This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

webpage redirects

52 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello….I have tried about 10 different virus scan programs….none find anything wrong with my PC…..

I have had to remove IE because it would keep running in the background at startup….
Now Firefox redirects pages to get-answers-now….and a couple others, like carpetworld.com!!!

Sure as heck there has to be a solution??!!

Here is my hijack file…

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:47:55 PM, on 22/11/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files (x86)\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73A8D51E-578B-4E4E-8FF8-112E51DBFBE3} (ADPConn Class) - http://caf.oeconnection.ca/ActiveX/DMSISM.CAB
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

–
End of file - 8423 bytes
Hi 87gtNOS,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Download aswMBR.exe ( 1.8mb ) to your desktop.

Double click the aswMBR.exe to run it.

When prompted to download the latest aswMBR definitions, click NO.

[external image: Posted Image]
Click the "Scan" button to start scan.

[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply.

===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Please include the following in your next reply:
  • DDS log
  • aswMBR log
  • GMER log
Thank you. . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 19:48:08 on 2011-11-23 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.3764.1915 [GMT -5:00] . AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\LSI SoftModem\agr64svc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Acer\Registration\GregHSRW.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Acer\Acer Updater\UpdaterService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\PLFSetI.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\igfxext.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe C:\Program Files (x86)\Launch Manager\LManager.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\REGSVR32.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank mStart Page = about:blank BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k mRun: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe mRun: [Client Access Service] "C:\Program Files (x86)\IBM\Client Access\cwbsvstr.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll DPF: {73A8D51E-578B-4E4E-8FF8-112E51DBFBE3} - hxxp://caf.oeconnection.ca/ActiveX/DMSISM.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{079E895E-A34A-44CA-AB30-B5385D4D0B79} : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{271FAE41-A699-468D-8B03-90E11F141682} : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{271FAE41-A699-468D-8B03-90E11F141682}\072796F627 : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{271FAE41-A699-468D-8B03-90E11F141682}\166756E65756 : DhcpNameServer = [removed] [removed] TCP: Interfaces\{271FAE41-A699-468D-8B03-90E11F141682}\3414050534C49454E445 : DhcpNameServer = [removed] [removed] TCP: Interfaces\{271FAE41-A699-468D-8B03-90E11F141682}\87271383030333 : DhcpNameServer = [removed] [removed] Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO-X64: SkypeIEPluginBHO - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File mRun-x64: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k mRun-x64: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" mRun-x64: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe mRun-x64: [Client Access Service] "C:\Program Files (x86)\IBM\Client Access\cwbsvstr.exe" mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.youtube.com/watch?v=fsEbM77DD_U&NR=1|http://forums.corvetteforum.com/c5-tech/2916387-vengeance-racing-built-1999-427-c5-corvette-videos-dyno-graph-pics-inside.html|http://www.youtube.com/watch?v=EOd9Wd9l9LA|http://www.youtube.com/watch?v=WWHPyrp7BSM&feature=related|http://ls1tech.com/forums/generation-iii-internal-engine/1469330-heads-cam-problem.html|http://ls1tech.com/forums/generation-iii-internal-engine/1469308-finally-got-my-cam.html FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll FF - plugin: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Jonathon\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll FF - plugin: C:\Windows\system32\TVUAx\npTVUAx.dll FF - plugin: C:\Windows\system32\Wat\npWatWeb.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;C:\Windows\system32\DRIVERS\Lbd.sys –> C:\Windows\system32\DRIVERS\Lbd.sys [?] R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys –> C:\Windows\system32\drivers\aswSnx.sys [?] R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys –> C:\Windows\system32\drivers\aswSP.sys [?] R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys –> C:\Windows\system32\DRIVERS\MpFilter.sys [?] R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\system32\DRIVERS\mwlPSDFilter.sys –> C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [?] R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\system32\DRIVERS\mwlPSDNServ.sys –> C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [?] R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys –> C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [?] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys –> C:\Windows\system32\drivers\aswFsBlk.sys [?] R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys –> C:\Windows\system32\drivers\aswMonFlt.sys [?] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-16 44768] R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys –> C:\Windows\system32\DRIVERS\eamonm.sys [?] R2 epfwwfpr;epfwwfpr;C:\Windows\system32\DRIVERS\epfwwfpr.sys –> C:\Windows\system32\DRIVERS\epfwwfpr.sys [?] R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2009-12-14 844320] R2 Greg_Service;GRegService;C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-8-28 1150496] R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-9-24 62720] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-6-17 144640] R2 sp_rsdrv2;Spyware Terminator Driver Filter;C:\Windows\system32\DRIVERS\stflt.sys –> C:\Windows\system32\DRIVERS\stflt.sys [?] R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-11-4 2320920] R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-11-4 240160] R3 esgiguard;esgiguard;C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [2011-3-2 13088] R3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?] R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys –> C:\Windows\system32\DRIVERS\Impcd.sys [?] R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys –> C:\Windows\system32\DRIVERS\IntcDAud.sys [?] R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys –> C:\Windows\system32\DRIVERS\k57nd60a.sys [?] R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys –> C:\Windows\system32\DRIVERS\MpNWMon.sys [?] R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys –> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?] R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 AmUStor;AM USB Stroage Driver;C:\Windows\system32\drivers\AmUStor.SYS –> C:\Windows\system32\drivers\AmUStor.SYS [?] S3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-11-15 17152] S3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe [2009-9-11 305448] S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-6-17 50432] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-7-18 140672] S4 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-9-22 974944] S4 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-4-17 135664] S4 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-4-17 135664] S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-11-3 2152152] S4 SpyHunter 4 Service;SpyHunter 4 Service;C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2011-10-10 995232] S4 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2011-11-20 1148632] . =============== Created Last 30 ================ . 2011-11-24 00:34:45 69000 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BF609C46-A044-4F4E-9E18-F5878BD26917}\offreg.dll 2011-11-24 00:34:42 8570192 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BF609C46-A044-4F4E-9E18-F5878BD26917}\mpengine.dll 2011-11-24 00:27:14 ——– d—–w- C:\Users\Jonathon\AppData\Local\{6AA4297C-E9C6-427F-9B3B-F0C6F32C9055} 2011-11-24 00:27:00 ——– d—–w- C:\Users\Jonathon\AppData\Local\{393113E8-AECE-4319-90BF-AF3FC6459262} 2011-11-23 00:59:25 ——– d—–w- C:\Users\Jonathon\AppData\Local\{DD3E6170-5244-4968-AA33-B4C3EA46426C} 2011-11-23 00:59:15 ——– d—–w- C:\Users\Jonathon\AppData\Local\{72DAF5E3-E635-4381-94F2-3BDC28AA38F1} 2011-11-23 00:47:05 388096 —-a-r- C:\Users\Jonathon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-11-22 02:51:48 ——– d—–w- C:\Program Files\ESET 2011-11-22 02:04:14 ——– d—–w- C:\rei 2011-11-22 02:04:03 ——– d—–w- C:\Program Files\Reimage 2011-11-22 00:33:36 110080 —-a-r- C:\Users\Jonathon\AppData\Roaming\Microsoft\Installer\{89A07279-1DB3-485A-B1DF-584DF86774B9}\IconF7A21AF7.exe 2011-11-22 00:33:36 110080 —-a-r- C:\Users\Jonathon\AppData\Roaming\Microsoft\Installer\{89A07279-1DB3-485A-B1DF-584DF86774B9}\IconD7F16134.exe 2011-11-22 00:33:36 110080 —-a-r- C:\Users\Jonathon\AppData\Roaming\Microsoft\Installer\{89A07279-1DB3-485A-B1DF-584DF86774B9}\Icon1226A4C5.exe 2011-11-22 00:33:33 ——– d—–w- C:\sh4ldr 2011-11-22 00:33:33 ——– d—–w- C:\Program Files\Enigma Software Group 2011-11-22 00:31:49 ——– d—–w- C:\Windows\89A072791DB3485AB1DF584DF86774B9.TMP 2011-11-22 00:31:46 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard 2011-11-21 23:47:40 ——– d—–w- C:\Users\Jonathon\AppData\Local\{59104D40-4DDD-4E04-B96C-D8318CEC757F} 2011-11-21 23:47:02 ——– d—–w- C:\Users\Jonathon\AppData\Local\{4B05806E-3EA5-4EFE-B7B3-7227A9B872F3} 2011-11-21 01:13:18 ——– d—–w- C:\Users\Jonathon\AppData\Local\{C571EA19-CD91-4394-8FCB-292471306875} 2011-11-21 01:13:09 ——– d—–w- C:\Users\Jonathon\AppData\Local\{C48BDE04-8BE7-4AA2-A143-67494879B46A} 2011-11-21 01:12:47 ——– d—–w- C:\Users\Jonathon\AppData\Local\{544BD090-ABBE-4179-83A5-0F1BEDF291D3} 2011-11-21 01:12:37 ——– d—–w- C:\Users\Jonathon\AppData\Local\{192ADDE0-1229-42D2-9236-B2F696C7D2EB} 2011-11-20 19:20:53 ——– d—–w- C:\Users\Jonathon\AppData\Roaming\SUPERAntiSpyware.com 2011-11-20 19:20:29 ——– d—–w- C:\ProgramData\!SASCORE 2011-11-20 19:20:23 ——– d—–w- C:\ProgramData\SUPERAntiSpyware.com 2011-11-20 19:20:23 ——– d—–w- C:\Program Files\SUPERAntiSpyware 2011-11-20 13:12:12 ——– d—–w- C:\Users\Jonathon\AppData\Local\{98F656C6-F277-4DC0-B7B0-A1CD4F6C2675} 2011-11-20 13:12:03 ——– d—–w- C:\Users\Jonathon\AppData\Local\{3A4D92DA-1309-4A5D-AFC9-1B91112CAB62} 2011-11-20 13:11:53 ——– d—–w- C:\Users\Jonathon\AppData\Local\{B7A5EBE1-71A4-484E-8DCF-D22AC55AEE67} 2011-11-20 13:11:43 ——– d—–w- C:\Users\Jonathon\AppData\Local\{AC801BF8-1680-444A-9EEA-5A9D43DDF989} 2011-11-20 12:57:45 51496 —-a-w- C:\Windows\System32\drivers\stflt.sys 2011-11-20 12:57:44 ——– d—–w- C:\Users\Jonathon\AppData\Roaming\Spyware Terminator 2011-11-20 12:57:44 ——– d—–w- C:\ProgramData\Spyware Terminator 2011-11-20 12:56:04 ——– d—–w- C:\Program Files (x86)\Spyware Terminator 2011-11-20 01:11:14 ——– d—–w- C:\Users\Jonathon\AppData\Local\{93DADDCD-AAC2-4319-A4FE-64510192D718} 2011-11-20 01:11:05 ——– d—–w- C:\Users\Jonathon\AppData\Local\{5BD290F0-0FAD-4F64-973D-929A9639F61E} 2011-11-20 01:10:56 ——– d—–w- C:\Users\Jonathon\AppData\Local\{0B6981B5-28A5-4A11-9D6D-0A80F19D0942} 2011-11-20 01:10:43 ——– d—–w- C:\Users\Jonathon\AppData\Local\{939604F1-D0CE-491C-AAC9-F5C536D3D90D} 2011-11-19 13:10:18 ——– d—–w- C:\Users\Jonathon\AppData\Local\{D5E3AEEC-E141-4C47-B220-C020C94EB956} 2011-11-19 13:10:09 ——– d—–w- C:\Users\Jonathon\AppData\Local\{264A4101-A2FC-415E-B5CC-7F034D4C614A} 2011-11-19 13:09:45 ——– d—–w- C:\Users\Jonathon\AppData\Local\{4E60AE43-418A-419F-B0FC-B2AC9A88AF99} 2011-11-19 13:08:16 ——– d—–w- C:\Users\Jonathon\AppData\Local\{76A652E4-576E-4CD8-BC0E-A57A89F6E076} 2011-11-19 00:44:31 ——– d—–w- C:\Users\Jonathon\AppData\Local\{C876AECA-F88F-491B-846E-1B79215C120B} 2011-11-19 00:44:18 ——– d—–w- C:\Users\Jonathon\AppData\Local\{8EC51DE4-F0F5-44E0-B87B-0A2A55C1E064} 2011-11-19 00:44:04 ——– d—–w- C:\Users\Jonathon\AppData\Local\{74BF20F1-B07E-41A2-8D0E-A59F153B2627} 2011-11-19 00:43:02 ——– d—–w- C:\Users\Jonathon\AppData\Local\{45E6B28D-9F87-48E6-AD10-19B8B1830246} 2011-11-18 00:16:35 ——– d—–w- C:\Users\Jonathon\AppData\Local\{427B17F7-96C6-401F-B1E4-ABBA457BA26F} 2011-11-18 00:16:26 ——– d—–w- C:\Users\Jonathon\AppData\Local\{5C1222A0-47ED-4320-9368-AB8CBECCA924} 2011-11-18 00:16:06 ——– d—–w- C:\Users\Jonathon\AppData\Local\{E52430C3-F4CA-4A88-9AC9-7A5AB2F0E3C4} 2011-11-18 00:15:56 ——– d—–w- C:\Users\Jonathon\AppData\Local\{26DBE823-26FD-468A-BEA7-E75F7DC7D1C0} 2011-11-17 14:51:18 16432 —-a-w- C:\Windows\System32\lsdelete.exe 2011-11-17 04:26:42 ——– d—–w- C:\Users\Jonathon\AppData\Roaming\Malwarebytes 2011-11-17 04:26:30 ——– d—–w- C:\ProgramData\Malwarebytes 2011-11-17 04:26:23 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-11-17 01:09:02 ——– d—–w- C:\Users\Jonathon\AppData\Local\{43A61615-C088-4137-95C9-C9F1CCA6165A} 2011-11-17 01:08:49 ——– d—–w- C:\Users\Jonathon\AppData\Local\{E251BAF5-C81A-45F1-B994-73CAA968119E} 2011-11-17 00:33:23 65368 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2011-11-17 00:33:23 601944 —-a-w- C:\Windows\System32\drivers\aswSnx.sys 2011-11-17 00:32:53 41184 —-a-w- C:\Windows\avastSS.scr 2011-11-17 00:32:41 ——– d—–w- C:\ProgramData\AVAST Software 2011-11-17 00:32:41 ——– d—–w- C:\Program Files\AVAST Software 2011-11-16 00:51:38 ——– d—–w- C:\Users\Jonathon\AppData\Local\{DA48C1CE-217E-463B-ADD6-524B5BEB175A} 2011-11-16 00:51:28 ——– d—–w- C:\Users\Jonathon\AppData\Local\{9C3D902E-F837-4644-B51E-E9161B6E6B4E} 2011-11-16 00:29:45 55384 —-a-w- C:\Windows\System32\drivers\SBREDrv.sys 2011-11-16 00:29:17 ——– d—–w- C:\Users\Jonathon\AppData\Local\Sunbelt Software 2011-11-15 20:43:05 69376 —-a-w- C:\Windows\System32\drivers\Lbd.sys 2011-11-15 20:42:54 ——– d—–w- C:\Program Files (x86)\Lavasoft 2011-11-15 11:34:58 8570192 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-11-15 04:05:17 ——– d—–w- C:\$RECYCLE.BIN 2011-11-15 03:16:45 98816 —-a-w- C:\Windows\sed.exe 2011-11-15 03:16:45 518144 —-a-w- C:\Windows\SWREG.exe 2011-11-15 03:16:45 256000 —-a-w- C:\Windows\PEV.exe 2011-11-15 03:16:45 208896 —-a-w- C:\Windows\MBR.exe 2011-11-15 03:15:34 ——– d—–w- C:\ComboFix 2011-11-15 02:08:59 917840 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8F82535A-662F-44D8-860F-247F0671DC17}\gapaengine.dll 2011-11-15 02:08:03 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client 2011-11-15 01:19:29 ——– d—–w- C:\Users\Jonathon\AppData\Local\{CBEDCB74-6865-406A-AC82-A4EA990347DB} 2011-11-15 01:19:19 ——– d—–w- C:\Users\Jonathon\AppData\Local\{271D71BE-43CC-475D-8447-6B430C56001A} 2011-11-14 04:45:04 8570192 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4FB009CB-02A7-40F1-A27E-8725C9F75D44}\mpengine.dll 2011-11-14 04:44:48 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll 2011-11-14 04:44:48 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll 2011-11-14 04:44:46 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-11-14 04:44:45 3144704 —-a-w- C:\Windows\System32\win32k.sys 2011-11-13 20:13:51 ——– d—–w- C:\Users\Jonathon\AppData\Local\{4743913C-9D55-4A9D-97F6-E50A37143A28} 2011-11-13 20:13:41 ——– d—–w- C:\Users\Jonathon\AppData\Local\{3D2FE25C-6FDF-4BA5-98DD-5E5F9516DA2B} 2011-11-13 20:09:22 200976 —-a-w- C:\Windows\SysWow64\drivers\tmcomm.sys 2011-11-13 15:24:33 ——– d—–w- C:\Program Files (x86)\Trend Micro 2011-11-13 15:20:38 ——– d—–w- C:\Program Files\Microsoft Security Client 2011-11-13 06:38:57 ——– d—–w- C:\Users\Jonathon\AppData\Local\{A04CBDE0-FDBC-4DFF-BC7D-4C8903F9E1F1} 2011-11-13 06:38:44 ——– d—–w- C:\Users\Jonathon\AppData\Local\{2E43166C-37FC-4279-84B5-98A355ECCA23} 2011-11-13 04:14:10 ——– d—–we C:\Windows\system64 2011-11-12 21:52:46 ——– d—–w- C:\Users\Jonathon\AppData\Local\{553785EC-8732-4E77-8443-5B3870BE1285} 2011-11-12 21:52:37 ——– d—–w- C:\Users\Jonathon\AppData\Local\{E6F922C6-CE17-4C01-BF99-130FD9411720} 2011-11-12 21:52:26 ——– d—–w- C:\Users\Jonathon\AppData\Local\{220F0B2B-7BAC-47FC-9A58-280C0FDBB36A} 2011-11-12 00:16:33 ——– d—–w- C:\Users\Jonathon\AppData\Local\{CF5CF72B-2834-4F65-96C3-CE1CCFA1F40A} 2011-11-12 00:16:22 ——– d—–w- C:\Users\Jonathon\AppData\Local\{EE1C2132-212C-445A-ABC6-C86637477195} 2011-11-12 00:16:08 ——– d—–w- C:\Users\Jonathon\AppData\Local\{72479621-AB8F-4912-92A2-BCF28A392967} 2011-11-11 02:20:25 ——– d—–w- C:\Users\Jonathon\AppData\Local\{DC1DC940-3B42-4F28-BD7D-4F5F2D1C4D58} 2011-11-11 02:20:15 ——– d—–w- C:\Users\Jonathon\AppData\Local\{BE3E2140-0C50-47F6-9914-78C53735BC3B} 2011-11-11 02:20:00 ——– d—–w- C:\Users\Jonathon\AppData\Local\{E1DFE2F8-FDF2-4926-BF66-DFCA0C4EEB2A} 2011-11-10 03:36:25 ——– d—–w- C:\Users\Jonathon\AppData\Local\{DCE84556-2768-4907-B665-CE7711399C41} 2011-11-10 03:36:11 ——– d—–w- C:\Users\Jonathon\AppData\Local\{DADFF1BB-BF20-4DC3-9D2F-E268B7D2911F} 2011-11-09 03:01:32 ——– d—–w- C:\Users\Jonathon\AppData\Local\{930B9656-1152-439B-A529-784549A29527} 2011-11-09 03:01:22 ——– d—–w- C:\Users\Jonathon\AppData\Local\{1AD79A5D-B6A1-409B-8FA5-7E89A59FFED2} 2011-11-08 00:29:17 ——– d—–w- C:\Users\Jonathon\AppData\Local\{430DE90D-6321-480B-9BC9-B626C6C3C173} 2011-11-08 00:29:07 ——– d—–w- C:\Users\Jonathon\AppData\Local\{9972C1BB-7B0E-4333-9D11-6E1D65C3981A} 2011-11-07 02:33:20 ——– d—–w- C:\Users\Jonathon\AppData\Local\{57BD25F9-B4E7-45A5-8BB9-DA1533133D1E} 2011-11-07 02:33:10 ——– d—–w- C:\Users\Jonathon\AppData\Local\{4A33B707-5575-4A56-9F01-EF545BB32AF6} 2011-11-07 02:33:01 ——– d—–w- C:\Users\Jonathon\AppData\Local\{0D4CAD39-2BCD-41BC-9C2F-A3F7B3ACCCE8} 2011-11-06 14:32:40 ——– d—–w- C:\Users\Jonathon\AppData\Local\{AA5883A8-F72B-43A1-AF98-26DD9F0FDC3C} 2011-11-06 14:32:30 ——– d—–w- C:\Users\Jonathon\AppData\Local\{1D423E37-0ACE-430C-AD41-A72DDAA36B11} 2011-11-06 14:32:21 ——– d—–w- C:\Users\Jonathon\AppData\Local\{841578C6-C738-464E-8849-1916130A2A79} 2011-11-06 14:32:11 ——– d—–w- C:\Users\Jonathon\AppData\Local\{1B93BDE7-C294-450D-B2F6-F0D588B7F948} 2011-11-06 02:31:45 ——– d—–w- C:\Users\Jonathon\AppData\Local\{8248DC40-C05E-4589-99CA-EAB985EFF3F2} 2011-11-06 02:31:36 ——– d—–w- C:\Users\Jonathon\AppData\Local\{0FBBD112-EAF4-4742-8D33-B29521B7CEA3} 2011-11-06 02:31:26 ——– d—–w- C:\Users\Jonathon\AppData\Local\{859D8FA1-C098-4190-9537-FDFAA383972C} 2011-11-05 12:56:21 ——– d—–w- C:\Users\Jonathon\AppData\Local\{74C3BA76-B617-4167-A805-42CA3933844A} 2011-11-05 12:56:10 ——– d—–w- C:\Users\Jonathon\AppData\Local\{6E98FBA0-F729-44B2-8A5F-5F05FF5607A3} 2011-11-05 12:55:58 ——– d—–w- C:\Users\Jonathon\AppData\Local\{D76FCB28-5479-486E-A98C-8863933F0293} 2011-11-04 23:53:10 ——– d—–w- C:\Users\Jonathon\AppData\Local\{EA5E3D54-0589-4220-A7C2-8FD6BE6FC67B} 2011-11-04 23:53:01 ——– d—–w- C:\Users\Jonathon\AppData\Local\{4A628A31-91CB-4246-B8C7-6AEF6E1E76ED} 2011-11-04 23:52:50 ——– d—–w- C:\Users\Jonathon\AppData\Local\{396E8248-DE05-4FD9-BEFE-B714C70900A7} 2011-11-03 23:49:54 ——– d—–w- C:\Users\Jonathon\AppData\Local\{913B6D51-6CDA-44B2-9F51-821A7E52BFE0} 2011-11-03 23:49:44 ——– d—–w- C:\Users\Jonathon\AppData\Local\{70CE2689-DEBA-46AA-9FF7-A257B06769A6} 2011-11-03 23:49:35 ——– d—–w- C:\Users\Jonathon\AppData\Local\{9A6CD843-BE87-49AF-AE56-BD5607612BB3} 2011-11-03 00:59:19 ——– d—–w- C:\Users\Jonathon\AppData\Local\{3C794409-991C-4B72-97F3-01DA099BAFF4} 2011-11-03 00:59:09 ——– d—–w- C:\Users\Jonathon\AppData\Local\{65223751-37A3-4741-9B6A-BCD261C94B66} 2011-11-03 00:59:00 ——– d—–w- C:\Users\Jonathon\AppData\Local\{F6C9D7AD-540C-4A20-AA25-66C76081C9E8} 2011-11-03 00:58:47 ——– d—–w- C:\Users\Jonathon\AppData\Local\{7CA377D2-AF29-400E-9641-ED173A35D655} 2011-11-01 23:33:41 ——– d—–w- C:\Users\Jonathon\AppData\Local\{2251D5DE-58EF-436A-B335-95D840A6726A} 2011-11-01 23:33:31 ——– d—–w- C:\Users\Jonathon\AppData\Local\{F257E7F1-79B5-4B0A-B777-2C57CEAEC35C} 2011-11-01 23:33:21 ——– d—–w- C:\Users\Jonathon\AppData\Local\{FD8FF9CF-A7A8-4DFF-B45B-F8D9C98E7B97} 2011-11-01 23:33:11 ——– d—–w- C:\Users\Jonathon\AppData\Local\{4898FE18-7D24-4106-A756-1AF50E8E7048} 2011-10-31 23:25:56 ——– d—–w- C:\Users\Jonathon\AppData\Local\{20BAA1B1-0E01-49BB-998A-DD7B9555F27F} 2011-10-31 23:25:45 ——– d—–w- C:\Users\Jonathon\AppData\Local\{00992023-066D-4EF7-899C-B698DCCCB780} 2011-10-31 23:25:26 ——– d—–w- C:\Users\Jonathon\AppData\Local\{6FBB1D93-6DC1-47F8-AAFD-518A9AED6B78} 2011-10-31 00:49:57 ——– d—–w- C:\Users\Jonathon\AppData\Local\{9DE798BD-1AC4-4EE1-A75C-4E45F67A98E8} 2011-10-31 00:49:48 ——– d—–w- C:\Users\Jonathon\AppData\Local\{42FB7ED7-FC9F-4408-A4EE-67578ECD080D} 2011-10-31 00:49:38 ——– d—–w- C:\Users\Jonathon\AppData\Local\{5320BEF9-180C-4422-ADF0-64DECBBCEB8F} 2011-10-30 12:49:17 ——– d—–w- C:\Users\Jonathon\AppData\Local\{83480B49-70E5-4DC9-A4CB-59F5896875DD} 2011-10-30 12:49:07 ——– d—–w- C:\Users\Jonathon\AppData\Local\{A6C31C21-333B-4860-ADC1-5F5B57108604} 2011-10-30 12:48:58 ——– d—–w- C:\Users\Jonathon\AppData\Local\{866A3738-DA0B-454B-B875-B6EFDA3EB0D3} 2011-10-30 12:48:48 ——– d—–w- C:\Users\Jonathon\AppData\Local\{188914E9-3B80-4EFB-B55D-9ECAC68CBBF5} 2011-10-30 00:48:19 ——– d—–w- C:\Users\Jonathon\AppData\Local\{B590FA27-F45F-43B7-85B6-31D9D4F167BB} 2011-10-30 00:48:10 ——– d—–w- C:\Users\Jonathon\AppData\Local\{D77B0EBC-1732-4046-B5E1-78C2D8ED6F63} 2011-10-29 12:47:45 ——– d—–w- C:\Users\Jonathon\AppData\Local\{8428CA4A-A5B7-4DDA-A398-925874063E14} 2011-10-29 12:47:35 ——– d—–w- C:\Users\Jonathon\AppData\Local\{5365644F-9B35-4E34-9C20-A0BE9CB04C54} 2011-10-28 23:47:26 ——– d—–w- C:\Users\Jonathon\AppData\Local\{59477A08-BE31-4A3A-A0B6-45BBCCFABA61} 2011-10-28 23:47:16 ——– d—–w- C:\Users\Jonathon\AppData\Local\{7BE2E7FD-E1B9-49A7-80AE-DCF1BEDCAA99} 2011-10-27 23:15:19 ——– d—–w- C:\Users\Jonathon\AppData\Local\{CBDF218C-94D7-447A-8D95-9F22DD13B929} 2011-10-27 23:15:09 ——– d—–w- C:\Users\Jonathon\AppData\Local\{AC2463B6-3AB2-4E01-8852-17CCE4C35952} 2011-10-27 23:14:58 ——– d—–w- C:\Users\Jonathon\AppData\Local\{F5FDDFD6-245E-414C-BFF9-568D73C99D23} 2011-10-26 23:30:02 ——– d—–w- C:\Users\Jonathon\AppData\Local\{401813B7-E637-4517-B4E6-DB72B66CC5E2} 2011-10-26 23:29:51 ——– d—–w- C:\Users\Jonathon\AppData\Local\{B3724040-D8B9-4AF2-9C53-A3BA41C53995} 2011-10-26 23:29:41 ——– d—–w- C:\Users\Jonathon\AppData\Local\{3663F61A-5078-4327-847D-0A067D6E9991} 2011-10-26 23:29:30 ——– d—–w- C:\Users\Jonathon\AppData\Local\{4913299F-743E-4FA5-A13B-2212DB714297} 2011-10-25 23:38:49 ——– d—–w- C:\Users\Jonathon\AppData\Local\{C6392C3E-F668-4ACD-B930-6A7CDA21F024} 2011-10-25 23:38:40 ——– d—–w- C:\Users\Jonathon\AppData\Local\{2E4F20A6-FCC1-403B-85E6-665C1AF05722} 2011-10-25 23:38:30 ——– d—–w- C:\Users\Jonathon\AppData\Local\{EBBFF44C-EBD0-48CA-9187-A545A14ECB59} 2011-10-25 23:38:21 ——– d—–w- C:\Users\Jonathon\AppData\Local\{2DC16E38-F65A-4AA3-9964-DE6C0D693771} . ==================== Find3M ==================== . 2011-10-18 23:42:20 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-01 05:24:07 2309120 —-a-w- C:\Windows\System32\jscript9.dll 2011-09-01 05:17:57 1389056 —-a-w- C:\Windows\System32\wininet.dll 2011-09-01 05:12:04 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-09-01 02:35:59 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-09-01 02:28:15 1126912 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-09-01 02:22:54 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-09-01 01:08:50 167704 —-a-w- C:\Windows\System32\igfxtray.exe 2011-09-01 01:08:48 510232 —-a-w- C:\Windows\System32\igfxsrvc.exe 2011-09-01 01:08:44 416024 —-a-w- C:\Windows\System32\igfxpers.exe 2011-09-01 01:08:42 239896 —-a-w- C:\Windows\System32\igfxext.exe 2011-09-01 01:08:34 392472 —-a-w- C:\Windows\System32\hkcmd.exe 2011-09-01 01:08:24 4378392 —-a-w- C:\Windows\System32\GfxUI.exe 2011-09-01 01:08:22 179992 —-a-w- C:\Windows\System32\difx64.exe 2011-09-01 00:58:50 90112 —-a-w- C:\Windows\System32\igfxCoIn_v2509.dll 2011-09-01 00:53:22 12306848 —-a-w- C:\Windows\System32\drivers\igdkmd64.sys 2011-09-01 00:53:20 8312320 —-a-w- C:\Windows\System32\igdumd64.dll 2011-09-01 00:51:16 867020 —-a-w- C:\Windows\SysWow64\igkrng575.bin 2011-09-01 00:51:16 867020 —-a-w- C:\Windows\System32\igkrng575.bin 2011-09-01 00:51:16 128204 —-a-w- C:\Windows\SysWow64\igcompkrng575.bin 2011-09-01 00:51:16 128204 —-a-w- C:\Windows\System32\igcompkrng575.bin 2011-09-01 00:51:16 105608 —-a-w- C:\Windows\SysWow64\igfcg575m.bin 2011-09-01 00:51:16 105608 —-a-w- C:\Windows\System32\igfcg575m.bin 2011-09-01 00:47:42 6322688 —-a-w- C:\Windows\SysWow64\igdumd32.dll 2011-09-01 00:45:02 581120 —-a-w- C:\Windows\SysWow64\igdumdx32.dll 2011-09-01 00:42:42 14598656 —-a-w- C:\Windows\System32\igd10umd64.dll 2011-09-01 00:37:18 12340224 —-a-w- C:\Windows\SysWow64\igd10umd32.dll 2011-09-01 00:31:14 18641408 —-a-w- C:\Windows\System32\ig4icd64.dll 2011-09-01 00:26:20 13903872 —-a-w- C:\Windows\SysWow64\ig4icd32.dll 2011-09-01 00:21:50 375808 —-a-w- C:\Windows\System32\igfxpph.dll 2011-09-01 00:21:46 378368 —-a-w- C:\Windows\System32\igfxTMM.dll 2011-09-01 00:21:40 28672 —-a-w- C:\Windows\System32\igfxexps.dll 2011-09-01 00:21:26 62464 —-a-w- C:\Windows\System32\igfxsrvc.dll 2011-09-01 00:20:58 110080 —-a-w- C:\Windows\System32\hccutils.dll 2011-09-01 00:20:50 4096 —-a-w- C:\Windows\System32\IGFXDEVLib.dll 2011-09-01 00:20:50 146432 —-a-w- C:\Windows\System32\gfxSrvc.dll 2011-09-01 00:20:48 390144 —-a-w- C:\Windows\System32\igfxdev.dll 2011-09-01 00:20:14 285696 —-a-w- C:\Windows\System32\igfxrenu.lrc 2011-09-01 00:20:08 9014784 —-a-w- C:\Windows\System32\igfxress.dll 2011-09-01 00:20:08 142336 —-a-w- C:\Windows\System32\igfxdo.dll 2011-09-01 00:16:32 24576 —-a-w- C:\Windows\SysWow64\igfxexps32.dll 2011-09-01 00:15:46 294400 —-a-w- C:\Windows\SysWow64\igfxdv32.dll 2011-09-01 00:13:52 98304 —-a-w- C:\Windows\SysWow64\iglhcp32.dll 2011-09-01 00:13:52 98304 —-a-w- C:\Windows\System32\iglhcp64.dll 2011-09-01 00:13:52 94208 —-a-w- C:\Windows\System32\IccLibDll_x64.dll 2011-09-01 00:13:52 376832 —-a-w- C:\Windows\SysWow64\iglhsip32.dll 2011-09-01 00:13:52 376832 —-a-w- C:\Windows\System32\iglhsip64.dll 2011-09-01 00:13:52 162816 —-a-w- C:\Windows\SysWow64\igfxcmrt32.dll 2011-09-01 00:13:52 140288 —-a-w- C:\Windows\System32\igfxcmrt64.dll 2011-08-27 05:37:49 861696 —-a-w- C:\Windows\System32\oleaut32.dll 2011-08-27 05:37:48 331776 —-a-w- C:\Windows\System32\oleacc.dll 2011-08-27 04:26:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-27 04:26:27 233472 —-a-w- C:\Windows\SysWow64\oleacc.dll . ============= FINISH: 20:01:42.90 ===============

Attachments:

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-23 20:09:45 —————————– 20:09:45.336 OS Version: Windows x64 6.1.7601 Service Pack 1 20:09:45.336 Number of processors: 4 586 0x2502 20:09:45.336 ComputerName: JONATHON-ACER UserName: Jonathon 20:09:46.990 Initialize success 20:09:47.115 AVAST engine defs: 11112302 20:10:15.865 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 20:10:15.865 Disk 0 Vendor: Hitachi_ PB3O Size: 305245MB BusType: 3 20:10:15.881 Disk 0 MBR read successfully 20:10:15.881 Disk 0 MBR scan 20:10:15.881 Disk 0 Windows VISTA default MBR code 20:10:15.881 Service scanning 20:10:16.489 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32 20:10:17.145 Modules scanning 20:10:17.145 Disk 0 trace - called modules: 20:10:17.176 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa8004c0e334]<< 20:10:17.176 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004bfb060] 20:10:17.191 3 CLASSPNP.SYS[fffff88001b5a43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004975050] 20:10:17.191 \Driver\iaStor[0xfffffa8004916570] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0xfffffa8004c0e334 20:10:17.987 AVAST engine scan C:\Windows 20:10:21.528 AVAST engine scan C:\Windows\system32 20:11:35.098 AVAST engine scan C:\Windows\system32\drivers 20:11:44.396 AVAST engine scan C:\Users\Jonathon 20:22:52.482 AVAST engine scan C:\ProgramData 20:25:06.643 Scan finished successfully 20:26:55.796 Disk 0 MBR has been saved successfully to "C:\Users\Jonathon\Desktop\MBR.dat" 20:26:55.827 The log file has been saved successfully to "C:\Users\Jonathon\Desktop\aswMBR.txt"
Hi 87gtNOS,

Thanks for the logs. You have multiple antivirus softwares installed on your computer. You should not have more than one antivirus software running at any given time because this can lead to conflicts and sluggish performance. I would recommend you uninstall Lavasoft Ad-Watch Live! Anti-Virus, avast! Antivirus, and ESET NOD32 Antivirus 5.0 and just use Microsoft Security Essentials because it is a great antivirus/antispyware program that is light on resources.

NEXT:

Please download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 11-11-23.03 - Jonathon 23/11/2011 22:20:42.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.3764.2367 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2011-10-24 to 2011-11-24 ))))))))))))))))))))))))))))))) . . 2011-11-24 04:03 . 2011-11-24 04:03 69000 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BF609C46-A044-4F4E-9E18-F5878BD26917}\offreg.dll 2011-11-24 04:01 . 2011-11-24 04:01 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-11-24 00:34 . 2011-10-07 02:16 8570192 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BF609C46-A044-4F4E-9E18-F5878BD26917}\mpengine.dll 2011-11-23 00:47 . 2011-11-23 00:47 388096 —-a-r- c:\users\Jonathon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-11-22 02:51 . 2011-11-22 02:51 ——– d—–w- c:\program files\ESET 2011-11-22 02:04 . 2011-11-23 00:30 ——– d—–w- C:\rei 2011-11-22 02:04 . 2011-11-22 02:04 ——– d—–w- c:\program files\Reimage 2011-11-22 00:33 . 2011-11-24 03:02 ——– d—–w- C:\sh4ldr 2011-11-22 00:33 . 2011-11-22 00:33 ——– d—–w- c:\program files\Enigma Software Group 2011-11-22 00:31 . 2011-11-24 03:02 ——– d—–w- c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP 2011-11-22 00:31 . 2011-11-22 00:31 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2011-11-20 19:20 . 2011-11-20 19:20 ——– d—–w- c:\users\Jonathon\AppData\Roaming\SUPERAntiSpyware.com 2011-11-20 19:20 . 2011-11-20 19:20 ——– d—–w- c:\programdata\!SASCORE 2011-11-20 19:20 . 2011-11-20 19:31 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-11-20 19:20 . 2011-11-20 19:20 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-11-20 12:57 . 2011-11-20 12:57 51496 —-a-w- c:\windows\system32\drivers\stflt.sys 2011-11-20 12:57 . 2011-11-22 23:55 ——– d—–w- c:\programdata\Spyware Terminator 2011-11-20 12:57 . 2011-11-20 12:57 ——– d—–w- c:\users\Jonathon\AppData\Roaming\Spyware Terminator 2011-11-20 12:56 . 2011-11-20 12:58 ——– d—–w- c:\program files (x86)\Spyware Terminator 2011-11-17 04:26 . 2011-11-17 04:26 ——– d—–w- c:\users\Jonathon\AppData\Roaming\Malwarebytes 2011-11-17 04:26 . 2011-11-17 04:26 ——– d—–w- c:\programdata\Malwarebytes 2011-11-17 04:26 . 2011-11-17 04:26 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-11-17 00:33 . 2011-09-06 21:45 254400 —-a-w- c:\windows\system32\aswBoot.exe 2011-11-17 00:32 . 2011-11-24 02:55 ——– d—–w- c:\programdata\AVAST Software 2011-11-17 00:32 . 2011-11-17 00:32 ——– d—–w- c:\program files\AVAST Software 2011-11-16 00:29 . 2011-11-15 21:48 55384 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-11-16 00:29 . 2011-11-16 00:29 ——– d—–w- c:\users\Jonathon\AppData\Local\Sunbelt Software 2011-11-15 20:42 . 2011-11-24 02:56 ——– d—–w- c:\programdata\Lavasoft 2011-11-15 11:34 . 2011-10-07 02:16 8570192 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-11-15 02:08 . 2011-11-15 02:08 917840 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8F82535A-662F-44D8-860F-247F0671DC17}\gapaengine.dll 2011-11-15 02:08 . 2011-11-15 02:08 ——– d—–w- c:\program files (x86)\Microsoft Security Client 2011-11-14 04:45 . 2011-10-07 04:16 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4FB009CB-02A7-40F1-A27E-8725C9F75D44}\mpengine.dll 2011-11-14 04:44 . 2011-10-01 05:45 886784 —-a-w- c:\program files\Common Files\System\wab32.dll 2011-11-14 04:44 . 2011-10-01 04:37 708608 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll 2011-11-14 04:44 . 2011-09-29 16:29 1923952 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-14 04:44 . 2011-09-29 04:03 3144704 —-a-w- c:\windows\system32\win32k.sys 2011-11-13 23:25 . 2011-11-14 00:20 ——– d—–w- c:\windows\system32\Macromed 2011-11-13 20:09 . 2011-06-21 04:09 200976 —-a-w- c:\windows\SysWow64\drivers\tmcomm.sys 2011-11-13 15:40 . 2011-11-13 15:40 ——– d—–w- c:\programdata\Intel 2011-11-13 15:24 . 2011-11-13 15:24 ——– d—–w- c:\program files (x86)\Trend Micro 2011-11-13 15:20 . 2011-11-15 02:07 ——– d—–w- c:\program files\Microsoft Security Client 2011-11-13 04:14 . 2011-11-13 04:14 ——– d—–we c:\windows\system64 . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-18 23:42 . 2011-05-19 02:16 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-01 05:24 . 2011-10-12 05:08 2309120 —-a-w- c:\windows\system32\jscript9.dll 2011-09-01 05:17 . 2011-10-12 05:08 1389056 —-a-w- c:\windows\system32\wininet.dll 2011-09-01 05:12 . 2011-10-12 05:08 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-09-01 02:35 . 2011-10-12 05:08 1798144 —-a-w- c:\windows\SysWow64\jscript9.dll 2011-09-01 02:28 . 2011-10-12 05:08 1126912 —-a-w- c:\windows\SysWow64\wininet.dll 2011-09-01 02:22 . 2011-10-12 05:08 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-09-01 01:08 . 2011-09-01 01:08 167704 —-a-w- c:\windows\system32\igfxtray.exe 2011-09-01 01:08 . 2011-09-01 01:08 510232 —-a-w- c:\windows\system32\igfxsrvc.exe 2011-09-01 01:08 . 2011-09-01 01:08 416024 —-a-w- c:\windows\system32\igfxpers.exe 2011-09-01 01:08 . 2011-09-01 01:08 239896 —-a-w- c:\windows\system32\igfxext.exe 2011-09-01 01:08 . 2011-09-01 01:08 392472 —-a-w- c:\windows\system32\hkcmd.exe 2011-09-01 01:08 . 2011-09-01 01:08 4378392 —-a-w- c:\windows\system32\GfxUI.exe 2011-09-01 01:08 . 2011-09-01 01:08 179992 —-a-w- c:\windows\system32\difx64.exe 2011-09-01 00:58 . 2011-09-01 00:58 90112 —-a-w- c:\windows\system32\igfxCoIn_v2509.dll 2011-09-01 00:53 . 2011-09-01 00:53 12306848 —-a-w- c:\windows\system32\drivers\igdkmd64.sys 2011-09-01 00:53 . 2011-09-01 00:53 8312320 —-a-w- c:\windows\system32\igdumd64.dll 2011-09-01 00:51 . 2011-09-01 00:51 867020 —-a-w- c:\windows\system32\igkrng575.bin 2011-09-01 00:51 . 2011-09-01 00:51 128204 —-a-w- c:\windows\system32\igcompkrng575.bin 2011-09-01 00:51 . 2011-09-01 00:51 105608 —-a-w- c:\windows\system32\igfcg575m.bin 2011-09-01 00:47 . 2011-09-01 00:47 6322688 —-a-w- c:\windows\SysWow64\igdumd32.dll 2011-09-01 00:45 . 2011-09-01 00:45 581120 —-a-w- c:\windows\SysWow64\igdumdx32.dll 2011-09-01 00:42 . 2009-12-14 15:32 14598656 —-a-w- c:\windows\system32\igd10umd64.dll 2011-09-01 00:37 . 2011-09-01 00:37 12340224 —-a-w- c:\windows\SysWow64\igd10umd32.dll 2011-09-01 00:31 . 2011-09-01 00:31 18641408 —-a-w- c:\windows\system32\ig4icd64.dll 2011-09-01 00:26 . 2011-09-01 00:26 13903872 —-a-w- c:\windows\SysWow64\ig4icd32.dll 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrrom.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrsky.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrhrv.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286208 —-a-w- c:\windows\system32\igfxrtrk.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286208 —-a-w- c:\windows\system32\igfxrslv.lrc 2011-09-01 00:22 . 2011-09-01 00:22 287232 —-a-w- c:\windows\system32\igfxresn.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286208 —-a-w- c:\windows\system32\igfxrsve.lrc 2011-09-01 00:22 . 2011-09-01 00:22 285696 —-a-w- c:\windows\system32\igfxrtha.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrrus.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrptg.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrplk.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286208 —-a-w- c:\windows\system32\igfxrptb.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286208 —-a-w- c:\windows\system32\igfxrnor.lrc 2011-09-01 00:22 . 2011-09-01 00:22 283136 —-a-w- c:\windows\system32\igfxrkor.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrita.lrc 2011-09-01 00:22 . 2011-09-01 00:22 283648 —-a-w- c:\windows\system32\igfxrjpn.lrc 2011-09-01 00:22 . 2011-09-01 00:22 287232 —-a-w- c:\windows\system32\igfxrell.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrdeu.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286208 —-a-w- c:\windows\system32\igfxrhun.lrc 2011-09-01 00:22 . 2011-09-01 00:22 285184 —-a-w- c:\windows\system32\igfxrheb.lrc 2011-09-01 00:22 . 2011-09-01 00:22 287232 —-a-w- c:\windows\system32\igfxrfra.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrnld.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286208 —-a-w- c:\windows\system32\igfxrfin.lrc 2011-09-01 00:22 . 2011-09-01 00:22 286720 —-a-w- c:\windows\system32\igfxrcsy.lrc 2011-09-01 00:22 . 2011-09-01 00:22 285696 —-a-w- c:\windows\system32\igfxrdan.lrc 2011-09-01 00:22 . 2011-09-01 00:22 282624 —-a-w- c:\windows\system32\igfxrcht.lrc 2011-09-01 00:22 . 2011-09-01 00:22 285184 —-a-w- c:\windows\system32\igfxrara.lrc 2011-09-01 00:22 . 2011-09-01 00:22 282624 —-a-w- c:\windows\system32\igfxrchs.lrc 2011-09-01 00:22 . 2011-09-01 00:22 126976 —-a-w- c:\windows\system32\igfxcpl.cpl 2011-09-01 00:21 . 2011-09-01 00:21 375808 —-a-w- c:\windows\system32\igfxpph.dll 2011-09-01 00:21 . 2011-09-01 00:21 378368 —-a-w- c:\windows\system32\igfxTMM.dll 2011-09-01 00:21 . 2009-12-14 15:32 28672 —-a-w- c:\windows\system32\igfxexps.dll 2011-09-01 00:21 . 2009-12-14 15:32 62464 —-a-w- c:\windows\system32\igfxsrvc.dll 2011-09-01 00:20 . 2009-12-14 15:32 110080 —-a-w- c:\windows\system32\hccutils.dll 2011-09-01 00:20 . 2011-09-01 00:20 4096 —-a-w- c:\windows\system32\IGFXDEVLib.dll 2011-09-01 00:20 . 2011-09-01 00:20 146432 —-a-w- c:\windows\system32\gfxSrvc.dll 2011-09-01 00:20 . 2009-12-14 15:32 390144 —-a-w- c:\windows\system32\igfxdev.dll 2011-09-01 00:20 . 2011-09-01 00:20 285696 —-a-w- c:\windows\system32\igfxrenu.lrc 2011-09-01 00:20 . 2011-09-01 00:20 142336 —-a-w- c:\windows\system32\igfxdo.dll 2011-09-01 00:20 . 2009-12-14 15:32 9014784 —-a-w- c:\windows\system32\igfxress.dll 2011-09-01 00:16 . 2011-09-01 00:16 24576 —-a-w- c:\windows\SysWow64\igfxexps32.dll 2011-09-01 00:15 . 2011-09-01 00:15 294400 —-a-w- c:\windows\SysWow64\igfxdv32.dll 2011-09-01 00:13 . 2011-09-01 00:13 98304 —-a-w- c:\windows\SysWow64\iglhcp32.dll 2011-09-01 00:13 . 2011-09-01 00:13 98304 —-a-w- c:\windows\system32\iglhcp64.dll 2011-09-01 00:13 . 2011-09-01 00:13 94208 —-a-w- c:\windows\system32\IccLibDll_x64.dll 2011-09-01 00:13 . 2011-09-01 00:13 376832 —-a-w- c:\windows\SysWow64\iglhsip32.dll 2011-09-01 00:13 . 2011-09-01 00:13 376832 —-a-w- c:\windows\system32\iglhsip64.dll 2011-09-01 00:13 . 2011-09-01 00:13 162816 —-a-w- c:\windows\SysWow64\igfxcmrt32.dll 2011-09-01 00:13 . 2011-09-01 00:13 140288 —-a-w- c:\windows\system32\igfxcmrt64.dll 2011-08-27 05:37 . 2011-10-12 05:05 861696 —-a-w- c:\windows\system32\oleaut32.dll 2011-08-27 05:37 . 2011-10-12 05:05 331776 —-a-w- c:\windows\system32\oleacc.dll 2011-08-27 04:26 . 2011-10-12 05:05 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-08-27 04:26 . 2011-10-12 05:05 233472 —-a-w- c:\windows\SysWow64\oleacc.dll . . ((((((((((((((((((((((((((((( SnapShot@2011-11-15_04.05.49 ))))))))))))))))))))))))))))))))))))))))) . + 2011-06-11 06:58 . 2011-06-11 06:58 51024 c:\windows\SysWOW64\vcomp100.dll + 2011-06-11 06:58 . 2011-06-11 06:58 81744 c:\windows\SysWOW64\mfcm100u.dll + 2011-06-11 06:58 . 2011-06-11 06:58 81744 c:\windows\SysWOW64\mfcm100.dll + 2011-06-11 06:58 . 2011-06-11 06:58 60752 c:\windows\SysWOW64\mfc100rus.dll + 2011-06-11 06:58 . 2011-06-11 06:58 43344 c:\windows\SysWOW64\mfc100kor.dll + 2011-06-11 06:58 . 2011-06-11 06:58 43856 c:\windows\SysWOW64\mfc100jpn.dll + 2011-06-11 06:58 . 2011-06-11 06:58 62288 c:\windows\SysWOW64\mfc100ita.dll + 2011-06-11 06:58 . 2011-06-11 06:58 64336 c:\windows\SysWOW64\mfc100fra.dll + 2011-06-11 06:58 . 2011-06-11 06:58 63824 c:\windows\SysWOW64\mfc100esn.dll + 2011-06-11 06:58 . 2011-06-11 06:58 55120 c:\windows\SysWOW64\mfc100enu.dll + 2011-06-11 06:58 . 2011-06-11 06:58 64336 c:\windows\SysWOW64\mfc100deu.dll + 2011-06-11 06:58 . 2011-06-11 06:58 36176 c:\windows\SysWOW64\mfc100cht.dll + 2011-06-11 06:58 . 2011-06-11 06:58 36176 c:\windows\SysWOW64\mfc100chs.dll - 2010-05-18 00:41 . 2011-06-19 23:03 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2010-05-18 00:41 . 2011-11-22 23:54 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2009-07-14 04:54 . 2011-11-24 00:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-08-21 22:06 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2011-11-24 00:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-08-21 22:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-11-24 00:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2011-08-21 22:06 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-11-05 00:35 . 2011-11-24 03:05 62970 c:\windows\system64\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-11-24 03:05 40484 c:\windows\system64\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-04-17 19:53 . 2011-11-24 03:05 17040 c:\windows\system64\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4272350839-2314675571-2890082633-1001_UserData.bin + 2011-09-01 00:13 . 2011-09-01 00:13 98304 c:\windows\system64\iglhcp64.dll + 2009-12-14 15:32 . 2011-09-01 00:21 62464 c:\windows\system64\igfxsrvc.dll + 2009-12-14 15:32 . 2011-09-01 00:21 28672 c:\windows\system64\igfxexps.dll + 2011-09-01 00:58 . 2011-09-01 00:58 90112 c:\windows\system64\igfxCoIn_v2509.dll + 2011-09-01 00:13 . 2011-09-01 00:13 94208 c:\windows\system64\IccLibDll_x64.dll + 2009-07-14 05:30 . 2011-11-24 02:57 86016 c:\windows\system64\DriverStore\infpub.dat - 2009-07-14 05:30 . 2011-07-25 03:37 86016 c:\windows\system64\DriverStore\infpub.dat + 2011-09-01 00:58 . 2011-09-01 00:58 90112 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igxpco64.dll + 2011-09-01 00:13 . 2011-09-01 00:13 98304 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\iglhcp64.dll + 2011-09-01 00:13 . 2011-09-01 00:13 98304 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\iglhcp32.dll + 2011-09-01 00:21 . 2011-09-01 00:21 62464 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxsrvc.dll + 2011-09-01 00:16 . 2011-09-01 00:16 24576 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxexps32.dll + 2011-09-01 00:21 . 2011-09-01 00:21 28672 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxexps.dll + 2011-09-01 00:51 . 2011-09-01 00:51 75776 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdde64.dll + 2011-09-01 00:46 . 2011-09-01 00:46 56832 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdde32.dll + 2011-09-01 00:13 . 2011-09-01 00:13 94208 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\IccLibDll_x64.dll + 2011-11-20 12:57 . 2011-11-20 12:57 51496 c:\windows\system64\drivers\stflt.sys + 2011-11-16 00:29 . 2011-11-15 21:48 55384 c:\windows\system64\drivers\SBREDrv.sys + 2010-04-18 11:46 . 2011-11-21 02:46 16384 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-04-18 11:46 . 2011-11-13 17:32 16384 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-04-18 11:46 . 2011-11-21 02:46 32768 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2010-04-18 11:46 . 2011-11-13 17:32 32768 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-11-21 02:46 32768 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2011-11-13 17:32 32768 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-11-05 00:35 . 2011-11-24 03:05 62970 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-11-24 03:05 40484 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-04-17 19:53 . 2011-11-24 03:05 17040 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4272350839-2314675571-2890082633-1001_UserData.bin - 2009-07-14 05:30 . 2011-07-25 03:37 86016 c:\windows\system32\DriverStore\infpub.dat + 2009-07-14 05:30 . 2011-11-24 02:57 86016 c:\windows\system32\DriverStore\infpub.dat + 2011-09-01 00:58 . 2011-09-01 00:58 90112 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igxpco64.dll + 2011-09-01 00:13 . 2011-09-01 00:13 98304 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\iglhcp64.dll + 2011-09-01 00:13 . 2011-09-01 00:13 98304 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\iglhcp32.dll + 2011-09-01 00:21 . 2011-09-01 00:21 62464 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxsrvc.dll + 2011-09-01 00:16 . 2011-09-01 00:16 24576 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxexps32.dll + 2011-09-01 00:21 . 2011-09-01 00:21 28672 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxexps.dll + 2011-09-01 00:51 . 2011-09-01 00:51 75776 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdde64.dll + 2011-09-01 00:46 . 2011-09-01 00:46 56832 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdde32.dll + 2011-09-01 00:13 . 2011-09-01 00:13 94208 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\IccLibDll_x64.dll + 2010-04-18 11:46 . 2011-11-21 02:46 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-04-18 11:46 . 2011-11-13 17:32 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-04-18 11:46 . 2011-11-13 17:32 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2010-04-18 11:46 . 2011-11-21 02:46 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-11-21 02:46 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2011-11-13 17:32 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:46 . 2011-11-18 02:50 96544 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2011-01-05 03:22 . 2011-11-18 01:36 40960 c:\windows\Installer\{E4E7C669-B395-483C-9375-187CA8AE3340}\NewShortcut4_8767562FBF9A4B0B8CADB895F55B27E1.exe - 2011-01-05 03:22 . 2011-01-05 03:22 40960 c:\windows\Installer\{E4E7C669-B395-483C-9375-187CA8AE3340}\NewShortcut4_8767562FBF9A4B0B8CADB895F55B27E1.exe + 2011-01-05 03:22 . 2011-11-18 01:36 40960 c:\windows\Installer\{E4E7C669-B395-483C-9375-187CA8AE3340}\NewShortcut2_F95B713659EF431D875B8E0A9B463CD4.exe - 2011-01-05 03:22 . 2011-01-05 03:22 40960 c:\windows\Installer\{E4E7C669-B395-483C-9375-187CA8AE3340}\NewShortcut2_F95B713659EF431D875B8E0A9B463CD4.exe + 2011-01-05 03:22 . 2011-11-18 01:36 10134 c:\windows\Installer\{E4E7C669-B395-483C-9375-187CA8AE3340}\ARPPRODUCTICON.exe - 2011-01-05 03:22 . 2011-01-05 03:22 10134 c:\windows\Installer\{E4E7C669-B395-483C-9375-187CA8AE3340}\ARPPRODUCTICON.exe + 2011-11-24 03:01 . 2011-11-24 03:01 66956 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCall.dll - 2010-08-26 00:03 . 2010-08-26 00:03 4096 c:\windows\system64\IGFXDEVLib.dll + 2011-09-01 00:20 . 2011-09-01 00:20 4096 c:\windows\system64\IGFXDEVLib.dll + 2011-09-01 00:20 . 2011-09-01 00:20 4096 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\IGFXDEVLib.dll + 2011-09-01 00:20 . 2011-09-01 00:20 4096 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\IGFXDEVLib.dll + 2011-11-24 04:02 . 2011-11-24 04:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-11-15 04:04 . 2011-11-15 04:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2011-11-24 04:02 . 2011-11-24 04:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-11-15 04:04 . 2011-11-15 04:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-01-05 03:22 . 2011-11-18 01:36 2550 c:\windows\Installer\{E4E7C669-B395-483C-9375-187CA8AE3340}\NewShortcut1_61E3EB1949394125895A39D9BA2EB7D6.exe - 2011-01-05 03:22 . 2011-01-05 03:22 2550 c:\windows\Installer\{E4E7C669-B395-483C-9375-187CA8AE3340}\NewShortcut1_61E3EB1949394125895A39D9BA2EB7D6.exe + 2011-06-11 06:58 . 2011-06-11 06:58 773968 c:\windows\SysWOW64\msvcr100.dll + 2011-06-11 06:58 . 2011-06-11 06:58 421200 c:\windows\SysWOW64\msvcp100.dll + 2011-09-01 00:51 . 2011-09-01 00:51 867020 c:\windows\SysWOW64\igkrng575.bin + 2011-09-01 00:51 . 2011-09-01 00:51 105608 c:\windows\SysWOW64\igfcg575m.bin + 2011-09-01 00:51 . 2011-09-01 00:51 128204 c:\windows\SysWOW64\igcompkrng575.bin + 2011-06-11 06:58 . 2011-06-11 06:58 138056 c:\windows\SysWOW64\atl100.dll + 2010-04-25 05:45 . 2011-11-19 20:27 248618 c:\windows\system64\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2011-09-01 00:13 . 2011-09-01 00:13 376832 c:\windows\system64\iglhsip64.dll + 2011-09-01 00:51 . 2011-09-01 00:51 867020 c:\windows\system64\igkrng575.bin + 2011-09-01 01:08 . 2011-09-01 01:08 167704 c:\windows\system64\igfxtray.exe + 2011-09-01 00:21 . 2011-09-01 00:21 378368 c:\windows\system64\igfxTMM.dll + 2011-09-01 01:08 . 2011-09-01 01:08 510232 c:\windows\system64\igfxsrvc.exe + 2011-09-01 00:21 . 2011-09-01 00:21 375808 c:\windows\system64\igfxpph.dll + 2011-09-01 01:08 . 2011-09-01 01:08 416024 c:\windows\system64\igfxpers.exe + 2011-09-01 01:08 . 2011-09-01 01:08 239896 c:\windows\system64\igfxext.exe + 2011-09-01 00:20 . 2011-09-01 00:20 142336 c:\windows\system64\igfxdo.dll - 2010-08-26 00:03 . 2010-08-26 00:03 142336 c:\windows\system64\igfxdo.dll + 2009-12-14 15:32 . 2011-09-01 00:20 390144 c:\windows\system64\igfxdev.dll + 2011-09-01 00:13 . 2011-09-01 00:13 140288 c:\windows\system64\igfxcmrt64.dll + 2011-09-01 00:51 . 2011-09-01 00:51 105608 c:\windows\system64\igfcg575m.bin + 2011-09-01 00:51 . 2011-09-01 00:51 128204 c:\windows\system64\igcompkrng575.bin + 2011-09-01 01:08 . 2011-09-01 01:08 392472 c:\windows\system64\hkcmd.exe + 2009-12-14 15:32 . 2011-09-01 00:20 110080 c:\windows\system64\hccutils.dll + 2011-09-01 00:20 . 2011-09-01 00:20 146432 c:\windows\system64\gfxSrvc.dll + 2009-07-14 05:30 . 2011-11-24 02:57 143360 c:\windows\system64\DriverStore\infstrng.dat - 2009-07-14 05:30 . 2011-07-25 03:37 143360 c:\windows\system64\DriverStore\infstrng.dat - 2009-07-14 05:30 . 2011-07-25 03:37 143360 c:\windows\system64\DriverStore\infstor.dat + 2009-07-14 05:30 . 2011-11-24 02:57 143360 c:\windows\system64\DriverStore\infstor.dat + 2011-09-01 00:13 . 2011-09-01 00:13 376832 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\iglhsip64.dll + 2011-09-01 00:13 . 2011-09-01 00:13 376832 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\iglhsip32.dll + 2011-09-01 00:51 . 2011-09-01 00:51 963116 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igkrng600.bin + 2011-09-01 00:51 . 2011-09-01 00:51 867020 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igkrng575.bin + 2011-09-01 01:08 . 2011-09-01 01:08 167704 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxtray.exe + 2011-09-01 00:21 . 2011-09-01 00:21 378368 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxTMM.dll + 2011-09-01 01:08 . 2011-09-01 01:08 510232 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxsrvc.exe + 2011-09-01 00:21 . 2011-09-01 00:21 375808 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxpph.dll + 2011-09-01 01:08 . 2011-09-01 01:08 416024 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxpers.exe + 2011-09-01 01:08 . 2011-09-01 01:08 239896 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxext.exe + 2011-09-01 00:15 . 2011-09-01 00:15 294400 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxdv32.dll + 2011-09-01 00:20 . 2011-09-01 00:20 142336 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxdo.dll + 2011-09-01 00:20 . 2011-09-01 00:20 390144 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxdev.dll + 2011-09-01 00:13 . 2011-09-01 00:13 140288 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxcmrt64.dll + 2011-09-01 00:13 . 2011-09-01 00:13 162816 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxcmrt32.dll + 2011-09-01 00:51 . 2011-09-01 00:51 216000 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfcg600m.bin + 2011-09-01 00:51 . 2011-09-01 00:51 105608 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfcg575m.bin + 2011-09-01 00:45 . 2011-09-01 00:45 581120 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdumdx32.dll + 2011-09-01 00:51 . 2011-09-01 00:51 145804 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igcompkrng600.bin + 2011-09-01 00:51 . 2011-09-01 00:51 128204 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igcompkrng575.bin + 2011-09-01 01:08 . 2011-09-01 01:08 392472 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\hkcmd.exe + 2011-09-01 00:20 . 2011-09-01 00:20 110080 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\hccutils.dll + 2011-09-01 00:20 . 2011-09-01 00:20 146432 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\gfxSrvc.dll + 2011-09-01 01:08 . 2011-09-01 01:08 179992 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\difx64.exe + 2011-08-04 14:20 . 2011-08-04 14:20 137144 c:\windows\system64\drivers\epfwwfpr.sys + 2011-08-04 14:20 . 2011-08-04 14:20 146432 c:\windows\system64\drivers\ehdrv.sys + 2011-08-09 19:24 . 2011-08-09 19:24 202576 c:\windows\system64\drivers\eamonm.sys + 2011-09-01 01:08 . 2011-09-01 01:08 179992 c:\windows\system64\difx64.exe - 2009-07-14 05:12 . 2011-11-13 16:50 262144 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2009-07-14 05:12 . 2011-11-20 12:57 262144 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2011-11-17 00:33 . 2011-09-06 21:45 254400 c:\windows\system64\aswBoot.exe + 2010-04-25 05:45 . 2011-11-19 20:27 248618 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2009-07-14 05:30 . 2011-07-25 03:37 143360 c:\windows\system32\DriverStore\infstrng.dat + 2009-07-14 05:30 . 2011-11-24 02:57 143360 c:\windows\system32\DriverStore\infstrng.dat + 2009-07-14 05:30 . 2011-11-24 02:57 143360 c:\windows\system32\DriverStore\infstor.dat - 2009-07-14 05:30 . 2011-07-25 03:37 143360 c:\windows\system32\DriverStore\infstor.dat + 2011-09-01 00:13 . 2011-09-01 00:13 376832 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\iglhsip64.dll + 2011-09-01 00:13 . 2011-09-01 00:13 376832 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\iglhsip32.dll + 2011-09-01 00:51 . 2011-09-01 00:51 963116 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igkrng600.bin + 2011-09-01 00:51 . 2011-09-01 00:51 867020 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igkrng575.bin + 2011-09-01 01:08 . 2011-09-01 01:08 167704 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxtray.exe + 2011-09-01 00:21 . 2011-09-01 00:21 378368 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxTMM.dll + 2011-09-01 01:08 . 2011-09-01 01:08 510232 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxsrvc.exe + 2011-09-01 00:21 . 2011-09-01 00:21 375808 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxpph.dll + 2011-09-01 01:08 . 2011-09-01 01:08 416024 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxpers.exe + 2011-09-01 01:08 . 2011-09-01 01:08 239896 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxext.exe + 2011-09-01 00:15 . 2011-09-01 00:15 294400 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxdv32.dll + 2011-09-01 00:20 . 2011-09-01 00:20 142336 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxdo.dll + 2011-09-01 00:20 . 2011-09-01 00:20 390144 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxdev.dll + 2011-09-01 00:13 . 2011-09-01 00:13 140288 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxcmrt64.dll + 2011-09-01 00:13 . 2011-09-01 00:13 162816 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxcmrt32.dll + 2011-09-01 00:51 . 2011-09-01 00:51 216000 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfcg600m.bin + 2011-09-01 00:51 . 2011-09-01 00:51 105608 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfcg575m.bin + 2011-09-01 00:45 . 2011-09-01 00:45 581120 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdumdx32.dll + 2011-09-01 00:51 . 2011-09-01 00:51 145804 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igcompkrng600.bin + 2011-09-01 00:51 . 2011-09-01 00:51 128204 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igcompkrng575.bin + 2011-09-01 01:08 . 2011-09-01 01:08 392472 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\hkcmd.exe + 2011-09-01 00:20 . 2011-09-01 00:20 110080 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\hccutils.dll + 2011-09-01 00:20 . 2011-09-01 00:20 146432 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\gfxSrvc.dll + 2011-09-01 01:08 . 2011-09-01 01:08 179992 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\difx64.exe + 2011-08-04 14:20 . 2011-08-04 14:20 137144 c:\windows\system32\drivers\epfwwfpr.sys + 2011-08-04 14:20 . 2011-08-04 14:20 146432 c:\windows\system32\drivers\ehdrv.sys + 2011-08-09 19:24 . 2011-08-09 19:24 202576 c:\windows\system32\drivers\eamonm.sys + 2009-07-14 05:12 . 2011-11-20 12:57 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat - 2009-07-14 05:12 . 2011-11-13 16:50 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2009-07-14 05:01 . 2011-11-24 04:02 308040 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2011-11-15 04:03 308040 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-02-20 04:08 . 2011-02-20 04:08 163840 c:\windows\Installer\75654d.msi + 2009-07-12 17:16 . 2009-07-12 17:16 223232 c:\windows\Installer\1ff879.msi + 2011-04-19 09:54 . 2011-04-19 09:54 227328 c:\windows\Installer\1a0208.msi + 2011-11-22 00:32 . 2011-11-22 00:32 188145 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCalla36.exe + 2011-11-24 03:01 . 2011-11-24 03:01 188145 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCalla36.dll + 2011-11-24 03:01 . 2011-11-24 03:01 175992 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCalla34.dll + 2011-11-24 03:01 . 2011-11-24 03:01 176035 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCalla33.dll + 2011-11-24 03:01 . 2011-11-24 03:01 176545 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCalla32.dll + 2011-11-24 03:01 . 2011-11-24 03:01 184625 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCalla31.exe + 2011-11-24 03:01 . 2011-11-24 03:01 188108 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCalla21.dll + 2011-11-24 03:01 . 2011-11-24 03:01 176035 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCalla2.dll + 2011-11-24 03:01 . 2011-11-24 03:01 179340 c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP\WiseCustomCalla.dll + 2011-06-11 06:58 . 2011-06-11 06:58 4422992 c:\windows\SysWOW64\mfc100u.dll + 2011-06-11 06:58 . 2011-06-11 06:58 4397384 c:\windows\SysWOW64\mfc100.dll + 2009-12-14 15:32 . 2011-09-01 00:20 9014784 c:\windows\system64\igfxress.dll + 2011-09-01 00:53 . 2011-09-01 00:53 8312320 c:\windows\system64\igdumd64.dll + 2011-09-01 01:08 . 2011-09-01 01:08 4378392 c:\windows\system64\GfxUI.exe + 2011-09-01 00:20 . 2011-09-01 00:20 9014784 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxress.dll + 2011-09-01 00:53 . 2011-09-01 00:53 8312320 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdumd64.dll + 2011-09-01 00:47 . 2011-09-01 00:47 6322688 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdumd32.dll + 2011-09-01 01:08 . 2011-09-01 01:08 4378392 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\GfxUI.exe + 2011-09-01 00:20 . 2011-09-01 00:20 9014784 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igfxress.dll + 2011-09-01 00:53 . 2011-09-01 00:53 8312320 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdumd64.dll + 2011-09-01 00:47 . 2011-09-01 00:47 6322688 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdumd32.dll + 2011-09-01 01:08 . 2011-09-01 01:08 4378392 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\GfxUI.exe + 2009-07-14 04:45 . 2011-11-18 02:27 7223330 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat + 2011-06-29 02:27 . 2011-06-29 02:27 4028928 c:\windows\Installer\19ce3d.msp + 2011-11-23 00:46 . 2011-11-23 00:46 1402880 c:\windows\Installer\1374d4.msi + 2011-11-18 02:21 . 2011-08-30 04:21 12872704 c:\windows\SysWOW64\shell32.dll - 2009-07-14 02:34 . 2011-11-14 08:04 10747904 c:\windows\system64\SMI\Store\Machine\schema.dat + 2009-07-14 02:34 . 2011-11-18 02:23 10747904 c:\windows\system64\SMI\Store\Machine\schema.dat + 2011-11-18 02:21 . 2011-08-30 05:25 14173184 c:\windows\system64\shell32.dll + 2009-12-14 15:32 . 2011-09-01 00:42 14598656 c:\windows\system64\igd10umd64.dll + 2011-09-01 00:31 . 2011-09-01 00:31 18641408 c:\windows\system64\ig4icd64.dll + 2011-09-01 00:53 . 2011-09-01 00:53 12306848 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdkmd64.sys + 2011-09-01 00:42 . 2011-09-01 00:42 14598656 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igd10umd64.dll + 2011-09-01 00:37 . 2011-09-01 00:37 12340224 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igd10umd32.dll + 2011-09-01 00:31 . 2011-09-01 00:31 18641408 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\ig4icd64.dll + 2011-09-01 00:26 . 2011-09-01 00:26 13903872 c:\windows\system64\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\ig4icd32.dll + 2011-09-01 00:53 . 2011-09-01 00:53 12306848 c:\windows\system64\drivers\igdkmd64.sys + 2009-07-14 02:34 . 2011-11-18 02:23 10747904 c:\windows\system32\SMI\Store\Machine\schema.dat - 2009-07-14 02:34 . 2011-11-14 08:04 10747904 c:\windows\system32\SMI\Store\Machine\schema.dat + 2011-11-18 02:21 . 2011-08-30 05:25 14173184 c:\windows\system32\shell32.dll + 2011-09-01 00:53 . 2011-09-01 00:53 12306848 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igdkmd64.sys + 2011-09-01 00:42 . 2011-09-01 00:42 14598656 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igd10umd64.dll + 2011-09-01 00:37 . 2011-09-01 00:37 12340224 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\igd10umd32.dll + 2011-09-01 00:31 . 2011-09-01 00:31 18641408 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\ig4icd64.dll + 2011-09-01 00:26 . 2011-09-01 00:26 13903872 c:\windows\system32\DriverStore\FileRepository\hpdt64.inf_amd64_neutral_53a013863729abd0\ig4icd32.dll + 2010-10-22 02:49 . 2011-11-24 04:02 25015260 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4272350839-2314675571-2890082633-1001-12288.dat . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2009-09-11 05:41 120104 —-a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2009-09-24 261888] "EgisTecLiveUpdate"="c:\program files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-11-01 1100368] "Client Access Service"="c:\program files (x86)\IBM\Client Access\cwbsvstr.exe" [2005-10-19 20531] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x] R3 cpuz134;cpuz134;c:\users\Jonathon\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x] R3 esgiguard;esgiguard;c:\program files\ENIGMA SOFTWARE GROUP\SPYHUNTER\esgiguard.sys [x] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [x] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x] R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-09-11 305448] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272] R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-06-18 50432] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 !SASCORE;SAS Core Service;c:\program files\SUPERANTISPYWARE\SASCORE64.EXE [2011-11-20 140672] R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-17 135664] R4 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-17 135664] R4 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files (x86)\Spyware Terminator\st_rsser64.exe [2011-09-28 1148632] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-09-30 844320] S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-09-24 62720] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-06-18 144640] S2 sp_rsdrv2;Spyware Terminator Driver Filter;c:\windows\system32\DRIVERS\stflt.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 2320920] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-17 20:30] . 2011-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-17 20:30] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2009-09-11 05:44 137512 —-a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-07-22 323072] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904] "mwlDaemon"="c:\program files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-09-11 349480] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-29 8312352] "PLFSetI"="c:\windows\PLFSetI.exe" [2009-11-20 200704] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-09-30 823840] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-09-01 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-09-01 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-09-01 416024] . ——- Supplementary Scan ——- . uStart Page = about:blank uLocal Page = c:\windows\system32\blank.htm mStart Page = about:blank mLocal Page = c:\windows\SYSTEM32\blank.htm TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.youtube.com/watch?v=fsEbM77DD_U&NR=1|http://forums.corvetteforum.com/c5-tech/2916387-vengeance-racing-built-1999-427-c5-corvette-videos-dyno-graph-pics-inside.html|http://www.youtube.com/watch?v=EOd9Wd9l9LA|http://www.youtube.com/watch?v=WWHPyrp7BSM&feature=related|http://ls1tech.com/forums/generation-iii-internal-engine/1469330-heads-cam-problem.html|http://ls1tech.com/forums/generation-iii-internal-engine/1469308-finally-got-my-cam.html . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) AddRemove-HijackThis - c:\users\Jonathon\Documents\My Received Files\hijackthis\HijackThis.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe . ************************************************************************** . Completion time: 2011-11-24 06:20:56 - machine was rebooted ComboFix-quarantined-files.txt 2011-11-24 11:20 ComboFix2.txt 2011-11-15 04:28 ComboFix3.txt 2011-11-13 22:52 . Pre-Run: 182,162,722,816 bytes free Post-Run: 180,678,692,864 bytes free . - - End Of File - - 095D863BC968EAA2A1BFC3C969310700
Hi 87gtNOS,

Happy Thanksgiving :D

I'd like to run a few more scans. I'm still not seeing anything.

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs
===================================================

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.
Thanks again!
I ran OTL the first time without selecting all users, so I ran it a 2nd time and the 2nd time it only gave me one txt file (OTL.txt) so I pasted the 1st Extras.txt.

OTL.txt

OTL logfile created on: 11/24/2011 2:29:51 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jonathon\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.68 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 61.32% Memory free
7.35 Gb Paging File | 5.93 Gb Available in Paging File | 80.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.30 Gb Total Space | 167.67 Gb Free Space | 58.77% Space Free | Partition Type: NTFS
Drive D: | 49.32 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 285.30 Gb Total Space | 167.67 Gb Free Space | 58.77% Space Free | Partition Type: NTFS

Computer Name: JONATHON-ACER | User Name: Jonathon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/24 14:17:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Jonathon\Downloads\OTL.exe
PRC - [2011/04/08 11:59:52 | 000,507,624 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/11/20 18:34:08 | 000,200,704 | —- | M] () – C:\Windows\PLFSetI.exe
PRC - [2009/11/01 18:40:52 | 001,100,368 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/09/30 23:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 23:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/09/24 18:42:32 | 000,261,888 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
PRC - [2009/09/24 18:42:28 | 000,062,720 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
PRC - [2009/09/11 00:42:30 | 000,349,480 | —- | M] (Egis Technology Inc.) – C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
PRC - [2009/08/28 04:38:58 | 001,150,496 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
PRC - [2009/08/04 16:09:34 | 000,199,464 | —- | M] (Egis Technology Inc.) – C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
PRC - [2009/07/03 21:47:12 | 000,240,160 | —- | M] (Acer) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2009/06/04 22:03:32 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/04 22:03:06 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe


========== Modules (No Company Name) ==========

MOD - [2009/11/20 18:34:08 | 000,200,704 | —- | M] () – C:\Windows\PLFSetI.exe
MOD - [2009/02/02 20:33:56 | 000,460,199 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/11/20 14:23:46 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Disabled | Stopped] – C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE – (!SASCORE)
SRV:64bit: - [2011/04/27 17:21:18 | 000,288,272 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV:64bit: - [2011/04/27 17:21:18 | 000,012,784 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2009/09/30 17:44:58 | 000,844,320 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/03 21:47:12 | 000,240,160 | —- | M] (Acer) [Auto | Running] – C:\Program Files\Acer\Acer Updater\UpdaterService.exe – (Updater Service)
SRV:64bit: - [2009/03/27 21:10:16 | 000,016,896 | —- | M] (LSI Corporation) [Auto | Running] – C:\Program Files\LSI SoftModem\agr64svc.exe – (AgereModemAudio)
SRV - [2011/09/28 03:09:58 | 001,148,632 | —- | M] (Crawler.com) [Disabled | Stopped] – C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe – (ST2012_Svc)
SRV - [2010/05/13 02:41:08 | 000,174,592 | —- | M] () [Disabled | Stopped] – C:\Program Files (x86)\Subsonic\subsonic-service.exe – (Subsonic)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/09/30 23:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2009/09/30 23:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/09/24 18:42:28 | 000,062,720 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2009/09/11 00:42:46 | 000,305,448 | —- | M] () [On_Demand | Stopped] – C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe – (MWLService)
SRV - [2009/08/28 04:38:58 | 001,150,496 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe – (Greg_Service)
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 22:03:06 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/05/22 13:02:20 | 000,250,616 | —- | M] (WildTangent, Inc.) [Disabled | Stopped] – C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe – (GameConsoleService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/11/20 07:57:45 | 000,051,496 | —- | M] (Windows ® Win 7 DDK provider) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\stflt.sys – (sp_rsdrv2)
DRV:64bit: - [2011/08/31 19:53:22 | 012,306,848 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011/04/29 13:34:32 | 000,100,864 | —- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ser2pl64.sys – (Ser2pl)
DRV:64bit: - [2011/04/27 15:25:24 | 000,084,864 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2009/10/30 09:56:34 | 000,244,736 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2009/10/26 15:39:44 | 000,151,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/10/16 01:33:06 | 000,050,176 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2009/10/05 16:34:00 | 001,542,656 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/09/17 23:12:06 | 000,292,912 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2009/09/17 15:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/08/13 14:20:46 | 001,209,856 | —- | M] (LSI Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\agrsm64.sys – (AgereSoftModem)
DRV:64bit: - [2009/08/06 07:43:58 | 000,320,040 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2009/07/22 17:06:26 | 000,040,448 | —- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AmUStor.sys – (AmUStor)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/19 21:09:57 | 000,054,272 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\L1E62x64.sys – (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:64bit: - [2009/06/10 15:34:38 | 001,311,232 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 21:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/06/02 22:15:30 | 000,060,464 | —- | M] (Egis Technology Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys – (mwlPSDVDisk)
DRV:64bit: - [2009/06/02 22:15:30 | 000,022,576 | —- | M] (Egis Technology Inc.) [File_System | System | Running] – C:\Windows\SysNative\drivers\mwlPSDFilter.sys – (mwlPSDFilter)
DRV:64bit: - [2009/06/02 22:15:30 | 000,020,016 | —- | M] (Egis Technology Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\mwlPSDNserv.sys – (mwlPSDNServ)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/05/05 19:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/05 19:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/02/17 11:18:48 | 000,069,192 | —- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ftdibus.sys – (FTDIBUS)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…18z1i5t5971d52n
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.youtube.com/watch?v=fsEbM77DD_U&NR=1|http://forums.corvetteforum.com/c5-tech/2916387-vengeance-racing-built-1999-427-c5-corvette-videos-dyno-graph-pics-inside.html|http://www.youtube.com/watch?v=EOd9Wd9l9LA|http://www.youtube.com/watch?v=WWHPyrp7BSM&feature=related|http://ls1tech.com/forums/generation-iii-internal-engine/1469330-heads-cam-problem.html|http://ls1tech.com/forums/generation-iii-internal-engine/1469308-finally-got-my-cam.html"

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Jonathon\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/14 20:11:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/16 18:56:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/11/21 21:51:52 | 000,000,000 | —D | M]

[2010/04/17 15:31:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Extensions
[2011/09/27 21:53:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions
[2010/12/31 11:41:40 | 000,000,000 | —D | M] (Image Zoom) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2010/04/17 16:04:42 | 000,000,000 | —D | M] (Media Converter) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
[2010/04/17 16:08:53 | 000,000,000 | —D | M] (IE View Lite) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\{FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3}
[2011/04/30 21:06:30 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\[removed]
[2010/12/11 22:15:38 | 000,000,000 | —D | M] (vShare) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\vshare@toolbar
[2010/10/23 20:57:41 | 000,001,583 | —- | M] () – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\searchplugins\web-search.xml
[2011/11/14 20:11:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/06/16 23:21:15 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
() (No name found) – C:\USERS\JONATHON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XA1ZY04V.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/05 01:53:18 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/04 22:21:03 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/04 22:21:03 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/11/24 05:59:56 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Client Access Service] C:\Program Files (x86)\IBM\Client Access\cwbsvstr.exe (IBM Corporation)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {73A8D51E-578B-4E4E-8FF8-112E51DBFBE3} http://caf.oeconnection.ca/ActiveX/DMSISM.CAB (ADPConn Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{079E895E-A34A-44CA-AB30-B5385D4D0B79}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{271FAE41-A699-468D-8B03-90E11F141682}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/11/21 19:34:00 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/03/23 00:21:14 | 000,000,038 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/24 14:13:16 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C7D6F82E-2B81-4F61-AB2F-BF01787D9563}
[2011/11/24 14:13:03 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{26CD7851-8899-40C6-88A9-FAC0DEBF427C}
[2011/11/24 06:21:32 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/24 06:02:05 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/23 22:11:44 | 000,000,000 | —D | C] – C:\ComboFix
[2011/11/23 22:09:33 | 004,306,022 | R— | C] (Swearware) – C:\Users\Jonathon\Desktop\ComboFix.exe
[2011/11/23 19:27:14 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{6AA4297C-E9C6-427F-9B3B-F0C6F32C9055}
[2011/11/23 19:27:00 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{393113E8-AECE-4319-90BF-AF3FC6459262}
[2011/11/22 19:59:25 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DD3E6170-5244-4968-AA33-B4C3EA46426C}
[2011/11/22 19:59:15 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{72DAF5E3-E635-4381-94F2-3BDC28AA38F1}
[2011/11/21 21:51:48 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2011/11/21 21:51:48 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/11/21 21:04:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2011/11/21 21:04:14 | 000,000,000 | —D | C] – C:\rei
[2011/11/21 21:04:03 | 000,000,000 | —D | C] – C:\Program Files\Reimage
[2011/11/21 19:33:33 | 000,000,000 | —D | C] – C:\sh4ldr
[2011/11/21 19:33:33 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2011/11/21 19:31:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2011/11/21 18:47:40 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{59104D40-4DDD-4E04-B96C-D8318CEC757F}
[2011/11/21 18:47:02 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4B05806E-3EA5-4EFE-B7B3-7227A9B872F3}
[2011/11/20 20:13:18 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C571EA19-CD91-4394-8FCB-292471306875}
[2011/11/20 20:13:09 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C48BDE04-8BE7-4AA2-A143-67494879B46A}
[2011/11/20 20:12:47 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{544BD090-ABBE-4179-83A5-0F1BEDF291D3}
[2011/11/20 20:12:37 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{192ADDE0-1229-42D2-9236-B2F696C7D2EB}
[2011/11/20 14:20:53 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/20 14:20:29 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2011/11/20 14:20:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/11/20 14:20:23 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/11/20 14:20:23 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/11/20 08:12:12 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{98F656C6-F277-4DC0-B7B0-A1CD4F6C2675}
[2011/11/20 08:12:03 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{3A4D92DA-1309-4A5D-AFC9-1B91112CAB62}
[2011/11/20 08:11:53 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{B7A5EBE1-71A4-484E-8DCF-D22AC55AEE67}
[2011/11/20 08:11:43 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{AC801BF8-1680-444A-9EEA-5A9D43DDF989}
[2011/11/20 07:57:45 | 000,051,496 | —- | C] (Windows ® Win 7 DDK provider) – C:\Windows\SysNative\drivers\stflt.sys
[2011/11/20 07:57:44 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Roaming\Spyware Terminator
[2011/11/20 07:57:44 | 000,000,000 | —D | C] – C:\ProgramData\Spyware Terminator
[2011/11/20 07:57:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012
[2011/11/20 07:56:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spyware Terminator
[2011/11/19 20:11:14 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{93DADDCD-AAC2-4319-A4FE-64510192D718}
[2011/11/19 20:11:05 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{5BD290F0-0FAD-4F64-973D-929A9639F61E}
[2011/11/19 20:10:56 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{0B6981B5-28A5-4A11-9D6D-0A80F19D0942}
[2011/11/19 20:10:43 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{939604F1-D0CE-491C-AAC9-F5C536D3D90D}
[2011/11/19 08:10:18 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{D5E3AEEC-E141-4C47-B220-C020C94EB956}
[2011/11/19 08:10:09 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{264A4101-A2FC-415E-B5CC-7F034D4C614A}
[2011/11/19 08:09:45 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4E60AE43-418A-419F-B0FC-B2AC9A88AF99}
[2011/11/19 08:08:16 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{76A652E4-576E-4CD8-BC0E-A57A89F6E076}
[2011/11/18 19:44:31 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C876AECA-F88F-491B-846E-1B79215C120B}
[2011/11/18 19:44:18 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{8EC51DE4-F0F5-44E0-B87B-0A2A55C1E064}
[2011/11/18 19:44:04 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{74BF20F1-B07E-41A2-8D0E-A59F153B2627}
[2011/11/18 19:43:02 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{45E6B28D-9F87-48E6-AD10-19B8B1830246}
[2011/11/17 19:16:35 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{427B17F7-96C6-401F-B1E4-ABBA457BA26F}
[2011/11/17 19:16:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{5C1222A0-47ED-4320-9368-AB8CBECCA924}
[2011/11/17 19:16:06 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{E52430C3-F4CA-4A88-9AC9-7A5AB2F0E3C4}
[2011/11/17 19:15:56 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{26DBE823-26FD-468A-BEA7-E75F7DC7D1C0}
[2011/11/16 23:26:42 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Roaming\Malwarebytes
[2011/11/16 23:26:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/16 23:26:30 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/16 23:26:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/16 20:09:02 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{43A61615-C088-4137-95C9-C9F1CCA6165A}
[2011/11/16 20:08:49 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{E251BAF5-C81A-45F1-B994-73CAA968119E}
[2011/11/16 19:33:23 | 000,254,400 | —- | C] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2011/11/16 19:32:41 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2011/11/16 19:32:41 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/11/16 19:24:30 | 000,000,000 | —D | C] – C:\Users\Jonathon\Documents\tdsskiller
[2011/11/15 19:51:38 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DA48C1CE-217E-463B-ADD6-524B5BEB175A}
[2011/11/15 19:51:28 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{9C3D902E-F837-4644-B51E-E9161B6E6B4E}
[2011/11/15 19:29:45 | 000,055,384 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/11/15 19:29:17 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\Sunbelt Software
[2011/11/15 15:42:54 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2011/11/14 22:16:45 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/14 22:16:45 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/14 22:16:45 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/14 21:08:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2011/11/14 20:19:29 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{CBEDCB74-6865-406A-AC82-A4EA990347DB}
[2011/11/14 20:19:19 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{271D71BE-43CC-475D-8447-6B430C56001A}
[2011/11/13 18:25:49 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/11/13 16:35:54 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/13 16:30:29 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/13 15:13:51 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4743913C-9D55-4A9D-97F6-E50A37143A28}
[2011/11/13 15:13:41 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{3D2FE25C-6FDF-4BA5-98DD-5E5F9516DA2B}
[2011/11/13 15:09:22 | 000,200,976 | —- | C] (Trend Micro Inc.) – C:\Windows\SysWow64\drivers\tmcomm.sys
[2011/11/13 10:40:11 | 000,000,000 | —D | C] – C:\ProgramData\Intel
[2011/11/13 10:24:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/11/13 10:24:33 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/13 10:20:38 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/11/13 01:38:57 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{A04CBDE0-FDBC-4DFF-BC7D-4C8903F9E1F1}
[2011/11/13 01:38:44 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{2E43166C-37FC-4279-84B5-98A355ECCA23}
[2011/11/12 23:14:10 | 000,000,000 | —D | C] – C:\Windows\system64
[2011/11/12 16:52:46 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{553785EC-8732-4E77-8443-5B3870BE1285}
[2011/11/12 16:52:37 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{E6F922C6-CE17-4C01-BF99-130FD9411720}
[2011/11/12 16:52:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{220F0B2B-7BAC-47FC-9A58-280C0FDBB36A}
[2011/11/11 19:16:33 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{CF5CF72B-2834-4F65-96C3-CE1CCFA1F40A}
[2011/11/11 19:16:22 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{EE1C2132-212C-445A-ABC6-C86637477195}
[2011/11/11 19:16:08 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{72479621-AB8F-4912-92A2-BCF28A392967}
[2011/11/10 21:20:25 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DC1DC940-3B42-4F28-BD7D-4F5F2D1C4D58}
[2011/11/10 21:20:15 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{BE3E2140-0C50-47F6-9914-78C53735BC3B}
[2011/11/10 21:20:00 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{E1DFE2F8-FDF2-4926-BF66-DFCA0C4EEB2A}
[2011/11/09 22:36:25 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DCE84556-2768-4907-B665-CE7711399C41}
[2011/11/09 22:36:11 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DADFF1BB-BF20-4DC3-9D2F-E268B7D2911F}
[2011/11/08 22:01:32 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{930B9656-1152-439B-A529-784549A29527}
[2011/11/08 22:01:22 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{1AD79A5D-B6A1-409B-8FA5-7E89A59FFED2}
[2011/11/07 19:29:17 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{430DE90D-6321-480B-9BC9-B626C6C3C173}
[2011/11/07 19:29:07 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{9972C1BB-7B0E-4333-9D11-6E1D65C3981A}
[2011/11/06 21:33:20 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{57BD25F9-B4E7-45A5-8BB9-DA1533133D1E}
[2011/11/06 21:33:10 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4A33B707-5575-4A56-9F01-EF545BB32AF6}
[2011/11/06 21:33:01 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{0D4CAD39-2BCD-41BC-9C2F-A3F7B3ACCCE8}
[2011/11/06 09:32:40 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{AA5883A8-F72B-43A1-AF98-26DD9F0FDC3C}
[2011/11/06 09:32:30 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{1D423E37-0ACE-430C-AD41-A72DDAA36B11}
[2011/11/06 09:32:21 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{841578C6-C738-464E-8849-1916130A2A79}
[2011/11/06 09:32:11 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{1B93BDE7-C294-450D-B2F6-F0D588B7F948}
[2011/11/05 21:31:45 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{8248DC40-C05E-4589-99CA-EAB985EFF3F2}
[2011/11/05 21:31:36 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{0FBBD112-EAF4-4742-8D33-B29521B7CEA3}
[2011/11/05 21:31:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{859D8FA1-C098-4190-9537-FDFAA383972C}
[2011/11/05 07:56:21 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{74C3BA76-B617-4167-A805-42CA3933844A}
[2011/11/05 07:56:10 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{6E98FBA0-F729-44B2-8A5F-5F05FF5607A3}
[2011/11/05 07:55:58 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{D76FCB28-5479-486E-A98C-8863933F0293}
[2011/11/04 18:53:10 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{EA5E3D54-0589-4220-A7C2-8FD6BE6FC67B}
[2011/11/04 18:53:01 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4A628A31-91CB-4246-B8C7-6AEF6E1E76ED}
[2011/11/04 18:52:50 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{396E8248-DE05-4FD9-BEFE-B714C70900A7}
[2011/11/03 18:49:54 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{913B6D51-6CDA-44B2-9F51-821A7E52BFE0}
[2011/11/03 18:49:44 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{70CE2689-DEBA-46AA-9FF7-A257B06769A6}
[2011/11/03 18:49:35 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{9A6CD843-BE87-49AF-AE56-BD5607612BB3}
[2011/11/02 19:59:19 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{3C794409-991C-4B72-97F3-01DA099BAFF4}
[2011/11/02 19:59:09 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{65223751-37A3-4741-9B6A-BCD261C94B66}
[2011/11/02 19:59:00 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{F6C9D7AD-540C-4A20-AA25-66C76081C9E8}
[2011/11/02 19:58:47 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{7CA377D2-AF29-400E-9641-ED173A35D655}
[2011/11/01 18:33:41 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{2251D5DE-58EF-436A-B335-95D840A6726A}
[2011/11/01 18:33:31 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{F257E7F1-79B5-4B0A-B777-2C57CEAEC35C}
[2011/11/01 18:33:21 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{FD8FF9CF-A7A8-4DFF-B45B-F8D9C98E7B97}
[2011/11/01 18:33:11 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4898FE18-7D24-4106-A756-1AF50E8E7048}
[2011/10/31 18:25:56 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{20BAA1B1-0E01-49BB-998A-DD7B9555F27F}
[2011/10/31 18:25:45 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{00992023-066D-4EF7-899C-B698DCCCB780}
[2011/10/31 18:25:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{6FBB1D93-6DC1-47F8-AAFD-518A9AED6B78}
[2011/10/30 19:49:57 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{9DE798BD-1AC4-4EE1-A75C-4E45F67A98E8}
[2011/10/30 19:49:48 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{42FB7ED7-FC9F-4408-A4EE-67578ECD080D}
[2011/10/30 19:49:38 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{5320BEF9-180C-4422-ADF0-64DECBBCEB8F}
[2011/10/30 18:50:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/10/30 07:49:17 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{83480B49-70E5-4DC9-A4CB-59F5896875DD}
[2011/10/30 07:49:07 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{A6C31C21-333B-4860-ADC1-5F5B57108604}
[2011/10/30 07:48:58 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{866A3738-DA0B-454B-B875-B6EFDA3EB0D3}
[2011/10/30 07:48:48 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{188914E9-3B80-4EFB-B55D-9ECAC68CBBF5}
[2011/10/29 19:48:19 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{B590FA27-F45F-43B7-85B6-31D9D4F167BB}
[2011/10/29 19:48:10 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{D77B0EBC-1732-4046-B5E1-78C2D8ED6F63}
[2011/10/29 07:47:45 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{8428CA4A-A5B7-4DDA-A398-925874063E14}
[2011/10/29 07:47:35 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{5365644F-9B35-4E34-9C20-A0BE9CB04C54}
[2011/10/28 18:47:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{59477A08-BE31-4A3A-A0B6-45BBCCFABA61}
[2011/10/28 18:47:16 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{7BE2E7FD-E1B9-49A7-80AE-DCF1BEDCAA99}
[2011/10/27 18:15:19 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{CBDF218C-94D7-447A-8D95-9F22DD13B929}
[2011/10/27 18:15:09 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{AC2463B6-3AB2-4E01-8852-17CCE4C35952}
[2011/10/27 18:14:58 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{F5FDDFD6-245E-414C-BFF9-568D73C99D23}
[2011/10/26 18:30:02 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{401813B7-E637-4517-B4E6-DB72B66CC5E2}
[2011/10/26 18:29:51 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{B3724040-D8B9-4AF2-9C53-A3BA41C53995}
[2011/10/26 18:29:41 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{3663F61A-5078-4327-847D-0A067D6E9991}
[2011/10/26 18:29:30 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4913299F-743E-4FA5-A13B-2212DB714297}
[2011/10/25 18:38:49 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C6392C3E-F668-4ACD-B930-6A7CDA21F024}
[2011/10/25 18:38:40 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{2E4F20A6-FCC1-403B-85E6-665C1AF05722}
[2011/10/25 18:38:30 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{EBBFF44C-EBD0-48CA-9187-A545A14ECB59}
[2011/10/25 18:38:21 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{2DC16E38-F65A-4AA3-9964-DE6C0D693771}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/24 14:16:05 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/24 14:12:54 | 000,006,784 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/24 14:12:54 | 000,006,784 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/24 14:08:21 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/24 14:05:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/24 14:05:33 | 2960,506,880 | -HS- | M] () – C:\hiberfil.sys
[2011/11/24 05:59:56 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/11/23 22:09:44 | 004,306,022 | R— | M] (Swearware) – C:\Users\Jonathon\Desktop\ComboFix.exe
[2011/11/23 20:26:55 | 000,000,512 | —- | M] () – C:\Users\Jonathon\Desktop\MBR.dat
[2011/11/22 19:47:07 | 000,002,991 | —- | M] () – C:\Users\Jonathon\Desktop\HiJackThis.lnk
[2011/11/22 19:30:50 | 000,000,272 | —- | M] () – C:\Windows\reimage.ini
[2011/11/21 21:04:15 | 000,001,908 | —- | M] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2011/11/21 19:34:00 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2011/11/20 14:20:28 | 000,001,815 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/20 14:12:39 | 000,226,756 | —- | M] () – C:\Users\Jonathon\AppData\Local\census.cache
[2011/11/20 14:12:36 | 000,105,390 | —- | M] () – C:\Users\Jonathon\AppData\Local\ars.cache
[2011/11/20 07:57:45 | 000,051,496 | —- | M] (Windows ® Win 7 DDK provider) – C:\Windows\SysNative\drivers\stflt.sys
[2011/11/20 07:57:40 | 000,001,049 | —- | M] () – C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
[2011/11/20 00:46:52 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2011/11/20 00:46:52 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2011/11/19 20:28:35 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2011/11/16 23:26:32 | 000,001,120 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/15 16:48:46 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/11/15 06:33:31 | 000,007,591 | —- | M] () – C:\Users\Jonathon\AppData\Local\Resmon.ResmonCfg
[2011/11/14 21:08:24 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2011/11/14 21:08:05 | 000,735,726 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/14 21:08:05 | 000,631,002 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/14 21:08:05 | 000,112,054 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/14 20:11:41 | 000,002,056 | —- | M] () – C:\Users\Jonathon\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/14 20:11:23 | 000,001,145 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/14 03:05:31 | 000,343,552 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/13 15:06:15 | 000,000,036 | —- | M] () – C:\Users\Jonathon\AppData\Local\housecall.guid.cache
[2011/11/10 22:24:36 | 000,093,844 | —- | M] () – C:\Users\Jonathon\Desktop\papa.jpg
[2011/11/10 22:22:24 | 000,490,924 | —- | M] () – C:\Users\Jonathon\Desktop\IMG_0862.JPG
[2011/11/06 20:14:24 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/30 18:50:29 | 000,002,219 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/23 20:26:55 | 000,000,512 | —- | C] () – C:\Users\Jonathon\Desktop\MBR.dat
[2011/11/22 19:47:07 | 000,002,991 | —- | C] () – C:\Users\Jonathon\Desktop\HiJackThis.lnk
[2011/11/21 21:05:27 | 000,000,272 | —- | C] () – C:\Windows\reimage.ini
[2011/11/21 21:04:15 | 000,001,908 | —- | C] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2011/11/21 19:34:00 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2011/11/20 14:20:28 | 000,001,815 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/20 07:57:40 | 000,001,049 | —- | C] () – C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
[2011/11/20 00:46:52 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/11/20 00:46:52 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/11/16 23:26:32 | 000,001,120 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/16 19:33:23 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2011/11/14 23:06:55 | 000,006,784 | -H– | C] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 23:06:55 | 000,006,784 | -H– | C] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 22:16:45 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/14 22:16:45 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/14 22:16:45 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/14 22:16:45 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/14 22:16:45 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/11/14 21:08:24 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2011/11/14 21:08:05 | 000,735,726 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/14 21:08:00 | 000,001,904 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/11/14 20:11:23 | 000,001,145 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/13 15:14:44 | 000,226,756 | —- | C] () – C:\Users\Jonathon\AppData\Local\census.cache
[2011/11/13 15:14:31 | 000,105,390 | —- | C] () – C:\Users\Jonathon\AppData\Local\ars.cache
[2011/11/13 15:06:15 | 000,000,036 | —- | C] () – C:\Users\Jonathon\AppData\Local\housecall.guid.cache
[2011/11/10 22:24:35 | 000,093,844 | —- | C] () – C:\Users\Jonathon\Desktop\papa.jpg
[2011/11/10 22:23:35 | 000,490,924 | —- | C] () – C:\Users\Jonathon\Desktop\IMG_0862.JPG
[2011/10/30 18:50:29 | 000,002,219 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/08/31 19:51:16 | 000,867,020 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/08/31 19:51:16 | 000,128,204 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2011/08/31 19:51:16 | 000,105,608 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2011/08/31 19:26:20 | 013,903,872 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2011/06/29 06:26:41 | 000,126,769 | —- | C] () – C:\Windows\LogWorks3 Uninstaller.exe
[2011/04/03 21:01:11 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/09/11 21:53:10 | 000,007,591 | —- | C] () – C:\Users\Jonathon\AppData\Local\Resmon.ResmonCfg
[2010/08/06 19:27:21 | 000,114,685 | —- | C] () – C:\Windows\LogWorks Uninstaller.exe
[2010/06/03 17:16:32 | 000,020,534 | —- | C] () – C:\Windows\SysWow64\cwbunplp.exe
[2010/06/03 17:16:29 | 000,172,032 | —- | C] () – C:\Windows\SysWow64\cwbrw.dll
[2010/06/03 17:16:29 | 000,126,976 | —- | C] () – C:\Windows\cwbzip.exe
[2010/06/03 17:16:29 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\cwbsv.dll
[2010/06/03 17:16:29 | 000,020,529 | —- | C] () – C:\Windows\SysWow64\cwbwiz.dll
[2010/06/03 17:16:29 | 000,020,480 | —- | C] () – C:\Windows\SysWow64\cwbsy.dll
[2010/06/03 17:16:29 | 000,020,480 | —- | C] () – C:\Windows\SysWow64\cwbnl.dll
[2010/06/03 17:16:29 | 000,020,480 | —- | C] () – C:\Windows\SysWow64\cwbco.dll
[2010/06/03 17:16:29 | 000,016,384 | —- | C] () – C:\Windows\SysWow64\cwbnldlg.dll
[2010/06/03 17:16:29 | 000,016,384 | —- | C] () – C:\Windows\SysWow64\cwbad.dll
[2010/04/17 17:47:39 | 000,000,376 | —- | C] () – C:\Users\Jonathon\AppData\Roaming\wklnhst.dat
[2010/04/17 17:19:31 | 000,004,608 | —- | C] () – C:\Users\Jonathon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/17 15:31:12 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2009/12/14 10:49:26 | 000,626,688 | —- | C] () – C:\Windows\Image.dll
[2009/12/14 10:49:26 | 000,200,704 | —- | C] () – C:\Windows\PLFSetI.exe
[2009/12/14 10:49:26 | 000,020,480 | —- | C] () – C:\Windows\USB_VIDEO_REG.exe
[2009/12/14 10:49:26 | 000,000,323 | —- | C] () – C:\Windows\PidList.ini
[2009/12/14 10:32:09 | 000,001,233 | —- | C] () – C:\Windows\WPatchProgress.ini
[2009/11/04 19:21:23 | 000,000,193 | —- | C] () – C:\Windows\Prelaunch.ini
[2009/11/04 19:21:23 | 000,000,169 | —- | C] () – C:\Windows\WisLangCode.ini
[2009/11/04 19:21:23 | 000,000,147 | —- | C] () – C:\Windows\WisPriority.ini
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:59:36 | 000,982,196 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 16:59:36 | 000,139,824 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 16:59:36 | 000,097,448 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 16:59:35 | 000,417,344 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/06/12 19:45:08 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\DiskAid
[2011/04/29 22:10:14 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\DriverFinder
[2010/06/27 18:30:28 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\Facebook
[2011/05/09 18:34:55 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\navionicsChartInstaller.Air.A3B2DB703D5E0A7ECA24FBD4B07176191EDD3C63.1
[2011/11/20 07:57:44 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\Spyware Terminator
[2010/04/17 17:47:41 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\Template
[2010/04/17 19:33:48 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\WildTangent
[2010/10/23 23:32:17 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\Windows Live Writer
[2011/10/08 07:54:39 | 000,032,536 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\ERDNT\cache86\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 01:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 01:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 01:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 01:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\ERDNT\cache86\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\ERDNT\cache64\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\system64\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\ERDNT\cache86\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\ERDNT\cache64\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\system64\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\ERDNT\cache64\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\system64\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 02:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 01:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\ZX14 105in 107ex:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\Spyder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\SKEETER:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\New Folder1:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\New Folder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\JNG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\APEX:Roxio EMC Stream

< End of report >





Extras.txt

OTL Extras logfile created on: 11/24/2011 2:21:59 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jonathon\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.68 Gb Total Physical Memory | 2.51 Gb Available Physical Memory | 68.29% Memory free
7.35 Gb Paging File | 6.08 Gb Available in Paging File | 82.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.30 Gb Total Space | 168.37 Gb Free Space | 59.02% Space Free | Partition Type: NTFS
Drive D: | 49.32 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 285.30 Gb Total Space | 168.37 Gb Free Space | 59.02% Space Free | Partition Type: NTFS

Computer Name: JONATHON-ACER | User Name: Jonathon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe"

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
"DisableUnicastResponsesToMulticastBroadcast" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{2677AAE2-D8F8-40AE-9149-67618ED43EFD}_is1" = Trinity USB Drivers 1.1.1.1
"{404BB1FF-A84F-432F-B77B-301E88E8D1C7}" = Apple Mobile Device Support
"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96D5EB02-DE18-4DCD-A713-929B4461CA8D}" = iTunes
"{A325B368-A9EC-40EF-A95C-9DEAD3683AE3}" = Broadcom Gigabit NetLink Controller
"{B84E3B73-8A6D-434A-B656-327A560BDE24}" = cwbin64a
"{C19D4D8F-4433-4F6D-9F0C-79589FD0B973}" = Bonjour
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"73FC7E42C8F05A3B5235FB18804B1F5C84709230" = Windows Driver Package - Innovate Motorsports Innovate USB Driver (10/12/2009 1.4.1.0)
"B1A8F7E99596998546E45BBBFC8B527A13989809" = Windows Driver Package - DIABLO (usbser) Ports (01/30/2009 1.1.1.1)
"LSI Soft Modem" = LSI HDA Modem
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Reimage Repair" = Reimage Repair
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{021AC692-8CAC-43B3-8A10-EC6DEC3F9333}_is1" = version 1.0.4.0
"{08F32589-5E39-42B8-8BC5-6A8126ED2A70}" = Microsoft Visual C++ 2008 Redistributable Package
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{56736259-613E-4A3B-B428-6235F2E76F44}_is1" = Spyware Terminator 2012
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5EC8AAFD-0D89-958A-520B-E2B80B7FD016}" = Navionics Chart Installer
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{746104AD-F13F-4A32-8A03-2F6506C2E58E}" = Easy MSI Editor
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7760D94E-B1B5-40A0-9AA0-ABF942108755}" = Acer Crystal Eye Webcam
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00D1-0409-0000-0000000FF1CE}" = Microsoft Office Access database engine 2007 (English)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0568C61-9443-43F3-9938-E573A3BEFB7B}" = WinPEP 7
"{A723530D-EB71-47E6-BDCB-BAFF3C8FE329}" = DSLogRedux
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.4.6 MUI
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{C1FCDCA1-2759-4E5E-84EE-3A665BB2F513}" = iPhoneBrowser
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C82185E8-C27B-4EF4-2010-4444BC2C2B6D}" = Microsoft Streets & Trips 2010
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}" = Alcor Micro USB Card Reader
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E7C669-B395-483C-9375-187CA8AE3340}" = HP Tuners VCM Suite 2.22
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"AC3Filter_is1" = AC3Filter 1.63b
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"CleanUp!" = CleanUp!
"ClientAccessExpress" = IBM iSeries Access for Windows
"DSDownloader_is1" = DSDownloader [removed]
"Dynojet Display File Manager_is1" = Dynojet Display File Manager 1.0.3.2
"GridVista" = Acer GridVista
"HijackThis" = HijackThis 1.99.1
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Identity Card" = Identity Card
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Acer Backup Manager
"InstallShield_{A0568C61-9443-43F3-9938-E573A3BEFB7B}" = WinPEP 7
"InstallShield_{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}" = Alcor Micro USB Card Reader
"IrfanView" = IrfanView (remove only)
"LManager" = Launch Manager
"LogonStudio" = LogonStudio
"LogWorks" = LogWorks
"LogWorks3" = LogWorks3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"Power Commander 3 Usb_is1" = Power Commander Control Center 3.2.0 (Test Build 1)
"RADVideo" = RAD Video Tools
"Subsonic" = Subsonic
"Veetle TV" = Veetle TV 0.9.18
"VLC media player" = VLC media player 1.1.8
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite" = Windows Live Essentials
"YTdetect" = Yahoo! Detect

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Virus Total finally loaded! There is no 'file' as you described when you click browse…..there is only a 'folder' that has content from SpyHunter with files called WiseCustomCall.dll and an application WiseCustomCall36.
Hi 87gtNOS,

I'm still not seeing anything in the logs.

Let's try this:

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
===================================================

Next, I need you to make a batch file.

Open a new Notepad session

  • Click the Start button, click Run
  • In the run box type notepad
  • Click OK
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
@Echo on
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0

In the notepad

Click File, Save as…, and set the Save in to your Desktop
In the filename box, type (including quotation marks) as the filename: "flush.bat"
Click Save


You should now have a file on your desktop with an icon like this [external image: Posted Image]


Double click on flush.bat & allow it to run. A small black screen may briefly flash on and off, that normal

===================================================

Finally:
  • Click on the Start button and then choose Control Panel.
  • Click on the System and Security link.

    Note: If you're viewing the Large icons or Small icons view of Control Panel, you won't see this link so just click on the Administrative Tools icon and skip to Step 4.
  • In the System and Security window, click on the Administrative Tools heading located near the bottom of the window.
  • In the Administrative Tools window, double-click on the Computer Management icon.
  • When Computer Management opens, click on Disk Management on the left side of the window, located under Storage.

    After a brief loading period, Disk Management should now appear on the right side of the Computer Management window.

    Note: If you don't see Disk Management listed, you may need to click on the |> icon to the left of the Storage icon.
Take a screen Shot of the Disk Management Window and attach the screen shot to your reply.
Hi 87gtNOS, Thanks for the screenshot. Can you please open disk management again and tell me what the capacity and free space of the second volume is? It got cut off in the screenshot. It's the entry that says "Healthy (Active, Primary Partition)." Also, are you still getting redirects?
oops. C drive is 285.30 GB capacity, 167.31 GB free, 59% free, NO Fault tolerance, 0% overhead System Reserved is 100MB capacity, 70MB free and yes, it still redirects to shopping sites, etc….

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI