This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser re-direct

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Having issues with a browser re-direct. It edited my Host file and made it hidden then read only. It also keep updating the proxy address for internet settings every so often. Even when i've fix both of these searches in google it keep re-directing. Sometimes to this address: hxxp://www.kisses-search.net

OTL details below - massive thanks in advance…

OTL logfile created on: 11/20/2011 7:09:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\steve\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.99 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 23.64% Memory free
7.98 Gb Paging File | 4.20 Gb Available in Paging File | 52.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.96 Gb Total Space | 80.21 Gb Free Space | 11.64% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 393.06 Gb Free Space | 42.20% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 233.28 Gb Free Space | 50.09% Space Free | Partition Type: NTFS
Drive F: | 5.49 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 7.28 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 465.76 Gb Total Space | 9.29 Gb Free Space | 2.00% Space Free | Partition Type: NTFS

Computer Name: DELLXPS | User Name: steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\steve\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd)
PRC - C:\Program Files (x86)\Desura\desura.exe (Desura Pty Ltd)
PRC - C:\Users\steve\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\Program Files (x86)\Evernote\Evernote3.5\EvernoteTray.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe ()
PRC - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe (Hauppauge Computer Works, Inc)
PRC - C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe (Hauppauge Computer Works, Inc.)
PRC - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
PRC - C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe (Trend Micro Inc.)
PRC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
PRC - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
PRC - c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
PRC - C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe (SingleClick Systems)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
PRC - C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe ()
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe (Apache Software Foundation)
PRC - C:\Program Files (x86)\Mindjet\MindManager 8\MmReminderService.exe (Mindjet)
PRC - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe ()
PRC - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe ()
PRC - C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe (CyberLink Corp.)
PRC - C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
PRC - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\libglesv2.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\libegl.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-50.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files (x86)\Desura\bin\cef_desura.dll ()
MOD - C:\Program Files (x86)\Desura\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Desura\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Desura\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Desura\bin\wxmsw290u_vc_desura.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libtidy.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libxml2.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libpcre.dll ()
MOD - C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\401d4cd2a06122a32cf094d541dcdd63\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\4ac62cbbdc0e405f1756166dc80edd09\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6afe3a43d112ed5356d73468c5c44045\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\SysWOW64\f5.exe ()
MOD - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\758e0ce53c80a7ad7cf76a4910d27762\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\6b8b76b26be7d7f4c3d1cb644811a2ef\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\c744f0f95227e75796b8689801740d4b\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\935ac020241e59cab3287d5eb38c592d\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f92c882fd4e7005c005e208daa04c28d\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\fdeec42fa02f3d789c42be2e33b130eb\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\5025c0c5e7134226b2fc0c4bdabf67ef\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\3060dfcdecbeb8ee65077fb29b217c3d\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4be2653d1c9804d2ff6e6b66d22764e1\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\500ddd904b1099f95552a81b54223b7f\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f58ab951b57c8526430486dcf7ee38fd\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll ()
MOD - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServerps.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\CppUtils.dll ()
MOD - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
MOD - C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\Windows\SysWOW64\msjetoledb40.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files (x86)\Common Files\Dell\apache\ioncube_loader_win_5.2.dll ()
MOD - C:\Program Files (x86)\Common Files\Dell\apache\libmysql.dll ()
MOD - C:\Program Files (x86)\Mindjet\MindManager 8\zlib.dll ()
MOD - C:\Program Files (x86)\CyberLink\Shared Files\richvideops.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvcPS.dll ()
MOD - C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
MOD - C:\Program Files (x86)\Common Files\Dell\apache\bin\zlib1.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (LVPrcS64) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (Desura Install Service) – C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (Serviio) – C:\Program Files (x86)\Serviio\bin\ServiioService.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (AdobeActiveFileMonitor9.0) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks SAS)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (KMService) – C:\Windows\SysWOW64\srvany.exe ()
SRV - (Hauppauge WinTV Extender) – C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe (Hauppauge Computer Works, Inc)
SRV - (HauppaugeTVServer) – C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (hnmsvc) – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
SRV - (dsl-fs-sync) – C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe (SingleClick Systems)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (VMCService) – C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (RoxMediaDB10) – c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (dsl-db) – C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe ()
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Symantec AntiVirus) – C:\Program Files (x86)\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files (x86)\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (EraserSvc11120) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (Apache2.2) – C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (TVECapSvc) TVEnhance Background Capture Service (TBCS) – C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe ()
SRV - (TVESched) TVEnhance Task Scheduler (TTS)) – C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe ()
SRV - (LiveUpdate) – C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (HCW85BDA) – C:\Windows\SysNative\drivers\HCW85BDA.sys (Hauppauge Computer Works)
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (tap0901) – C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (LVUVC64) Logitech QuickCam Pro 9000(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (VClone) – C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (Ext2Fsd) – C:\Windows\SysNative\drivers\ext2fsd.sys (www.ext2fsd.com)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ewusbnet) – C:\Windows\SysNative\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (Packet) – C:\Windows\SysNative\drivers\packet.sys (SingleClick Systems)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hwdatacard) – C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (SRTSPL) – C:\Windows\SysNative\drivers\srtspl64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (Ext2fs) – C:\Windows\SysNative\drivers\ext2fs.sys (Stephan Schreiber)
DRV:64bit: - (IfsMount) – C:\Windows\SysNative\drivers\ifsmount.sys (Stephan Schreiber)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (ZTEusbser6k) – C:\Windows\SysNative\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbnmea) – C:\Windows\SysNative\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbmdm6k) – C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (LVUSBS64) – C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.)
DRV:64bit: - (lvpepf64) – C:\Windows\SysNative\drivers\lv302a64.sys (Logitech Inc.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20111118.004\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20111118.004\ENG64.SYS (Symantec Corporation)
DRV - (RivaTuner64) – C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\Windows\SysWOW64\drivers\RxFilter.sys (Sonic Solutions)
DRV - (Packet) – C:\Windows\SysWOW64\drivers\packet.sys (SingleClick Systems)
DRV - (SRTSPL) – C:\Windows\SysWOW64\drivers\srtspl64.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\SysWOW64\drivers\srtspx64.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\SysWOW64\drivers\srtsp64.sys (Symantec Corporation)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) – C:\Program Files (x86)\CyberLink\PlayMovie\000.fcl (Cyberlink Corp.)
DRV - (ASPI32) – C:\Windows\SysWow64\drivers\aspi32.sys (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.jp.msn.com/USCON/19
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=302398"
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {bcd47b5a-43be-433f-9051-7ce2cdf94ac0}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.608
FF - prefs.js..extensions.enabledItems: {F0B6E3F9-ECD1-40b6-A25F-5C3FF68FB079}:1.0.1
FF - prefs.js..extensions.enabledItems: {ec268e28-22c6-4a6c-ac22-635cabee283c}:1.0.1
FF - prefs.js..extensions.enabledItems: {AA6F0803-145A-4200-8E5E-68898D02B5B3}:1.1.5
FF - prefs.js..extensions.enabledItems: [removed]:2.0.2
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: TFToolbarX@torrent-finder:1.2.5
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..network.proxy.backup.ftp: "[removed]"
FF - prefs.js..network.proxy.backup.ftp_port: 3128
FF - prefs.js..network.proxy.backup.gopher: "[removed]"
FF - prefs.js..network.proxy.backup.gopher_port: 3128
FF - prefs.js..network.proxy.backup.socks: "[removed]"
FF - prefs.js..network.proxy.backup.socks_port: 3128
FF - prefs.js..network.proxy.backup.ssl: "[removed]"
FF - prefs.js..network.proxy.backup.ssl_port: 3128
FF - prefs.js..network.proxy.ftp: "[removed]"
FF - prefs.js..network.proxy.ftp_port: 3124
FF - prefs.js..network.proxy.gopher: "[removed]"
FF - prefs.js..network.proxy.gopher_port: 3124
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "[removed]"
FF - prefs.js..network.proxy.socks_port: 3124
FF - prefs.js..network.proxy.ssl: "[removed]"
FF - prefs.js..network.proxy.ssl_port: 3124
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 49192
FF - prefs.js..network.proxy.type: 1

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\steve\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\steve\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\steve\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\steve\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\steve\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/01 22:05:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/04/16 15:02:00 | 000,000,000 | —D | M]

[2010/04/15 10:01:05 | 000,000,000 | —D | M] (No name found) – C:\Users\steve\AppData\Roaming\Mozilla\Extensions
[2011/10/20 20:39:55 | 000,000,000 | —D | M] (No name found) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions
[2010/04/16 20:56:09 | 000,000,000 | —D | M] (Right-Click-Link) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{AA6F0803-145A-4200-8E5E-68898D02B5B3}
[2010/07/24 14:12:31 | 000,000,000 | —D | M] (ActiveInbox for Gmail and Google Apps) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{bcd47b5a-43be-433f-9051-7ce2cdf94ac0}
[2010/04/10 11:15:18 | 000,000,000 | —D | M] (Web Developer) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/10/03 15:20:38 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/30 20:23:22 | 000,000,000 | —D | M] ("Tab Mix Plus") – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/04/10 11:15:20 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/04/16 20:56:09 | 000,000,000 | —D | M] (Plain Text Links) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{ec268e28-22c6-4a6c-ac22-635cabee283c}
[2010/04/10 11:15:20 | 000,000,000 | —D | M] ("OpenDownload") – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{F0B6E3F9-ECD1-40b6-A25F-5C3FF68FB079}
[2010/06/09 09:54:31 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]
[2010/06/30 20:23:19 | 000,000,000 | —D | M] (Save File to) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]
[2010/04/22 22:47:14 | 000,000,000 | —D | M] (Ancestry.com Advanced Image Viewer) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]
[2010/04/10 11:15:10 | 000,000,000 | —D | M] (Torrent Finder Toolbar) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\TFToolbarX@torrent-finder
[2010/04/10 11:15:10 | 000,000,000 | —D | M] (URL Suffix) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\urlsuffix@mozilla
[2010/01/22 08:07:10 | 000,001,606 | —- | M] () – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\searchplugins\amazondotcom.xml
[2009/01/11 14:21:06 | 000,001,595 | —- | M] () – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\searchplugins\ebay.xml
[2011/10/20 20:39:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/16 09:48:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/28 19:31:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/04/06 08:23:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/13 16:41:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/04 05:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/06/26 15:20:28 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files (x86)\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2010/04/02 03:56:49 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/04/02 03:56:50 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/04/02 03:56:50 | 000,000,769 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/04/02 03:56:50 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Orbit Downloader (Disabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.71\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\steve\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: ActiveInbox for Gmail\u2122\u200B = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddndffgplldhbjpnlgkdihdlfhipagmf\4.0.3.8_0\
CHR - Extension: ActiveInbox for Gmail\u2122\u200B = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddndffgplldhbjpnlgkdihdlfhipagmf\4.0.3.8_0\content\locales\locale_
CHR - Extension: Smartr Inbox for Gmail = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\gakklmehjhhdfjjgnmpkjoemjmeomnli\0.61_1\
CHR - Extension: Add LinkedIn profile to JobAdder = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcminoiojbaeabfpccladipipdelebcl\1.1.5_0\
CHR - Extension: Poppit = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\

O1 HOSTS File: ([2011/11/20 09:31:09 | 000,000,709 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry_EptMon] C:\Windows\SysNative\EptMon64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [RunDLLEntry_THXCfg] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [autodetect] C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
O4 - HKLM..\Run: [ccApp] C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter File not found
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 8\MmReminderService.exe (Mindjet)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [msconfig.exe] C:\Users\steve\AppData\Roaming\Microsoft\System\Services\msconfig.exe ()
O4 - HKLM..\Run: [PCMAgent] C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [TVEService] C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vptray] C:\Program Files (x86)\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [AirVideoServer] C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe ()
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [Desura] C:\Program Files (x86)\Desura\desura.exe (Desura Pty Ltd)
O4 - HKCU..\Run: [Evernote] C:\Program Files (x86)\Evernote\Evernote3.5\evernote.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe (Softthinks)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\ContentMerger10.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet)
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\steve\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\steve\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1B6295B3-E3F9-4600-8AC0-9F35CE4C4E0E}: DhcpNameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FD173155-D01E-43CB-839C-81F4E538B3C6}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\x-excid - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\Windows\Downloaded Program Files\mimectl.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/30 21:06:55 | 000,000,033 | -HS- | M] () - D:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2011/09/06 18:15:22 | 000,000,051 | R— | M] () - F:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2010/11/10 02:57:14 | 000,000,075 | R— | M] () - G:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{150eaeb0-73cc-11e0-ba3e-a4badb033177}\Shell - "" = AutoRun
O33 - MountPoints2\{150eaeb0-73cc-11e0-ba3e-a4badb033177}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{150eaeb9-73cc-11e0-ba3e-a4badb033177}\Shell - "" = AutoRun
O33 - MountPoints2\{150eaeb9-73cc-11e0-ba3e-a4badb033177}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{c9e5b92c-df3b-11df-a09e-a4badb033177}\Shell - "" = AutoRun
O33 - MountPoints2\{c9e5b92c-df3b-11df-a09e-a4badb033177}\Shell\AutoRun\command - "" = J:\Autorun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Setup.exe – [2011/05/31 20:06:52 | 000,355,920 | R— | M] (Valve Corporation)
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck msln)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.avis - C:\Windows\SysWow64\ff_acm.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\Windows\SysWow64\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 12:50:00 | 000,067,632 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\msln.exe
[2011/11/20 11:36:17 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011/11/20 11:36:17 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011/11/20 11:36:17 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/11/20 11:34:53 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/11/20 11:34:52 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/11/20 11:06:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/11/20 11:01:36 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/11/20 11:01:29 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/11/20 09:22:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/11/20 09:22:46 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/11/20 09:22:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2011/11/20 09:21:44 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/20 09:21:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/11/20 09:01:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\C6EA0
[2011/11/20 09:00:49 | 000,000,000 | -HSD | C] – C:\Users\steve\AppData\Local\2de42b37
[2011/11/20 09:00:37 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\BA5C6
[2011/11/20 09:00:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\LP
[2011/11/20 09:00:28 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\GDocsDrive
[2011/11/16 22:55:47 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{49606A9B-349D-4D49-B907-53E1ED5C5863}
[2011/11/16 22:55:33 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{7378F475-52C8-4712-9A2C-6E10F6B8B57A}
[2011/11/16 20:36:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/11/16 20:32:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/11/14 20:03:53 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{9A0CCF61-B2D5-4C46-9BF1-AD09E4B3490D}
[2011/11/14 20:03:42 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{BE0567DA-DF9B-4BA1-A725-92F9DCA0A2B5}
[2011/11/11 17:51:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/11/08 23:07:30 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{BB8CA1A7-50B6-4E11-B701-03194D1C673C}
[2011/11/08 23:07:18 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{DE729AC6-5163-45FA-BFA2-2A9C79525B33}
[2011/11/06 21:46:45 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Activision
[2011/11/02 20:11:57 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{91FF9FFD-739F-432E-95AA-7AA40E82F34B}
[2011/11/02 20:11:45 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{6793D855-B64A-4796-88F6-71BE88D457DF}
[2011/10/30 08:32:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/10/23 14:11:17 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{27A19C73-7241-455B-8631-64BE0E74CDF9}
[2011/10/23 14:11:05 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{A6618503-815F-4392-91BA-0351FDB7A91B}
[2010/09/13 15:47:15 | 000,109,248 | —- | C] (Microsoft Corporation) – C:\Users\steve\AppData\Roaming\MSWINSCK.OCX
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/20 18:54:05 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4196817925-3903972391-1900847604-1000UA.job
[2011/11/20 18:49:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 13:49:01 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 12:50:00 | 000,067,632 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\msln.exe
[2011/11/20 11:36:38 | 000,001,785 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/11/20 11:33:12 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 11:33:12 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 11:17:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 11:17:02 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2011/11/20 11:16:36 | 3214,135,296 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 11:10:53 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/11/20 09:54:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4196817925-3903972391-1900847604-1000Core.job
[2011/11/20 09:31:09 | 000,000,709 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/11/20 09:22:51 | 000,001,288 | —- | M] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/11/20 09:22:51 | 000,001,264 | —- | M] () – C:\Users\steve\Desktop\Spybot - Search & Destroy.lnk
[2011/11/20 09:21:44 | 000,002,975 | —- | M] () – C:\Users\steve\Desktop\HiJackThis.lnk
[2011/11/20 08:46:17 | 000,000,110 | —- | M] () – C:\Users\steve\Documents\ax_files.xml
[2011/11/20 08:46:02 | 000,001,181 | —- | M] () – C:\Users\Public\Desktop\Alcohol 120%.lnk
[2011/11/20 08:35:19 | 000,730,384 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/20 08:35:19 | 000,630,928 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/20 08:35:19 | 000,111,052 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/16 21:04:36 | 000,218,332 | -H– | M] () – C:\Windows\SysWow64\mlfcache.dat
[2011/10/24 09:46:16 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/20 11:36:38 | 000,001,785 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/11/20 09:22:51 | 000,001,288 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/11/20 09:22:51 | 000,001,264 | —- | C] () – C:\Users\steve\Desktop\Spybot - Search & Destroy.lnk
[2011/11/20 09:21:44 | 000,002,975 | —- | C] () – C:\Users\steve\Desktop\HiJackThis.lnk
[2011/09/16 19:40:41 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2011/05/05 02:28:10 | 000,059,904 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/05/03 22:05:39 | 000,218,332 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/03/18 04:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/02/13 20:28:42 | 000,103,736 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/02/13 20:28:38 | 000,669,184 | —- | C] () – C:\Windows\SysWow64\pbsvc.exe
[2011/02/13 20:28:38 | 000,066,872 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2010/11/30 17:55:23 | 000,007,168 | —- | C] () – C:\Users\steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/06 15:52:32 | 000,000,917 | —- | C] () – C:\Windows\SysWow64\CLWatson.ini
[2010/10/25 21:44:19 | 000,005,015 | —- | C] () – C:\Windows\HCWPNP.INI
[2010/10/14 23:16:43 | 000,237,568 | —- | C] () – C:\Windows\SysWow64\rmc_rtspdl.dll
[2010/10/14 01:36:44 | 000,179,263 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/10/04 09:09:28 | 000,000,135 | —- | C] () – C:\Windows\ODBC.INI
[2010/10/04 09:09:27 | 000,000,209 | —- | C] () – C:\Windows\ODBCINST.INI
[2010/10/04 09:09:00 | 000,142,337 | —- | C] () – C:\Windows\SysWow64\Wait.exe
[2010/09/29 09:50:23 | 000,193,024 | —- | C] () – C:\Windows\SysWow64\f5.exe
[2010/09/18 16:14:54 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/08/04 09:11:56 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\cdga.dll
[2010/08/03 22:50:38 | 000,000,204 | —- | C] () – C:\Windows\MYOBP.INI
[2010/08/03 22:50:38 | 000,000,039 | —- | C] () – C:\Windows\MYOB.INI
[2010/08/03 22:49:57 | 000,000,663 | —- | C] () – C:\Windows\openrda.ini
[2010/08/03 22:49:44 | 000,000,000 | —- | C] () – C:\Windows\drvxl32.INI
[2010/08/03 22:49:43 | 000,000,000 | —- | C] () – C:\Windows\drvwd32.INI
[2010/07/03 13:41:59 | 000,007,622 | —- | C] () – C:\Users\steve\AppData\Local\Resmon.ResmonCfg
[2010/06/12 15:31:36 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\srvany.exe
[2010/05/29 17:15:16 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/05/26 17:17:46 | 000,000,000 | —- | C] () – C:\Windows\PowerReg.dat
[2010/04/12 19:55:59 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/03/25 12:47:52 | 000,177,664 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2010/03/25 12:47:52 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2010/03/25 12:47:52 | 000,001,264 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2010/03/25 12:47:52 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2010/03/25 12:47:52 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2010/02/21 05:48:22 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/01/25 12:58:06 | 000,462,848 | —- | C] () – C:\Windows\SysWow64\ractrlkeyhook.dll
[2009/08/16 11:08:36 | 000,178,176 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2009/07/14 16:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 13:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 13:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 11:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 10:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 08:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/16 14:25:02 | 000,121,512 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
[2009/06/11 08:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/05/29 16:52:26 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/05/29 16:47:06 | 000,761,856 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2007/11/15 06:37:26 | 000,053,299 | —- | C] () – C:\Windows\SysWow64\pthreadVC.dll
[2007/02/05 21:05:26 | 000,000,038 | —- | C] () – C:\Windows\AviSplitter.INI
[2006/05/05 19:26:00 | 000,335,872 | —- | C] () – C:\Windows\SysWow64\ctreestd.dll
[2000/01/31 09:02:00 | 000,047,104 | —- | C] () – C:\Windows\SysWow64\Wh2Robo.dll

========== LOP Check ==========

[2011/11/20 18:53:28 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\BA5C6
[2011/07/02 11:39:08 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/10/24 10:34:13 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\DAEMON Tools Pro
[2011/08/22 20:04:19 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\FileZilla
[2010/06/26 15:20:49 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Foxit
[2010/06/29 20:21:43 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Foxit Software
[2011/11/20 09:00:28 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\GDocsDrive
[2010/04/10 10:34:47 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\GlobalSCAPE
[2011/05/08 10:37:26 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\GrabPro
[2010/08/04 09:10:47 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\HandBrake
[2010/04/11 21:37:09 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\ImgBurn
[2010/04/09 09:28:33 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Leadertech
[2011/05/01 12:54:32 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\ManyCam
[2011/06/04 09:43:09 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Orbit
[2011/03/06 11:05:45 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\PCDr
[2010/11/06 15:55:25 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\PowerCinema
[2010/10/14 23:29:25 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\ProgSense
[2011/10/09 20:37:54 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\redsn0w
[2010/10/13 21:02:07 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\TeraCopy
[2011/06/04 13:47:39 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Unity
[2011/11/20 19:16:12 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\uTorrent
[2011/05/04 21:24:38 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Vodafone
[2010/04/07 23:46:35 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Win7codecs
[2010/04/10 11:14:44 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Windows Live Writer
[2011/06/04 15:51:56 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Xilisoft
[2011/10/24 09:46:16 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2009/07/14 16:08:49 | 000,032,402 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/11/20 11:10:53 | 000,000,506 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/04/27 11:57:21 | 000,001,024 | —- | M] () – C:\.rnd
[2011/06/14 22:09:14 | 000,000,000 | —- | M] () – C:\10.1.19.109
[2010/07/31 22:20:31 | 000,000,165 | —- | M] () – C:\62P3DTNV.dat
[2010/03/26 04:16:22 | 000,004,889 | RH– | M] () – C:\dell.sdr
[2010/10/25 21:32:46 | 000,297,443 | —- | M] () – C:\hcwclear.txt
[2011/11/20 11:16:36 | 3214,135,296 | -HS- | M] () – C:\hiberfil.sys
[2011/04/27 08:40:07 | 000,001,821 | —- | M] () – C:\index.html
[2010/10/25 21:44:52 | 000,001,203 | —- | M] () – C:\install.log
[1995/04/27 00:33:10 | 000,146,976 | —- | M] (Microsoft Corporation) – C:\Mfcoleui.dll
[2011/11/20 11:16:55 | 4285,517,824 | -HS- | M] () – C:\pagefile.sys
[2011/11/20 09:55:27 | 000,087,720 | —- | M] () – C:\TDSSKiller.2.6.19.0_20.11.2011_09.54.30_log.txt
[2011/08/26 09:07:03 | 000,000,222 | —- | M] () – C:\test.txt

< %systemroot%\Fonts\*.com >
[2009/07/14 16:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 16:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 16:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 16:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 07:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 16:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/09/13 14:53:20 | 000,109,248 | —- | M] (Microsoft Corporation) – C:\Users\steve\AppData\Roaming\Microsoft\MSWINSCK.OCX

< %PROGRAMFILES%\*.* >
[2009/07/14 15:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/06 22:07:04 | 000,000,221 | -HS- | M] () – C:\Users\steve\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/06/26 15:20:50 | 000,000,200 | —- | M] () – C:\Users\steve\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay.url

< %USERPROFILE%\Desktop\*.exe >
[2011/07/02 10:38:06 | 1463,636,243 | —- | M] () – C:\Users\steve\Desktop\Adobe Premiere Elements 9.exe
[2011/08/21 11:50:48 | 000,483,328 | —- | M] (Simon Tatham) – C:\Users\steve\Desktop\putty.exe
[2010/08/29 08:59:58 | 000,163,840 | —- | M] () – C:\Users\steve\Desktop\ts-koe.exe
[2003/04/04 11:51:12 | 000,073,728 | —- | M] (eXtalia EXP) – C:\Users\steve\Desktop\ts203.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Files - Unicode (All) ==========
[2010/05/11 21:19:20 | 000,014,683 | —- | M] ()(C:\Windows\SysWow64\?????) – C:\Windows\SysWow64\㲫륫ܨᇓ箝
[2010/05/11 21:19:20 | 000,014,683 | —- | C] ()(C:\Windows\SysWow64\?????) – C:\Windows\SysWow64\㲫륫ܨᇓ箝

========== Alternate Data Streams ==========

@Alternate Data Stream - 160 bytes -> C:\Users\steve\pool_stamp_ivy.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 160 bytes -> C:\Users\steve\Fine_back.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:5D432CE3

< End of report >
Hi bluejam,


Sorry for the delay on replying. The forum is a bit busy at the moment.


Please follow these steps:

Step 1 | Download DDS from any of the links below:

Link 1
Link 2
Link 2

——————————————————————–
  • Save it to your desktop.
  • Please disable any anti-malware program that will block scripts from running before running DDS.
  • Double-Click on dds and a command window will appear. This is normal.
  • Shortly after two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save & post the logs.
  • Save the logs to a convenient place such as your desktop.
  • Post the contents of the DDS.txt report in your next reply.
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.


Step 2 | Please download GMER from one of the following locations and save it to your desktop:

Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

——————————————————————–

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Right-click on the randomly named GMER file (i.e. n7gmo46c.exe) and choose "Run as administrator" to run it. Allow the gmer.sys driver to load if asked.

Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then right-click on gmer.exe and choose "Run as administrator".

[external image: Posted Image]

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Make sure these options are all checked:
  • Services
  • Registry
  • Files
  • Systemdrive drive/partition, which is typically C:\
  • ADS

[external image: Posted Image]
Click the image to enlarge it

  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
– If you encounter any problems, try running GMER in Safe Mode.
Thanks mate - here are the results for all 3 scans…


GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-25 18:46:18
Windows 6.1.7600
Running: 8p1ohb9n.exe


—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xF0 0x07 0xD1 0xB6 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x42 0x6F 0x5A 0x8D …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1F 0xF3 0xB0 0x27 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xF0 0x07 0xD1 0xB6 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x42 0x6F 0x5A 0x8D …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1F 0xF3 0xB0 0x27 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@auditpol C:\Users\steve\AppData\Local\auditpol.exe

—- Files - GMER 1.0.15 —-

File C:\Users\steve\AppData\Local\auditpol.dll 25600 bytes executable
File C:\Users\steve\AppData\Local\auditpol.exe 65536 bytes executable
File C:\Windows\System32\auditpol.exe 64000 bytes executable
File C:\Windows\SysWOW64\auditpol.exe 50176 bytes executable
File C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7600.16385_none_23376bf5921e7b63\auditpol.exe 64000 bytes executable
File C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7600.16385_none_c718d071d9c10a2d\auditpol.exe 50176 bytes executable

—- EOF - GMER 1.0.15 —-



.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_26
Run by [removed] at 9:57:35 on 2011-11-25
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.61.1033.18.4087.1727 [GMT 11:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Symantec AntiVirus\DefWatch.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\PROGRA~2\WinTV\Extend\WINTVE~1.EXE
C:\PROGRA~2\WinTV\TVServer\HAUPPA~1.EXE
c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
C:\Program Files (x86)\Serviio\bin\ServiioService.exe
C:\Program Files (x86)\Serviio\bin\ServiioService.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Symantec AntiVirus\Rtvscan.exe
C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe
C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe
C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wuauclt.exe
C:\Users\steve\AppData\Local\auditpol.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe
C:\Program Files (x86)\Symantec AntiVirus\VPTray.exe
C:\Program Files (x86)\Mindjet\MindManager 8\MmReminderService.exe
C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe
C:\Program Files (x86)\Evernote\Evernote3.5\EvernoteTray.exe
C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe
C:\Program Files (x86)\Serviio\bin\ServiioConsole.exe
C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe
C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe
C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe
C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Windows\explorer.exe
C:\Windows\explorer.exe
C:\Program Files (x86)\Medieval Software\Medieval CUE Splitter\CUE_Splitter.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\steve\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\splwow64.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\lws.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\steve\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: CmjBrowserHelperObject Object: {6fe6a929-59d1-4763-91ad-29b61cffb35b} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [AirVideoServer] C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe
uRun: [Evernote] "C:\Program Files (x86)\Evernote\Evernote3.5\evernote.exe" /minimized
uRun: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
uRun: [Desura] C:\Program Files (x86)\Desura\desura.exe -autostart
uRun: [Google Update] "C:\Users\steve\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [auditpol] C:\Users\steve\AppData\Local\auditpol.exe
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
mRun: [vptray] C:\PROGRA~2\SYMANT~1\VPTray.exe
mRun: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 8\MMReminderService.exe
mRun: [autodetect] C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
mRun: []
mRun: [PCMAgent] "C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe"
mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe"
mRun: [PlayMovie] "C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe"
mRun: [TVEService] "C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [auditpol] C:\Users\steve\AppData\Local\auditpol.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRun: [msconfig.exe] C:\Users\steve\AppData\Roaming\Microsoft\System\Services\msconfig.exe
mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRunOnce: [Launcher] C1\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
StartupFolder: C:\Users\steve\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files (x86)\Logitech\Ereg\eReg.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEA~1.LNK - C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEA~2.LNK - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DRIVER~1.LNK - C:\Program Files\DriveRestore Professional\DriveRestore.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\EVERNO~1.LNK - C:\Windows\Installer\{F761359C-9CED-45AE-9A51-9D6605CD55C4}\Evernote.ico
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Serviio.lnk - C:\Program Files (x86)\Serviio\bin\ServiioConsole.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WINTVR~1.LNK - C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\steve\Desktop\PartyPoker.lnk
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2F72393D-2472-4F82-B600-ED77F354B7FF} - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll
IE: {36ECAF82-3300-8F84-092E-AFF36D6C7040} - {86529161-034E-4F8A-88D2-3C625E612E04} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{1B6295B3-E3F9-4600-8AC0-9F35CE4C4E0E} : DhcpNameServer = 8.8.8.8
TCP: Interfaces\{FD173155-D01E-43CB-839C-81F4E538B3C6} : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\Windows\Downloaded Program Files\mimectl.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: SnagIt Toolbar Loader: {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll
BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-X64: 0x1 - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64: Search Helper - No File
BHO-X64: CmjBrowserHelperObject Object: {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
TB-X64: Snagit: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB-X64: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB-X64: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
EB-X64: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - No File
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
mRun-x64: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun-x64: [UpdReg] C:\Windows\UpdReg.EXE
mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun-x64: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
mRun-x64: [vptray] C:\PROGRA~2\SYMANT~1\VPTray.exe
mRun-x64: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 8\MMReminderService.exe
mRun-x64: [autodetect] C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe
mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
mRun-x64: [(Default)]
mRun-x64: [PCMAgent] "C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe"
mRun-x64: [CLMLServer] "C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe"
mRun-x64: [PlayMovie] "C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe"
mRun-x64: [TVEService] "C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [auditpol] C:\Users\steve\AppData\Local\auditpol.exe
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRun-x64: [msconfig.exe] C:\Users\steve\AppData\Roaming\Microsoft\System\Services\msconfig.exe
mRun-x64: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRunOnce-x64: [Launcher] C1\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE-X64: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\steve\Desktop\PartyPoker.lnk
IE-X64: {B1F8A311-6DCF-4B63-9068-8EB0E21129A1} - C:\Microgaming\Casino\AllSlots\casinogame.exe
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au
FF - prefs.js: network.proxy.ftp - 134.226.52.34
FF - prefs.js: network.proxy.ftp_port - 3124
FF - prefs.js: network.proxy.gopher - [removed]
FF - prefs.js: network.proxy.gopher_port - 3124
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 49192
FF - prefs.js: network.proxy.socks - [removed]
FF - prefs.js: network.proxy.socks_port - 3124
FF - prefs.js: network.proxy.ssl - 134.226.52.34
FF - prefs.js: network.proxy.ssl_port - 3124
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.71\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll
FF - plugin: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\steve\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\steve\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]\plugins\npRACtrl.dll
FF - plugin: C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]\plugins\npImgCtl.dll
FF - plugin: C:\Users\steve\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\steve\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Plain Text Links: {ec268e28-22c6-4a6c-ac22-635cabee283c} - %profile%\extensions\{ec268e28-22c6-4a6c-ac22-635cabee283c}
FF - Ext: OpenDownload: {F0B6E3F9-ECD1-40b6-A25F-5C3FF68FB079} - %profile%\extensions\{F0B6E3F9-ECD1-40b6-A25F-5C3FF68FB079}
FF - Ext: Right-Click-Link: {AA6F0803-145A-4200-8E5E-68898D02B5B3} - %profile%\extensions\{AA6F0803-145A-4200-8E5E-68898D02B5B3}
FF - Ext: Web Developer: {c45c406e-ab73-11d8-be73-000a95be3b12} - %profile%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
FF - Ext: Tab Mix Plus: {dc572301-7619-498c-a57d-39143191b318} - %profile%\extensions\{dc572301-7619-498c-a57d-39143191b318}
FF - Ext: LogMeIn, Inc. Remote Access Plugin: [removed] - %profile%\extensions\[removed]
FF - Ext: ActiveInbox for Gmail and Google Apps: {bcd47b5a-43be-433f-9051-7ce2cdf94ac0} - %profile%\extensions\{bcd47b5a-43be-433f-9051-7ce2cdf94ac0}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Save File to: [removed] - %profile%\extensions\[removed]
FF - Ext: Torrent Finder Toolbar: TFToolbarX@torrent-finder - %profile%\extensions\TFToolbarX@torrent-finder
FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: Ancestry.com Advanced Image Viewer: [removed] - %profile%\extensions\[removed]
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 Ext2fs;Ext2fs;C:\Windows\system32\DRIVERS\ext2fs.sys –> C:\Windows\system32\DRIVERS\ext2fs.sys [?]
R1 IfsMount;IfsMount;C:\Windows\system32\DRIVERS\ifsmount.sys –> C:\Windows\system32\DRIVERS\ifsmount.sys [?]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files (x86)\CyberLink\PlayMovie\000.fcl [2010-11-6 32240]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-9-6 169408]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2008-8-11 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\Windows\system32\drivers\LMIRfsDriver.sys –> C:\Windows\system32\drivers\LMIRfsDriver.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys –> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-11-18 138360]
R3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\system32\drivers\LVUSBS64.sys –> C:\Windows\system32\drivers\LVUSBS64.sys [?]
R3 LVUVC64;Logitech HD Pro Webcam C910(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys –> C:\Windows\system32\DRIVERS\lvuvc64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?]
R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\Dell Support Center\pcdsrvc_x64.pkms [2011-10-6 25072]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys –> C:\Windows\system32\Drivers\RtsUStor.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\system32\DRIVERS\ewusbnet.sys –> C:\Windows\system32\DRIVERS\ewusbnet.sys [?]
S3 Ext2Fsd;Linux ext2 file system driver;C:\Windows\system32\drivers\Ext2Fsd.sys –> C:\Windows\system32\drivers\Ext2Fsd.sys [?]
S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys –> C:\Windows\system32\drivers\HCW85BDA.sys [?]
S3 lvpepf64;Volume Adapter;C:\Windows\system32\DRIVERS\lv302a64.sys –> C:\Windows\system32\DRIVERS\lv302a64.sys [?]
S3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\system32\DRIVERS\LVPr2M64.sys –> C:\Windows\system32\DRIVERS\LVPr2M64.sys [?]
S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys –> C:\Windows\system32\DRIVERS\lvrs64.sys [?]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys –> C:\Windows\system32\drivers\nvhda64v.sys [?]
S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2009-8-23 19952]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?]
.
=============== Created Last 30 ================
.
2011-11-24 21:31:53 ——– d—–w- C:\Users\steve\AppData\Roaming\Visual Explorer Ultimate
2011-11-24 21:31:53 ——– d—–w- C:\Program Files (x86)\Visual Explorer Ultimate
2011-11-24 20:52:04 ——– d—–w- C:\Users\steve\AppData\Local\{B736F20D-8FF9-4019-AD8C-31A56907B8AD}
2011-11-24 20:51:52 ——– d—–w- C:\Users\steve\AppData\Local\{6B9EC3DD-EB4C-4533-A7A0-CE3B4C5694A9}
2011-11-23 04:04:11 ——– d—–w- C:\Users\steve\AppData\Local\Logitech® Webcam Software
2011-11-23 04:00:09 53248 —-a-r- C:\Users\steve\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-11-23 03:59:52 ——– d—–w- C:\Program Files (x86)\Common Files\LWS
2011-11-23 03:46:51 ——– d—–w- C:\Users\steve\AppData\Local\{3748AEA7-3F5A-45B7-B93E-9CE50A3BC24B}
2011-11-23 03:46:39 ——– d—–w- C:\Users\steve\AppData\Local\{0DA68A44-2805-4260-8DD0-FF127379580A}
2011-11-21 03:41:28 ——– d—–w- C:\Users\steve\AppData\Local\{9A2C4190-20BA-4E68-8167-A8E43A6759F7}
2011-11-21 03:41:16 ——– d—–w- C:\Users\steve\AppData\Local\{FA9669C6-9F2D-494E-83DF-F28922AB4CED}
2011-11-20 21:10:43 ——– d—–w- C:\Program Files (x86)\ESET
2011-11-20 01:50:00 67632 —-a-w- C:\Windows\System32\msln.exe
2011-11-20 00:36:17 34152 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2011-11-20 00:36:17 126312 —-a-w- C:\Windows\System32\GEARAspi64.dll
2011-11-20 00:36:17 107368 —-a-w- C:\Windows\SysWow64\GEARAspi.dll
2011-11-20 00:34:53 ——– d—–w- C:\Program Files\iPod
2011-11-20 00:34:52 ——– d—–w- C:\Program Files\iTunes
2011-11-20 00:01:36 ——– d—–w- C:\Program Files\Bonjour
2011-11-19 22:35:19 8570192 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{840A8954-135A-4132-9770-15C5EA471501}\mpengine.dll
2011-11-19 22:35:18 270720 ——w- C:\Windows\System32\MpSigStub.exe
2011-11-19 22:22:46 ——– d—–w- C:\ProgramData\Spybot - Search & Destroy
2011-11-19 22:22:46 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-11-19 22:21:44 388096 —-a-r- C:\Users\steve\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-11-19 22:21:43 ——– d—–w- C:\Program Files (x86)\Trend Micro
2011-11-19 22:15:19 709968 —-a-w- C:\Windows\isRS-000.tmp
2011-11-19 22:01:15 ——– d—–w- C:\Program Files (x86)\C6EA0
2011-11-19 22:00:49 ——– d-sh–w- C:\Users\steve\AppData\Local\2de42b37
2011-11-19 22:00:37 ——– d—–w- C:\Users\steve\AppData\Roaming\BA5C6
2011-11-19 22:00:35 ——– d—–w- C:\Program Files (x86)\LP
2011-11-19 22:00:34 65536 –sh–w- C:\Users\steve\AppData\Local\auditpol.exe
2011-11-19 22:00:34 25600 –sh–w- C:\Users\steve\AppData\Local\auditpol.dll
2011-11-19 22:00:28 ——– d—–w- C:\Users\steve\AppData\Roaming\GDocsDrive
2011-11-16 11:55:47 ——– d—–w- C:\Users\steve\AppData\Local\{49606A9B-349D-4D49-B907-53E1ED5C5863}
2011-11-16 11:55:33 ——– d—–w- C:\Users\steve\AppData\Local\{7378F475-52C8-4712-9A2C-6E10F6B8B57A}
2011-11-16 09:36:27 ——– d—–w- C:\Program Files (x86)\iTunes
2011-11-14 09:03:53 ——– d—–w- C:\Users\steve\AppData\Local\{9A0CCF61-B2D5-4C46-9BF1-AD09E4B3490D}
2011-11-14 09:03:42 ——– d—–w- C:\Users\steve\AppData\Local\{BE0567DA-DF9B-4BA1-A725-92F9DCA0A2B5}
2011-11-08 12:07:30 ——– d—–w- C:\Users\steve\AppData\Local\{BB8CA1A7-50B6-4E11-B701-03194D1C673C}
2011-11-08 12:07:18 ——– d—–w- C:\Users\steve\AppData\Local\{DE729AC6-5163-45FA-BFA2-2A9C79525B33}
2011-11-06 10:46:45 ——– d—–w- C:\Users\steve\AppData\Local\Activision
2011-11-02 09:11:57 ——– d—–w- C:\Users\steve\AppData\Local\{91FF9FFD-739F-432E-95AA-7AA40E82F34B}
2011-11-02 09:11:45 ——– d—–w- C:\Users\steve\AppData\Local\{6793D855-B64A-4796-88F6-71BE88D457DF}
.
==================== Find3M ====================
.
2011-09-04 07:33:59 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-31 06:00:50 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-30 12:05:32 96104 —-a-w- C:\Windows\System32\dns-sd.exe
2011-08-30 12:05:32 85864 —-a-w- C:\Windows\System32\dnssd.dll
2011-08-30 12:05:04 83816 —-a-w- C:\Windows\SysWow64\dns-sd.exe
2011-08-30 12:05:04 73064 —-a-w- C:\Windows\SysWow64\dnssd.dll
.
============= FINISH: 9:59:02.16 ===============

Attachments:

Hi bluejam, thanks for the logs.

You are using peer-to-peer programs, specifically uTorrent.
These are what we call an optional removal. However, anytime you are running any type of peer-to-peer application, you are more prone to infection by malware, and this is probably how you became infected in the first place. The choice to remove them is entirely up to you, but I would strongly recommend that you do.
If you do not want to, please at least refrain from using any peer-to-peer programs for the remainder of my fix.

I have a couple of questions that will help me understand what kind of infection we are facing:

1. Are you running a web server on this machine?
2. You are using a proxy server from Ireland for different protocols (http, ftp, etc.) in Firefox. Are you aware of this?


Please follow these steps:

Step 1 | Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it

Step 2 | Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2

  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select "Run As Administrator" (Vista-W7).
  • When prompted to run the scan, click Yes.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt)

Step 3 | Please go to the following site to scan a file: Virus Total

  • Click on Browse, and upload the following file for analysis:

    • C:\Users\steve\AppData\Local\auditpol.exe
      C:\Windows\isRS-000.tmp
      C:\Users\steve\AppData\Local\auditpol.dll
  • Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
  • If it says already scanned – click "reanalyze now"
  • Please post the results in your next reply.

Step 4 | Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2


——————————————————————–
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :dir
    C:\Users\steve\AppData\Local\2de42b37 /s
    C:\Users\steve\AppData\Roaming\BA5C6 /s
    C:\Program Files (x86)\C6EA0 /s
    C:\Program Files (x86)\LP /s

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hi, Thanks - good advice i've turned off utorrent. I only use Chrome now - i rarely use Firefox or IE - however they did have the redirect occuring with them too. At the time of infection the malware edited my hosts file and made it hidden. I fixed this by removing the Ip redirect in the host , unhidding and making it read only - this stopped it being written too. The proxy server settings in chrome/ie/firefox kept being changed too although this seems to have stopped since malware remove aduitpol.exe Malware removed auditpol.exe 2 days ago and the re-direct fixed itself for a little then reverted on occasion (if i reboot i think) The scans have it seems found positive results - here they are - again thanks in advance. aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-28 21:48:35 —————————– 21:48:35.108 OS Version: Windows x64 6.1.7600 21:48:35.108 Number of processors: 8 586 0x1A05 21:48:35.109 ComputerName: DELLXPS UserName: steve 21:49:06.334 Initialize success 21:54:39.437 AVAST engine defs: 11112800 21:58:19.398 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 21:58:19.402 Disk 0 Vendor: Hitachi_ ST6O Size: 953869MB BusType: 3 21:58:19.404 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-1 21:58:19.406 Disk 1 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3 21:58:19.408 Disk 2 (boot) \Device\Harddisk2\DR2 -> \Device\Ide\IAAStorageDevice-2 21:58:19.410 Disk 2 Vendor: ST375052 CC45 Size: 715404MB BusType: 3 21:58:19.412 Disk 3 \Device\Harddisk3\DR3 -> \Device\Ide\IAAStorageDevice-3 21:58:19.414 Disk 3 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3 21:58:19.417 Disk 2 MBR read error 0 21:58:19.419 Disk 2 MBR scan 21:58:19.426 Disk 2 unknown MBR code 21:58:19.429 MBR BIOS signature not found 0 21:58:19.432 Service scanning 21:58:26.465 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 21:58:28.723 Modules scanning 21:58:28.727 Disk 2 trace - called modules: 21:58:28.749 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa80040a9d40]<< 21:58:28.753 1 nt!IofCallDriver -> \Device\Harddisk2\DR2[0xfffffa8004d24060] 21:58:29.930 AVAST engine scan C:\Windows 21:58:29.953 AVAST engine scan C:\Windows\system32 21:58:29.961 AVAST engine scan C:\Windows\system32\drivers 21:58:29.966 AVAST engine scan C:\Users\steve 21:58:29.973 AVAST engine scan C:\ProgramData 21:58:29.977 Scan finished successfully 21:58:52.679 Disk 2 MBR has been saved successfully to "C:\Users\steve\Desktop\fix\MBR.dat" 21:58:52.686 The log file has been saved successfully to "C:\Users\steve\Desktop\fix\aswMBR.txt" GooredFix by jpshortstuff (03.07.10.1) Log created at 21:51 on 28/11/2011 (steve) Firefox version 3.6.6 (en-GB) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files (x86)\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [23:00 14/04/2010] {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [22:48 15/04/2010] {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [08:31 28/08/2010] {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [21:23 05/04/2011] {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [05:41 13/07/2011] C:\Users\steve\Application Data\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\ [removed] [22:54 08/06/2010] [removed] [09:23 30/06/2010] [removed] [11:47 22/04/2010] TFToolbarX@torrent-finder [22:09 06/02/2010] urlsuffix@mozilla [06:28 30/12/2008] {AA6F0803-145A-4200-8E5E-68898D02B5B3} [09:56 16/04/2010] {bcd47b5a-43be-433f-9051-7ce2cdf94ac0} [03:12 24/07/2010] {c45c406e-ab73-11d8-be73-000a95be3b12} [08:47 04/10/2009] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [04:20 03/10/2010] {dc572301-7619-498c-a57d-39143191b318} [09:23 30/06/2010] {E2883E8F-472F-4fb0-9522-AC9BF37916A7} [10:32 09/03/2010] {ec268e28-22c6-4a6c-ac22-635cabee283c} [09:56 16/04/2010] {F0B6E3F9-ECD1-40b6-A25F-5C3FF68FB079} [01:47 02/09/2009] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] (Key not found) -=E.O.F=- File name: isRS-000.tmp Submission date: 2011-11-28 10:53:52 (UTC) Current status: finished Result: 0/ 43 (0.0%) File name: auditpol.dll Submission date: 2011-11-28 10:55:48 (UTC) Current status: finished Result: 14/ 43 (32.6%) TableTabulatedCSVHTMLBBCodeShow positives only Antivirus Version Last update Result AhnLab-V3 2011.11.27.00 2011.11.27 Trojan/Win32.Jorik AntiVir 7.11.18.80 2011.11.28 TR/Crypt.XPACK.Gen3 Antiy-AVL 2.0.3.7 2011.11.28 - Avast 6.0.1289.0 2011.11.28 Win32:Downloader-LNE [Trj] AVG 10.0.0.1190 2011.11.28 Generic25.CKSH BitDefender 7.2 2011.11.28 - ByteHero 1.0.0.1 2011.11.14 - CAT-QuickHeal 12.00 2011.11.28 - ClamAV 0.97.3.0 2011.11.28 - Commtouch 5.3.2.6 2011.11.28 - Comodo 10791 2011.11.27 - DrWeb 5.0.2.03300 2011.11.28 BackDoor.Cleaman Emsisoft 5.1.0.11 2011.11.28 Trojan-Dropper!IK eSafe 7.0.17.0 2011.11.27 - eTrust-Vet 37.0.9590 2011.11.28 - F-Prot 4.6.5.141 2011.11.27 - F-Secure 9.0.16440.0 2011.11.28 - Fortinet 4.3.370.0 2011.11.27 W32/PackedJkXtoobr.C!tr GData 22 2011.11.28 Win32:Downloader-LNE Ikarus T3.1.1.109.0 2011.11.28 Trojan-Dropper Jiangmin 13.0.900 2011.11.27 - K7AntiVirus 9.119.5542 2011.11.25 - Kaspersky 9.0.0.837 2011.11.28 HEUR:Trojan.Win32.Generic McAfee 5.400.0.1158 2011.11.28 - McAfee-GW-Edition 2010.1D 2011.11.28 - Microsoft 1.7801 2011.11.28 Trojan:Win32/Cleaman.B NOD32 6665 2011.11.28 a variant of Win32/Kryptik.VSE Norman 6.07.13 2011.11.27 W32/Kryptik.ATE nProtect 2011-11-28.02 2011.11.28 - Panda 10.0.3.5 2011.11.27 - PCTools 8.0.0.5 2011.11.28 - Prevx 3.0 2011.11.28 - Rising 23.86.00.01 2011.11.28 - Sophos 4.71.0 2011.11.28 - SUPERAntiSpyware 4.40.0.1006 2011.11.26 Trojan.Agent/Gen-Frauder Symantec 20111.2.0.82 2011.11.28 - TheHacker 6.7.0.1.350 2011.11.27 - TrendMicro 9.500.0.1008 2011.11.28 - TrendMicro-HouseCall 9.500.0.1008 2011.11.28 - VBA32 3.12.16.4 2011.11.25 - VIPRE 11169 2011.11.28 - ViRobot 2011.11.28.4797 2011.11.28 - VirusBuster 14.1.87.0 2011.11.27 - MD5: d6857ef178b59d5e7565633202edd526 SHA1: 93c218192d454ded8ddfcccdf79eac5877961b26 SHA256: 54fb83c7e372e2d28a9f4394c66e04b6d5c2b084ebe235a7d43ff8495093b15d File size: 25600 bytes Scan date: 2011-11-28 10:55:48 (UTC) SystemLook 30.07.11 by jpshortstuff Log created at 21:59 on 28/11/2011 by steve Administrator - Elevation successful WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results. ========== dir ========== C:\Users\steve\AppData\Local\2de42b37 - Parameters: "/s" —Files— @ –ahs– 2048 bytes [22:00 19/11/2011] [22:00 19/11/2011] C:\Users\steve\AppData\Local\2de42b37\U d–hs– [22:00 19/11/2011] C:\Users\steve\AppData\Roaming\BA5C6 - Parameters: "/s" —Files— 6EA0.A5C –a—- 8095 bytes [22:00 19/11/2011] [03:46 20/11/2011] No folders found. C:\Program Files (x86)\C6EA0 - Parameters: "/s" —Files— None found. No folders found. C:\Program Files (x86)\LP - Parameters: "/s" —Files— None found. C:\Program Files (x86)\LP\177B d—— [22:00 19/11/2011] 637.tmp –a—- 0 bytes [22:00 19/11/2011] [22:00 19/11/2011] 7445.tmp –a—- 0 bytes [00:23 20/11/2011] [00:23 20/11/2011] 9F0E.tmp –a—- 0 bytes [22:01 19/11/2011] [22:01 19/11/2011] D088.tmp –a—- 0 bytes [00:24 20/11/2011] [00:24 20/11/2011] -= EOF =-
Hi bluejam, thanks for the logs and the additional information.

Please follow these steps:


Step 1 | Please download DeFogger to your desktop.

  • Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.


Step 2 | Please Download TDSSKiller.zip

  • Double-click on TDSSKiller.exe to run the application.
  • Click on the Start Scan button and wait for the scan and disinfection process to be over.
  • If an infected file is detected, the default action will be Cure, click on Continue
    [external image: Posted Image]
  • If a suspicious file is detected, the default action will be Skip, click on Continue
    [external image: Posted Image]
  • If you are asked to reboot the computer to complete the process, click on the Reboot Now button. A report will be automatically saved at the root of the System drive ((usually C:\) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" (for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt). Please copy and paste the contents of that file here.
  • If no reboot is required, click on Report. A log file will appear. Please copy and paste the contents of that file in your next reply.

Step 3 | Please run aswMBR one more time, with the instructions from my previous post.
Hi,

I rebooted and Malware Bytes detected and quarantined auditpol.dll again - i've seen this twice now. The scan also picks auditpol up - i tried to delete but the file is locked. While running aswmbr Symantec found Trojan.Gen.2 in the avast4 temp folder and quarantined it.

I'll await your next steps..thanks again

TFSSKiller report is as follows:


08:57:17.0014 1156 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
08:57:17.0552 1156 ============================================================
08:57:17.0552 1156 Current date / time: 2011/12/04 08:57:17.0552
08:57:17.0552 1156 SystemInfo:
08:57:17.0552 1156
08:57:17.0552 1156 OS Version: 6.1.7600 ServicePack: 0.0
08:57:17.0552 1156 Product type: Workstation
08:57:17.0552 1156 ComputerName: DELLXPS
08:57:17.0552 1156 UserName: steve
08:57:17.0553 1156 Windows directory: C:\Windows
08:57:17.0553 1156 System windows directory: C:\Windows
08:57:17.0553 1156 Running under WOW64
08:57:17.0553 1156 Processor architecture: Intel x64
08:57:17.0553 1156 Number of processors: 8
08:57:17.0553 1156 Page size: 0x1000
08:57:17.0553 1156 Boot type: Normal boot
08:57:17.0553 1156 ============================================================
08:57:18.0446 1156 Initialize success
08:57:26.0328 7208 ============================================================
08:57:26.0328 7208 Scan started
08:57:26.0328 7208 Mode: Manual;
08:57:26.0328 7208 ============================================================
08:57:27.0013 7208 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
08:57:27.0015 7208 1394ohci - ok
08:57:27.0060 7208 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
08:57:27.0064 7208 ACPI - ok
08:57:27.0084 7208 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
08:57:27.0101 7208 AcpiPmi - ok
08:57:27.0153 7208 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
08:57:27.0182 7208 adp94xx - ok
08:57:27.0218 7208 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
08:57:27.0237 7208 adpahci - ok
08:57:27.0272 7208 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
08:57:27.0285 7208 adpu320 - ok
08:57:27.0327 7208 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
08:57:27.0358 7208 AFD - ok
08:57:27.0383 7208 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
08:57:27.0400 7208 agp440 - ok
08:57:27.0423 7208 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
08:57:27.0436 7208 aliide - ok
08:57:27.0526 7208 ALSysIO - ok
08:57:27.0561 7208 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
08:57:27.0582 7208 amdide - ok
08:57:27.0619 7208 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
08:57:27.0646 7208 AmdK8 - ok
08:57:27.0854 7208 amdkmdag (0415ffe1b6a6ea141feafca57567f57f) C:\Windows\system32\DRIVERS\atikmdag.sys
08:57:28.0127 7208 amdkmdag - ok
08:57:28.0183 7208 amdkmdap (dc24d6f38f17c0d643d9aa8a6852f8d0) C:\Windows\system32\DRIVERS\atikmpag.sys
08:57:28.0216 7208 amdkmdap - ok
08:57:28.0248 7208 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
08:57:28.0272 7208 AmdPPM - ok
08:57:28.0283 7208 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
08:57:28.0295 7208 amdsata - ok
08:57:28.0340 7208 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
08:57:28.0360 7208 amdsbs - ok
08:57:28.0379 7208 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
08:57:28.0379 7208 amdxata - ok
08:57:28.0418 7208 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
08:57:28.0430 7208 AppID - ok
08:57:28.0456 7208 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
08:57:28.0469 7208 arc - ok
08:57:28.0484 7208 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
08:57:28.0501 7208 arcsas - ok
08:57:28.0529 7208 ASPI32 - ok
08:57:28.0559 7208 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
08:57:28.0577 7208 AsyncMac - ok
08:57:28.0610 7208 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
08:57:28.0630 7208 atapi - ok
08:57:28.0688 7208 AtiHDAudioService (dbb487d09f56c674430ac454fd8bcab9) C:\Windows\system32\drivers\AtihdW76.sys
08:57:28.0717 7208 AtiHDAudioService - ok
08:57:28.0794 7208 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
08:57:28.0822 7208 b06bdrv - ok
08:57:28.0861 7208 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
08:57:28.0876 7208 b57nd60a - ok
08:57:28.0911 7208 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
08:57:28.0928 7208 Beep - ok
08:57:28.0978 7208 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
08:57:28.0996 7208 blbdrive - ok
08:57:29.0064 7208 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
08:57:29.0066 7208 bowser - ok
08:57:29.0096 7208 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
08:57:29.0114 7208 BrFiltLo - ok
08:57:29.0133 7208 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
08:57:29.0144 7208 BrFiltUp - ok
08:57:29.0235 7208 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
08:57:29.0260 7208 Brserid - ok
08:57:29.0301 7208 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
08:57:29.0324 7208 BrSerWdm - ok
08:57:29.0351 7208 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
08:57:29.0361 7208 BrUsbMdm - ok
08:57:29.0375 7208 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
08:57:29.0387 7208 BrUsbSer - ok
08:57:29.0407 7208 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
08:57:29.0419 7208 BTHMODEM - ok
08:57:29.0483 7208 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
08:57:29.0483 7208 cdfs - ok
08:57:29.0582 7208 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
08:57:29.0601 7208 cdrom - ok
08:57:29.0628 7208 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
08:57:29.0646 7208 circlass - ok
08:57:29.0687 7208 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
08:57:29.0690 7208 CLFS - ok
08:57:29.0717 7208 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
08:57:29.0729 7208 CmBatt - ok
08:57:29.0776 7208 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
08:57:29.0793 7208 cmdide - ok
08:57:29.0827 7208 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
08:57:29.0832 7208 CNG - ok
08:57:29.0854 7208 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
08:57:29.0866 7208 Compbatt - ok
08:57:29.0878 7208 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
08:57:29.0892 7208 CompositeBus - ok
08:57:29.0915 7208 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
08:57:29.0927 7208 crcdisk - ok
08:57:29.0984 7208 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
08:57:29.0986 7208 DfsC - ok
08:57:30.0001 7208 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
08:57:30.0015 7208 discache - ok
08:57:30.0054 7208 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
08:57:30.0056 7208 Disk - ok
08:57:30.0106 7208 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
08:57:30.0120 7208 drmkaud - ok
08:57:30.0181 7208 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
08:57:30.0200 7208 DXGKrnl - ok
08:57:30.0290 7208 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
08:57:30.0357 7208 ebdrv - ok
08:57:30.0452 7208 eeCtrl (5ccf1be80930aeb1cdebf561666325e8) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
08:57:30.0470 7208 eeCtrl - ok
08:57:30.0542 7208 ElbyCDIO (9a47ac3dfcf81d30922cdaaf1c2d579f) C:\Windows\system32\Drivers\ElbyCDIO.sys
08:57:30.0555 7208 ElbyCDIO - ok
08:57:30.0578 7208 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
08:57:30.0596 7208 elxstor - ok
08:57:30.0652 7208 EraserUtilDrv11120 - ok
08:57:30.0706 7208 EraserUtilRebootDrv (7a898e4a744621711be7e7b796c69876) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
08:57:30.0707 7208 EraserUtilRebootDrv - ok
08:57:30.0727 7208 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
08:57:30.0738 7208 ErrDev - ok
08:57:30.0806 7208 ewusbnet (251af86e0a4ddf3a6b181ed5103b06b1) C:\Windows\system32\DRIVERS\ewusbnet.sys
08:57:30.0818 7208 ewusbnet - ok
08:57:30.0841 7208 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
08:57:30.0855 7208 exfat - ok
08:57:30.0903 7208 Ext2fs (a08acad7835c27415bab7e5a16e78eeb) C:\Windows\system32\DRIVERS\ext2fs.sys
08:57:30.0905 7208 Ext2fs - ok
08:57:30.0961 7208 Ext2Fsd (77541bb9ea03008ff40035f2d3ef114e) C:\Windows\system32\drivers\Ext2Fsd.sys
08:57:30.0995 7208 Ext2Fsd - ok
08:57:31.0018 7208 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
08:57:31.0019 7208 fastfat - ok
08:57:31.0042 7208 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
08:57:31.0053 7208 fdc - ok
08:57:31.0077 7208 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
08:57:31.0078 7208 FileInfo - ok
08:57:31.0097 7208 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
08:57:31.0109 7208 Filetrace - ok
08:57:31.0122 7208 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
08:57:31.0132 7208 flpydisk - ok
08:57:31.0155 7208 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
08:57:31.0158 7208 FltMgr - ok
08:57:31.0172 7208 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
08:57:31.0178 7208 FsDepends - ok
08:57:31.0195 7208 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
08:57:31.0207 7208 Fs_Rec - ok
08:57:31.0267 7208 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
08:57:31.0269 7208 fvevol - ok
08:57:31.0289 7208 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
08:57:31.0304 7208 gagp30kx - ok
08:57:31.0348 7208 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
08:57:31.0360 7208 GEARAspiWDM - ok
08:57:31.0493 7208 HCW85BDA (8c65f6099835254d78294572af4e250a) C:\Windows\system32\drivers\HCW85BDA.sys
08:57:31.0539 7208 HCW85BDA - ok
08:57:31.0585 7208 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
08:57:31.0606 7208 HdAudAddService - ok
08:57:31.0623 7208 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
08:57:31.0624 7208 HDAudBus - ok
08:57:31.0646 7208 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
08:57:31.0656 7208 HidBatt - ok
08:57:31.0671 7208 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
08:57:31.0683 7208 HidBth - ok
08:57:31.0707 7208 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
08:57:31.0720 7208 HidIr - ok
08:57:31.0741 7208 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
08:57:31.0752 7208 HidUsb - ok
08:57:31.0777 7208 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
08:57:31.0789 7208 HpSAMD - ok
08:57:31.0816 7208 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
08:57:31.0899 7208 HTTP - ok
08:57:31.0960 7208 hwdatacard (4b5c07db91a0099272faae732e1152bd) C:\Windows\system32\DRIVERS\ewusbmdm.sys
08:57:31.0978 7208 hwdatacard - ok
08:57:32.0015 7208 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
08:57:32.0015 7208 hwpolicy - ok
08:57:32.0033 7208 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
08:57:32.0053 7208 i8042prt - ok
08:57:32.0094 7208 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys
08:57:32.0097 7208 iaStor - ok
08:57:32.0122 7208 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
08:57:32.0152 7208 iaStorV - ok
08:57:32.0211 7208 IfsMount (4374219378fdcec86f68cc2a103fa783) C:\Windows\system32\DRIVERS\ifsmount.sys
08:57:32.0239 7208 IfsMount - ok
08:57:32.0263 7208 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
08:57:32.0277 7208 iirsp - ok
08:57:32.0350 7208 IntcAzAudAddService (2a7cf87be453241fe0baa1c8651e7aa4) C:\Windows\system32\drivers\RTKVHD64.sys
08:57:32.0433 7208 IntcAzAudAddService - ok
08:57:32.0463 7208 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
08:57:32.0480 7208 intelide - ok
08:57:32.0510 7208 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
08:57:32.0511 7208 intelppm - ok
08:57:32.0545 7208 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:57:32.0567 7208 IpFilterDriver - ok
08:57:32.0589 7208 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
08:57:32.0603 7208 IPMIDRV - ok
08:57:32.0622 7208 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
08:57:32.0639 7208 IPNAT - ok
08:57:32.0657 7208 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
08:57:32.0668 7208 IRENUM - ok
08:57:32.0683 7208 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
08:57:32.0695 7208 isapnp - ok
08:57:32.0715 7208 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
08:57:32.0732 7208 iScsiPrt - ok
08:57:32.0750 7208 JRAID (71235f7baa7e5e79d38157df7a0f806a) C:\Windows\system32\DRIVERS\jraid.sys
08:57:32.0752 7208 JRAID - ok
08:57:32.0768 7208 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
08:57:32.0781 7208 kbdclass - ok
08:57:32.0792 7208 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
08:57:32.0802 7208 kbdhid - ok
08:57:32.0837 7208 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
08:57:32.0838 7208 KSecDD - ok
08:57:32.0877 7208 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
08:57:32.0880 7208 KSecPkg - ok
08:57:32.0897 7208 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
08:57:32.0913 7208 ksthunk - ok
08:57:32.0960 7208 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
08:57:32.0978 7208 lltdio - ok
08:57:33.0135 7208 LMIInfo (0317335b15ff3bda8e10197e3434cfc0) C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys
08:57:33.0154 7208 LMIInfo - ok
08:57:33.0216 7208 lmimirr (413ecdcfad9a82804d3674c8d7eec24e) C:\Windows\system32\DRIVERS\lmimirr.sys
08:57:33.0234 7208 lmimirr - ok
08:57:33.0242 7208 LMIRfsClientNP - ok
08:57:33.0266 7208 LMIRfsDriver (c57d3faa50e6f395759ffb7c709bd944) C:\Windows\system32\drivers\LMIRfsDriver.sys
08:57:33.0267 7208 LMIRfsDriver - ok
08:57:33.0291 7208 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
08:57:33.0305 7208 LSI_FC - ok
08:57:33.0325 7208 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
08:57:33.0338 7208 LSI_SAS - ok
08:57:33.0376 7208 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
08:57:33.0400 7208 LSI_SAS2 - ok
08:57:33.0420 7208 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
08:57:33.0433 7208 LSI_SCSI - ok
08:57:33.0448 7208 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
08:57:33.0449 7208 luafv - ok
08:57:33.0501 7208 lvpepf64 (4cb64d7458abd8396bcd389a69c8fc80) C:\Windows\system32\DRIVERS\lv302a64.sys
08:57:33.0518 7208 lvpepf64 - ok
08:57:33.0567 7208 LVPr2M64 (ded333dbdbbcc3555a6e6244522e2f1a) C:\Windows\system32\DRIVERS\LVPr2M64.sys
08:57:33.0588 7208 LVPr2M64 - ok
08:57:33.0627 7208 LVRS64 (ef2be2f45d4f06410a3bd2a3467325b0) C:\Windows\system32\DRIVERS\lvrs64.sys
08:57:33.0658 7208 LVRS64 - ok
08:57:33.0678 7208 LVUSBS64 (0034f69d0007d3f77f6b96fa51228e85) C:\Windows\system32\drivers\LVUSBS64.sys
08:57:33.0691 7208 LVUSBS64 - ok
08:57:33.0817 7208 LVUVC64 (ac22f92c6078640fe8a70d662a2f3ad5) C:\Windows\system32\DRIVERS\lvuvc64.sys
08:57:33.0964 7208 LVUVC64 - ok
08:57:34.0034 7208 MBAMProtector (23a854450dab5c9b7a42ab9be6f2e4bd) C:\Windows\system32\drivers\mbam.sys
08:57:34.0034 7208 MBAMProtector - ok
08:57:34.0076 7208 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
08:57:34.0096 7208 megasas - ok
08:57:34.0117 7208 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
08:57:34.0131 7208 MegaSR - ok
08:57:34.0165 7208 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
08:57:34.0178 7208 Modem - ok
08:57:34.0228 7208 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
08:57:34.0229 7208 monitor - ok
08:57:34.0252 7208 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
08:57:34.0275 7208 mouclass - ok
08:57:34.0302 7208 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
08:57:34.0315 7208 mouhid - ok
08:57:34.0334 7208 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
08:57:34.0335 7208 mountmgr - ok
08:57:34.0355 7208 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
08:57:34.0365 7208 mpio - ok
08:57:34.0380 7208 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
08:57:34.0393 7208 mpsdrv - ok
08:57:34.0431 7208 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
08:57:34.0457 7208 MRxDAV - ok
08:57:34.0511 7208 mrxsmb (b7f3d2c40bdf8ffb73ebfb19c77734e2) C:\Windows\system32\DRIVERS\mrxsmb.sys
08:57:34.0513 7208 mrxsmb - ok
08:57:34.0528 7208 mrxsmb10 (86c6f88b5168ce21cf8d69d0b3ff5d19) C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:57:34.0531 7208 mrxsmb10 - ok
08:57:34.0548 7208 mrxsmb20 (b081069251c8e9f42cb8769d07148f9c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:57:34.0552 7208 mrxsmb20 - ok
08:57:34.0604 7208 msahci (bccf16d5fb1109162380e3e28dc9e4e5) C:\Windows\system32\DRIVERS\msahci.sys
08:57:34.0621 7208 msahci - ok
08:57:34.0642 7208 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
08:57:34.0660 7208 msdsm - ok
08:57:34.0672 7208 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
08:57:34.0672 7208 Msfs - ok
08:57:34.0689 7208 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
08:57:34.0699 7208 mshidkmdf - ok
08:57:34.0710 7208 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
08:57:34.0710 7208 msisadrv - ok
08:57:34.0737 7208 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
08:57:34.0747 7208 MSKSSRV - ok
08:57:34.0759 7208 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
08:57:34.0768 7208 MSPCLOCK - ok
08:57:34.0785 7208 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
08:57:34.0795 7208 MSPQM - ok
08:57:34.0817 7208 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
08:57:34.0820 7208 MsRPC - ok
08:57:34.0840 7208 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
08:57:34.0840 7208 mssmbios - ok
08:57:34.0852 7208 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
08:57:34.0862 7208 MSTEE - ok
08:57:34.0876 7208 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
08:57:34.0887 7208 MTConfig - ok
08:57:34.0904 7208 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
08:57:34.0905 7208 Mup - ok
08:57:34.0929 7208 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
08:57:34.0947 7208 NativeWifiP - ok
08:57:35.0063 7208 NAVENG (2dbe90210de76be6e1653bb20ec70ec2) C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20111201.018\ENG64.SYS
08:57:35.0064 7208 NAVENG - ok
08:57:35.0127 7208 NAVEX15 (346da70e203b8e2c850277713de8f71b) C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20111201.018\EX64.SYS
08:57:35.0141 7208 NAVEX15 - ok
08:57:35.0180 7208 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
08:57:35.0191 7208 NDIS - ok
08:57:35.0211 7208 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
08:57:35.0221 7208 NdisCap - ok
08:57:35.0253 7208 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
08:57:35.0263 7208 NdisTapi - ok
08:57:35.0280 7208 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
08:57:35.0295 7208 Ndisuio - ok
08:57:35.0309 7208 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
08:57:35.0322 7208 NdisWan - ok
08:57:35.0341 7208 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
08:57:35.0356 7208 NDProxy - ok
08:57:35.0378 7208 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
08:57:35.0379 7208 NetBIOS - ok
08:57:35.0398 7208 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
08:57:35.0418 7208 NetBT - ok
08:57:35.0449 7208 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
08:57:35.0463 7208 nfrd960 - ok
08:57:35.0511 7208 NPF (97c691eda269792d897c69f6ff7989cc) C:\Windows\system32\drivers\npf.sys
08:57:35.0530 7208 NPF - ok
08:57:35.0550 7208 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
08:57:35.0550 7208 Npfs - ok
08:57:35.0570 7208 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
08:57:35.0583 7208 nsiproxy - ok
08:57:35.0622 7208 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
08:57:35.0651 7208 Ntfs - ok
08:57:35.0672 7208 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
08:57:35.0688 7208 Null - ok
08:57:35.0716 7208 NVHDA (cb599955ce2ce9694721562f9481cd84) C:\Windows\system32\drivers\nvhda64v.sys
08:57:35.0735 7208 NVHDA - ok
08:57:35.0984 7208 nvlddmkm (e55cab397f77d5208db18a78b1b7c0d5) C:\Windows\system32\DRIVERS\nvlddmkm.sys
08:57:36.0268 7208 nvlddmkm - ok
08:57:36.0296 7208 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
08:57:36.0311 7208 nvraid - ok
08:57:36.0335 7208 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
08:57:36.0349 7208 nvstor - ok
08:57:36.0378 7208 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
08:57:36.0410 7208 nv_agp - ok
08:57:36.0442 7208 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
08:57:36.0453 7208 ohci1394 - ok
08:57:36.0505 7208 Packet (99e6aa0ae2d05389ba7f7dff6866b569) C:\Windows\system32\DRIVERS\packet.sys
08:57:36.0519 7208 Packet - ok
08:57:36.0540 7208 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
08:57:36.0556 7208 Parport - ok
08:57:36.0576 7208 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
08:57:36.0577 7208 partmgr - ok
08:57:36.0670 7208 PCDSRVC{1E208CE0-FB7451FF-06020101}_0 (7317a0b550f7ac0223b7070897670476) c:\program files\dell support center\pcdsrvc_x64.pkms
08:57:36.0733 7208 PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - ok
08:57:36.0759 7208 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
08:57:36.0762 7208 pci - ok
08:57:36.0788 7208 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
08:57:36.0803 7208 pciide - ok
08:57:36.0826 7208 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
08:57:36.0851 7208 pcmcia - ok
08:57:36.0870 7208 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
08:57:36.0871 7208 pcw - ok
08:57:36.0895 7208 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
08:57:36.0919 7208 PEAUTH - ok
08:57:37.0005 7208 PID_PEPI (37ea62238e17ae88e4713d9246ca1c1c) C:\Windows\system32\DRIVERS\LV302V64.SYS
08:57:37.0055 7208 PID_PEPI - ok
08:57:37.0099 7208 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
08:57:37.0113 7208 PptpMiniport - ok
08:57:37.0140 7208 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
08:57:37.0154 7208 Processor - ok
08:57:37.0179 7208 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
08:57:37.0189 7208 Psched - ok
08:57:37.0232 7208 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys
08:57:37.0233 7208 PxHlpa64 - ok
08:57:37.0269 7208 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
08:57:37.0328 7208 ql2300 - ok
08:57:37.0345 7208 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
08:57:37.0358 7208 ql40xx - ok
08:57:37.0377 7208 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
08:57:37.0389 7208 QWAVEdrv - ok
08:57:37.0406 7208 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
08:57:37.0417 7208 RasAcd - ok
08:57:37.0458 7208 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
08:57:37.0475 7208 RasAgileVpn - ok
08:57:37.0514 7208 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
08:57:37.0532 7208 Rasl2tp - ok
08:57:37.0548 7208 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
08:57:37.0566 7208 RasPppoe - ok
08:57:37.0586 7208 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
08:57:37.0597 7208 RasSstp - ok
08:57:37.0617 7208 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
08:57:37.0619 7208 rdbss - ok
08:57:37.0633 7208 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
08:57:37.0645 7208 rdpbus - ok
08:57:37.0662 7208 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
08:57:37.0673 7208 RDPCDD - ok
08:57:37.0693 7208 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
08:57:37.0704 7208 RDPENCDD - ok
08:57:37.0719 7208 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
08:57:37.0730 7208 RDPREFMP - ok
08:57:37.0744 7208 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
08:57:37.0759 7208 RDPWD - ok
08:57:37.0781 7208 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
08:57:37.0783 7208 rdyboost - ok
08:57:37.0908 7208 RimUsb (7b04c9843921ab1f695fb395422c5360) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
08:57:37.0927 7208 RimUsb - ok
08:57:38.0004 7208 RivaTuner64 (a10b40cf9eb57d24e44717a2d38a00f4) C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys
08:57:38.0032 7208 RivaTuner64 - ok
08:57:38.0067 7208 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
08:57:38.0079 7208 rspndr - ok
08:57:38.0117 7208 RSUSBSTOR (2db8116d52b19216812c4e6d5d837810) C:\Windows\system32\Drivers\RtsUStor.sys
08:57:38.0119 7208 RSUSBSTOR - ok
08:57:38.0155 7208 RTL8167 (b49dc435ae3695bac5623dd94b05732d) C:\Windows\system32\DRIVERS\Rt64win7.sys
08:57:38.0182 7208 RTL8167 - ok
08:57:38.0189 7208 RxFilter - ok
08:57:38.0217 7208 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
08:57:38.0236 7208 sbp2port - ok
08:57:38.0292 7208 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
08:57:38.0306 7208 scfilter - ok
08:57:38.0329 7208 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
08:57:38.0340 7208 secdrv - ok
08:57:38.0375 7208 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
08:57:38.0387 7208 Serenum - ok
08:57:38.0413 7208 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
08:57:38.0438 7208 Serial - ok
08:57:38.0472 7208 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
08:57:38.0482 7208 sermouse - ok
08:57:38.0523 7208 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
08:57:38.0536 7208 sffdisk - ok
08:57:38.0549 7208 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
08:57:38.0561 7208 sffp_mmc - ok
08:57:38.0577 7208 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
08:57:38.0588 7208 sffp_sd - ok
08:57:38.0606 7208 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
08:57:38.0617 7208 sfloppy - ok
08:57:38.0648 7208 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
08:57:38.0661 7208 SiSRaid2 - ok
08:57:38.0672 7208 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
08:57:38.0688 7208 SiSRaid4 - ok
08:57:38.0721 7208 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
08:57:38.0739 7208 Smb - ok
08:57:38.0764 7208 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
08:57:38.0765 7208 spldr - ok
08:57:38.0835 7208 sptd (602884696850c86434530790b110e8eb) C:\Windows\System32\Drivers\sptd.sys
08:57:38.0879 7208 sptd - ok
08:57:38.0903 7208 SRTSP (620df2e4eca4d3b18486a0976b731411) C:\Windows\system32\Drivers\SRTSP64.SYS
08:57:38.0906 7208 SRTSP - ok
08:57:38.0924 7208 SRTSPL (15ae63bfb22579a06d9dfdce3a094aa1) C:\Windows\system32\Drivers\SRTSPL64.SYS
08:57:38.0951 7208 SRTSPL - ok
08:57:38.0968 7208 SRTSPX (9560cf1b6b002b3277b427491f9e6819) C:\Windows\system32\Drivers\SRTSPX64.SYS
08:57:38.0981 7208 SRTSPX - ok
08:57:39.0060 7208 srv (148d50904d2a0df29a19778715eb35bb) C:\Windows\system32\DRIVERS\srv.sys
08:57:39.0066 7208 srv - ok
08:57:39.0115 7208 srv2 (ce2189fe31d36678ac9eb7ddee08ec96) C:\Windows\system32\DRIVERS\srv2.sys
08:57:39.0120 7208 srv2 - ok
08:57:39.0140 7208 srvnet (cb69edeb069a49577592835659cd0e46) C:\Windows\system32\DRIVERS\srvnet.sys
08:57:39.0143 7208 srvnet - ok
08:57:39.0211 7208 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
08:57:39.0230 7208 stexstor - ok
08:57:39.0250 7208 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
08:57:39.0263 7208 swenum - ok
08:57:39.0300 7208 SymEvent (70c8d165063eb76f1a373b74456d2aab) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
08:57:39.0310 7208 SymEvent - ok
08:57:39.0373 7208 tap0901 (bcd6a90d6fd757ce9c29ddc850f7f231) C:\Windows\system32\DRIVERS\tap0901.sys
08:57:39.0392 7208 tap0901 - ok
08:57:39.0473 7208 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
08:57:39.0549 7208 Tcpip - ok
08:57:39.0614 7208 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
08:57:39.0623 7208 TCPIP6 - ok
08:57:39.0654 7208 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
08:57:39.0665 7208 tcpipreg - ok
08:57:39.0684 7208 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
08:57:39.0695 7208 TDPIPE - ok
08:57:39.0713 7208 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
08:57:39.0724 7208 TDTCP - ok
08:57:39.0741 7208 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
08:57:39.0754 7208 tdx - ok
08:57:39.0772 7208 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
08:57:39.0779 7208 TermDD - ok
08:57:39.0806 7208 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
08:57:39.0819 7208 tssecsrv - ok
08:57:39.0851 7208 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
08:57:39.0865 7208 tunnel - ok
08:57:39.0891 7208 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
08:57:39.0908 7208 uagp35 - ok
08:57:39.0935 7208 udfs (31ba4a33afab6a69ea092b18017f737f) C:\Windows\system32\DRIVERS\udfs.sys
08:57:39.0937 7208 udfs - ok
08:57:39.0966 7208 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
08:57:39.0982 7208 uliagpkx - ok
08:57:40.0012 7208 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
08:57:40.0029 7208 umbus - ok
08:57:40.0067 7208 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
08:57:40.0084 7208 UmPass - ok
08:57:40.0157 7208 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
08:57:40.0178 7208 USBAAPL64 - ok
08:57:40.0220 7208 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys
08:57:40.0242 7208 usbaudio - ok
08:57:40.0262 7208 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
08:57:40.0280 7208 usbccgp - ok
08:57:40.0310 7208 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
08:57:40.0327 7208 usbcir - ok
08:57:40.0351 7208 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
08:57:40.0363 7208 usbehci - ok
08:57:40.0394 7208 usbhub (7cc1c95896d60e868aa6dd2dd2f97ead) C:\Windows\system32\DRIVERS\usbhub.sys
08:57:40.0414 7208 usbhub - ok
08:57:40.0437 7208 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
08:57:40.0454 7208 usbohci - ok
08:57:40.0473 7208 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
08:57:40.0486 7208 usbprint - ok
08:57:40.0531 7208 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
08:57:40.0552 7208 usbscan - ok
08:57:40.0581 7208 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
08:57:40.0595 7208 USBSTOR - ok
08:57:40.0611 7208 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
08:57:40.0624 7208 usbuhci - ok
08:57:40.0694 7208 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys
08:57:40.0735 7208 usbvideo - ok
08:57:40.0801 7208 VClone (84bb306b7863883018d7f3eb0c453bd5) C:\Windows\system32\DRIVERS\VClone.sys
08:57:40.0813 7208 VClone - ok
08:57:40.0853 7208 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
08:57:40.0854 7208 vdrvroot - ok
08:57:40.0882 7208 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
08:57:40.0895 7208 vga - ok
08:57:40.0907 7208 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
08:57:40.0920 7208 VgaSave - ok
08:57:40.0936 7208 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
08:57:40.0949 7208 vhdmp - ok
08:57:40.0964 7208 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
08:57:40.0975 7208 viaide - ok
08:57:41.0008 7208 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
08:57:41.0010 7208 volmgr - ok
08:57:41.0031 7208 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
08:57:41.0034 7208 volmgrx - ok
08:57:41.0083 7208 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
08:57:41.0086 7208 volsnap - ok
08:57:41.0103 7208 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
08:57:41.0127 7208 vsmraid - ok
08:57:41.0158 7208 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
08:57:41.0171 7208 vwifibus - ok
08:57:41.0201 7208 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
08:57:41.0214 7208 WacomPen - ok
08:57:41.0250 7208 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
08:57:41.0270 7208 WANARP - ok
08:57:41.0273 7208 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
08:57:41.0274 7208 Wanarpv6 - ok
08:57:41.0301 7208 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
08:57:41.0311 7208 Wd - ok
08:57:41.0341 7208 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
08:57:41.0347 7208 Wdf01000 - ok
08:57:41.0378 7208 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
08:57:41.0389 7208 WfpLwf - ok
08:57:41.0426 7208 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys
08:57:41.0440 7208 WimFltr - ok
08:57:41.0456 7208 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
08:57:41.0469 7208 WIMMount - ok
08:57:41.0542 7208 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
08:57:41.0561 7208 WinUsb - ok
08:57:41.0591 7208 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
08:57:41.0591 7208 WmiAcpi - ok
08:57:41.0615 7208 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
08:57:41.0628 7208 ws2ifsl - ok
08:57:41.0659 7208 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
08:57:41.0671 7208 WudfPf - ok
08:57:41.0699 7208 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
08:57:41.0715 7208 WUDFRd - ok
08:57:41.0768 7208 ZTEusbmdm6k (0835c10fdb25daf7bcaaf138423826f3) C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
08:57:41.0786 7208 ZTEusbmdm6k - ok
08:57:41.0850 7208 ZTEusbnmea (0835c10fdb25daf7bcaaf138423826f3) C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
08:57:41.0868 7208 ZTEusbnmea - ok
08:57:41.0899 7208 ZTEusbser6k (0835c10fdb25daf7bcaaf138423826f3) C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
08:57:41.0917 7208 ZTEusbser6k - ok
08:57:42.0032 7208 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} (177590b0d2f8be513626bb8c8d6e6a08) C:\Program Files (x86)\CyberLink\PlayMovie\000.fcl
08:57:42.0053 7208 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} - ok
08:57:42.0060 7208 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk0\DR0
08:57:42.0065 7208 \Device\Harddisk0\DR0 - ok
08:57:42.0068 7208 MBR (0x1B8) (e1c682b9e829932d54e657fe42fb9630) \Device\Harddisk1\DR1
08:57:42.0072 7208 \Device\Harddisk1\DR1 - ok
08:57:42.0097 7208 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk2\DR2
08:57:42.0103 7208 \Device\Harddisk2\DR2 - ok
08:57:42.0105 7208 MBR (0x1B8) (e1c682b9e829932d54e657fe42fb9630) \Device\Harddisk3\DR3
08:57:42.0108 7208 \Device\Harddisk3\DR3 - ok
08:57:42.0111 7208 Boot (0x1200) (909e82ac98a6983381b883523e54e304) \Device\Harddisk0\DR0\Partition0
08:57:42.0112 7208 \Device\Harddisk0\DR0\Partition0 - ok
08:57:42.0147 7208 Boot (0x1200) (c048e95fe1017b80caaded16e2b0f7e0) \Device\Harddisk1\DR1\Partition0
08:57:42.0148 7208 \Device\Harddisk1\DR1\Partition0 - ok
08:57:42.0151 7208 Boot (0x1200) (4256b7c147c07b1673cfea056a3232f2) \Device\Harddisk2\DR2\Partition0
08:57:42.0152 7208 \Device\Harddisk2\DR2\Partition0 - ok
08:57:42.0161 7208 Boot (0x1200) (c7b78d7ddf48138c072a9b1ff3dfd032) \Device\Harddisk2\DR2\Partition1
08:57:42.0163 7208 \Device\Harddisk2\DR2\Partition1 - ok
08:57:42.0165 7208 Boot (0x1200) (48b767f63f125e55458ac3b6ef9f605a) \Device\Harddisk3\DR3\Partition0
08:57:42.0167 7208 \Device\Harddisk3\DR3\Partition0 - ok
08:57:42.0167 7208 ============================================================
08:57:42.0168 7208 Scan finished
08:57:42.0168 7208 ============================================================
08:57:42.0176 8288 Detected object count: 0
08:57:42.0177 8288 Actual detected object count: 0


aswMBR - updated the virus def and this is the report:


aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-12-04 08:59:03
—————————–
08:59:03.859 OS Version: Windows x64 6.1.7600
08:59:03.859 Number of processors: 8 586 0x1A05
08:59:03.859 ComputerName: DELLXPS UserName: steve
08:59:07.953 Initialize success
09:01:29.837 AVAST engine defs: 11120302
09:01:37.702 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
09:01:37.705 Disk 0 Vendor: Hitachi_ ST6O Size: 953869MB BusType: 3
09:01:37.707 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-1
09:01:37.708 Disk 1 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3
09:01:37.710 Disk 2 (boot) \Device\Harddisk2\DR2 -> \Device\Ide\IAAStorageDevice-2
09:01:37.712 Disk 2 Vendor: ST375052 CC45 Size: 715404MB BusType: 3
09:01:37.715 Disk 3 \Device\Harddisk3\DR3 -> \Device\Ide\IAAStorageDevice-3
09:01:37.717 Disk 3 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3
09:01:37.745 Disk 2 MBR read successfully
09:01:37.748 Disk 2 MBR scan
09:01:37.753 Disk 2 Windows 7 default MBR code
09:01:37.756 Service scanning
09:01:39.178 Modules scanning
09:01:39.188 Disk 2 trace - called modules:
09:01:39.196 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
09:01:39.201 1 nt!IofCallDriver -> \Device\Harddisk2\DR2[0xfffffa8004c4e060]
09:01:39.204 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-2[0xfffffa8004b93050]
09:01:56.986 AVAST engine scan C:\Windows
09:02:00.311 AVAST engine scan C:\Windows\system32
09:04:19.699 AVAST engine scan C:\Windows\system32\drivers
09:04:34.802 AVAST engine scan C:\Users\steve
09:04:44.839 File: C:\Users\steve\AppData\Local\auditpol.dll **INFECTED** Win32:Downloader-LNE [Trj]
09:04:44.916 File: C:\Users\steve\AppData\Local\auditpol.exe **INFECTED** Win32:Downloader-LNE [Trj]
09:52:44.213 AVAST engine scan C:\ProgramData
10:04:25.651 Scan finished successfully
10:05:11.006 Disk 2 MBR has been saved successfully to "C:\Users\steve\Desktop\fix\MBR.dat"
10:05:11.013 The log file has been saved successfully to "C:\Users\steve\Desktop\fix\aswMBR2.txt"
Please download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi there, Sorry for the delay in replaying. Combofix did a great job. Please run Combofix one more time, and paste the results in your next reply.
All problems have gone and not had any further issues for 1-2 weeks so i'd say it's fixed. Thanks Blottedisk - massive thanks! Great job - very much appreciated… regards

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI