11-21 00:41:27 16384 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54:17 . 2011-11-21 05:00:12 16384 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-11-16 10:00:03 . 2011-11-21 04:47:26 42116 C:\Windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10:35 . 2011-11-21 04:47:20 27844 C:\Windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-03-22 02:31:17 . 2011-11-21 04:47:21 23062 C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3996681575-678226163-2777997048-1000_UserData.bin + 2009-07-14 04:46:26 . 2011-11-21 00:50:23 94640 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2011-11-21 05:00:08 . 2011-11-21 05:00:08 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-11-21 00:41:23 . 2011-11-21 00:41:23 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2011-11-21 05:00:08 . 2011-11-21 05:00:08 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-11-21 00:41:23 . 2011-11-21 00:41:23 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-11-21 00:41:54 . 2009-10-07 08:46:36 131608 C:\Windows\Temp\logishrd\LVPrcInj02.dll + 2011-11-21 05:00:21 . 2009-10-07 08:46:36 131608 C:\Windows\Temp\logishrd\LVPrcInj02.dll - 2011-11-21 00:41:53 . 2009-10-07 08:47:22 109080 C:\Windows\Temp\logishrd\LVPrcInj01.dll + 2011-11-21 05:00:18 . 2009-10-07 08:47:22 109080 C:\Windows\Temp\logishrd\LVPrcInj01.dll + 2010-04-13 02:34:41 . 2011-11-21 04:43:39 289764 C:\Windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin + 2009-07-14 05:01:48 . 2011-11-21 04:59:20 355584 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01:48 . 2011-11-21 00:40:28 355584 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2011-11-07 08:38:54 . 2011-11-21 00:40:33 1187442 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996681575-678226163-2777997048-1000-12288.dat + 2011-11-07 08:38:54 . 2011-11-21 04:44:20 1187442 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996681575-678226163-2777997048-1000-12288.dat + 2010-09-07 06:51:26 . 2011-11-21 04:59:20 16321252 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996681575-678226163-2777997048-1000-8192.dat - 2010-09-07 06:51:26 . 2011-11-21 00:40:32 16321252 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996681575-678226163-2777997048-1000-8192.dat ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] 2011-01-17 23:54:02 175912 —-a-w- C:\Program Files (x86)\XfireXO\prxtbXfir.dll [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] 2010-03-25 20:31:46 2355296 —-a-w- C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll" [2010-03-25 20:31:46 2355296] "{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "C:\Program Files (x86)\XfireXO\prxtbXfir.dll" [2011-01-17 23:54:02 175912] [HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Logitech Vid"="C:\Program Files (x86)\Logitech\Vid HD\Vid.exe" [2011-01-13 02:01:28 6129496] "cdloader"="C:\Users\jellybean\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 12:39:04 50592] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-20 21:23:12 5495680] "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-21 00:09:11 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "JMB36X IDE Setup"="C:\Windows\RaidTool\xInsIDE.exe" [2007-03-20 06:36:18 36864] "Desktop Disc Tool"="C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-08-03 16:05:48 498160] "Microsoft Default Manager"="C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 18:12:14 288080] "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe" [2010-09-08 19:17:42 421888] "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" [2010-11-11 08:40:24 421160] "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 19:59:52 254696] "EEventManager"="C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-12-04 20:24:30 665424] "Gateway Photo Frame"="C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe" [2009-07-20 21:07:10 124416] "LogitechQuickCamRibbon"="C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 20:36:56 2793304] "avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe" [2011-09-06 21:45:30 3722416] "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 20:55:28 937920] C:\Users\jellybean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ CNET TechTracker.lnk - C:\Users\jellybean\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe [2011-8-30 2620416] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ GamersFirst LIVE!.lnk - C:\Program Files (x86)\GamersFirst\LIVE!\Live.exe [2011-8-15 2589808] C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy Software Installer.lnk - C:\Program Files\Best Buy Software Installer\Best Buy Software Installer.exe [2009-10-28 1132984] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" R2 0120361321830016mcinstcleanup;McAfee Application Installer Cleanup (0120361321830016);C:\Users\JELLYB~1\AppData\Local\Temp\012036~1.EXE [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 21:16:28 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 22:27:14 138576] R2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 08:22:46 135664] R3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-01 01:44:14 183560] R3 dump_wmimmc;dump_wmimmc;C:\Program Files (x86)\softnyxGame\GunBoundIS\GameGuard\dump_wmimmc.sys [x] R3 EagleX64;EagleX64;C:\Windows\system32\drivers\EagleX64.sys [x] R3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 08:22:46 135664] R3 nosGetPlusHelper;getPlus® Helper 3004;C:\Windows\System32\svchost.exe [2009-07-14 01:39:46 27136] R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe [x] S0 PxHlpa64;PxHlpa64;C:\Windows\System32\Drivers\PxHlpa64.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 16:26:56 14928] S1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 21:55:18 12368] S1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys [x] S2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-11-20 21:23:13 140672] S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 20:55:28 64952] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;C:\Windows\system32\drivers\aswMonFlt.sys [x] S2 Greg_Service;GRegService;C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe [2009-08-28 09:38:58 1150496] S2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 08:47:10 191000] S2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 03:34:22 2314240] S2 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2009-07-04 02:47:12 240160] S3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;C:\Windows\system32\DRIVERS\e1k62x64.sys [x] S3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys [x] S3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys [x] S3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\system32\DRIVERS\LVPr2M64.sys [x] S3 LVUVC64;Logitech Webcam 120(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys [x] [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper Contents of the 'Scheduled Tasks' folder 2011-11-21 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 08:22:49 . 2010-05-01 08:22:46] 2011-11-21 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 08:22:49 . 2010-05-01 08:22:46] 2011-11-20 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3996681575-678226163-2777997048-1000Core.job - C:\Users\jellybean\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 23:15:15 . 2010-10-17 19:31:37] 2011-11-21 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3996681575-678226163-2777997048-1000UA.job - C:\Users\jellybean\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 23:15:15 . 2010-10-17 19:31:37] ——— x86-64 ———– [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 21:45:17 134384 —-a-w- C:\Program Files\AVAST Software\Avast\ashShA64.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 19:25:54 186904] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-28 10:57:38 8312352] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2010-08-26 03:45:04 161304] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2010-08-26 03:44:54 386584] "Persistence"="C:\Windows\system32\igfxpers.exe" [2010-08-26 03:45:00 415256] "combofix"="C:\ComboFix\CF15184.3XE" [2010-11-20 13:24:33 345088]
Looking good BubbleRap!

I would like you to give Malwarebytes another run.
  • Click the Update tab, then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Next, click Scanner, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
===================================================

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI