This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search Engine Redirect + PING.EXE [Closed]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was quite surprised to see so many threads about these particular infections in various tech support boards. Clicking any google search results redirects to a shopping website or some random website that dosen't look like it's registered (soandso Free Search Now!) I can also see PING.EXE in the task manager, it reopens automatically. ESET Smart Security detects an infected file at bootup and requests reboot to complete cleaning the infection, but however many times I restart the infection reappears. C:\Windows\assembly\GAC_32\Desktop.ini - a variant of Win32/Sirefef.DN trojan - cleaned by deleting (after the next restart) There were approx. 7 infections detected with M'Bytes Anti Malware, all of which were cleaned, scans come out clean as of today. I also noticed that the hosts file is deleted at machine boot or shutdown, not sure which excatly. DDS.txt . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29 Run by [removed] at 20:46:21 on 2011-11-23 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.8191.6127 [GMT 0:00] . AV: ESET Smart Security 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5} SP: ESET Smart Security 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe C:\ASUS.SYS\config\DVMExportService.exe C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe C:\Program Files (x86)\Common Files\Mediafour\M4LIC.EXE C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe C:\Windows\SysWOW64\vmnat.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe L:\Program Files (x86)\VMware Workstation\vmware-authd.exe C:\Windows\SysWOW64\vmnetdhcp.exe C:\Windows\system32\wbem\wmiprvse.exe L:\Program Files (x86)\VMware Workstation\vmware-hostd.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Nero\Update\NASvc.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe C:\Program Files\Mediafour\MacDrive 8\MacDrive.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Saitek\SD6\Software\SaiMfd.exe C:\Program Files\Logitech\SetPointP\SetPoint.exe C:\Program Files\ESET\ESET Smart Security\egui.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Program Files\ASUS\Turbo Key\TurboKey.exe C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Windows\SysWOW64\ping.exe C:\Windows\system32\conhost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: Logitech Scroll App: {e11db59d-5008-42ff-9069-535843bc0be1} - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - Yontoo Layers uRun: [AdobeBridge] uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background mRun: [Turbo Key] "C:\Program Files\ASUS\Turbo Key\TurboKey.exe" mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray StartupFolder: C:\Users\Filip\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: EnableLinkedConnections = 1 (0x1) IE: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll LSP: mswsock.dll LSP: %SystemRoot%\system32\vsocklib.dll DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{8242B4E1-B488-439F-A5FE-D4C3C23C4495} : DhcpNameServer = 192.168.1.254 TCP: Interfaces\{E2E466DE-8EB3-4A94-99D8-1DB2698E39BD} : DhcpNameServer = 192.168.55.2 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4 BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Skype Plug-In: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO-X64: SkypeIEPluginBHO - No File BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Free Download Manager: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO-X64: Logitech Scroll App: {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll BHO-X64: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - Yontoo Layers BHO-X64: Yontoo Layers - No File mRun-x64: [Turbo Key] "C:\Program Files\ASUS\Turbo Key\TurboKey.exe" mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL . ============= SERVICES / DRIVERS =============== . R0 MDFSYSNT;MacDrive file system driver;C:\Windows\system32\drivers\MDFSYSNT.sys –> C:\Windows\system32\drivers\MDFSYSNT.sys [?] R0 MDPMGRNT;MacDrive Partition Driver;C:\Windows\system32\DRIVERS\MDPMGRNT.SYS –> C:\Windows\system32\DRIVERS\MDPMGRNT.SYS [?] R1 CBDisk;CBDisk;\??\C:\Windows\system32\drivers\CBDisk.sys –> C:\Windows\system32\drivers\CBDisk.sys [?] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952] R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2011-4-26 90112] R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys –> C:\Windows\system32\drivers\cpuz135_x64.sys [?] R2 DvmMDES;DeviceVM Meta Data Export Service;C:\ASUS.SYS\config\DVMExportService.exe [2009-10-14 319488] R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-5-14 731840] R2 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys –> C:\Windows\system32\DRIVERS\epfwwfp.sys [?] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-8-15 2329480] R2 M4LIC;Mediafour M4LIC service;C:\Program Files (x86)\Common Files\Mediafour\M4LIC.EXE [2009-7-29 205312] R2 MacDrive8Service;MacDrive 8 service;C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe [2010-1-7 218112] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-13 366152] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-3-29 598312] R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-1 2253120] R2 RtNdPt60;Realtek NDIS Protocol Driver;C:\Windows\system32\DRIVERS\RtNdPt60.sys –> C:\Windows\system32\DRIVERS\RtNdPt60.sys [?] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-4-27 2280312] R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-3-9 92592] R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-8-21 846448] R2 VMwareHostd;VMware Workstation Server;L:\Program Files (x86)\VMware Workstation\vmware-hostd.exe [2011-8-22 11837440] R3 DKRtWrt;DKRtWrt;C:\Windows\system32\DRIVERS\DKRtWrt.sys –> C:\Windows\system32\DRIVERS\DKRtWrt.sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?] R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 V0260VID;Live! Cam Vista IM;C:\Windows\system32\DRIVERS\V0260Vid.sys –> C:\Windows\system32\DRIVERS\V0260Vid.sys [?] S2 AMService;AMService;C:\Windows\TEMP\dbnwjd\setup.exe run –> C:\Windows\TEMP\dbnwjd\setup.exe run [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 KMService;KMService;C:\Windows\System32\srvany.exe [2011-5-25 8192] S2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688] S3 ggflt;SEMC USB Flash Driver Filter;C:\Windows\system32\DRIVERS\ggflt.sys –> C:\Windows\system32\DRIVERS\ggflt.sys [?] S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys –> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536] S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?] S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys –> C:\Windows\system32\drivers\rdpvideominiport.sys [?] S3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0);C:\Windows\system32\DRIVERS\RtTeam60.sys –> C:\Windows\system32\DRIVERS\RtTeam60.sys [?] S3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.0);C:\Windows\system32\DRIVERS\RtVlan60.sys –> C:\Windows\system32\DRIVERS\RtVlan60.sys [?] S3 SaiK0836;SaiK0836;C:\Windows\system32\DRIVERS\SaiK0836.sys –> C:\Windows\system32\DRIVERS\SaiK0836.sys [?] S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-6-5 152064] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);C:\Windows\system32\DRIVERS\RtTeam60.sys –> C:\Windows\system32\DRIVERS\RtTeam60.sys [?] S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\system32\DRIVERS\teamviewervpn.sys –> C:\Windows\system32\DRIVERS\teamviewervpn.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] . =============== File Associations =============== . txtfile="C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1" . =============== Created Last 30 ================ . 2011-11-23 16:03:07 ——– d—–w- C:\Users\Filip\AppData\Local\{6BC45846-2F67-4C15-BDD1-C5D2A2FBC217} 2011-11-23 16:01:55 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\offreg.dll 2011-11-23 16:01:53 8570192 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\mpengine.dll 2011-11-22 20:00:23 ——– d—–w- C:\Program Files (x86)\Algodoo 2011-11-22 16:17:21 ——– d—–w- C:\Users\Filip\AppData\Local\{5BBBAA24-90DC-4480-B395-3D9BFB8CA64D} 2011-11-21 11:37:37 ——– d—–w- C:\Users\Filip\AppData\Local\{93B1615B-A5E3-4B30-B9B2-5D4DB12D7A28} 2011-11-21 11:37:20 ——– d—–w- C:\Users\Filip\AppData\Local\{BAFAB55A-00BE-4B8A-84F5-7907B0ECA4E4} 2011-11-20 12:12:00 ——– d—–w- C:\Users\Filip\AppData\Local\{7A24CF98-A65E-49E5-ADF6-B44547BF6966} 2011-11-20 12:11:38 ——– d—–w- C:\Users\Filip\AppData\Local\{17350408-A3DC-4C50-B653-753D232313A6} 2011-11-20 12:06:10 ——– d—–w- C:\Users\Filip\AppData\Local\{6D42D460-61A4-4437-8BAE-BF616E563E38} 2011-11-19 13:18:13 ——– d—–w- C:\Users\Filip\AppData\Roaming\ESET 2011-11-19 13:16:48 ——– d—–w- C:\Program Files\ESET 2011-11-19 09:42:18 ——– d—–w- C:\Users\Filip\AppData\Local\{754C8F4A-1768-4214-9CE0-015947FBB78B} 2011-11-19 09:41:53 ——– d—–w- C:\Users\Filip\AppData\Local\{0EA356A3-4CF1-48A1-8CBF-39CC02C53E52} 2011-11-18 22:41:50 ——– d—–w- C:\Users\Filip\AppData\Roaming\.minecraft 2011-11-18 21:56:13 ——– d—–w- C:\Users\Filip\AppData\Roaming\mctechnick 2011-11-18 17:55:32 ——– d—–w- C:\Users\Filip\AppData\Local\{51A67855-334F-4988-8A54-7FAECA7FDC98} 2011-11-18 17:55:08 ——– d—–w- C:\Users\Filip\AppData\Local\{8E705346-414A-40F1-88BE-B68530E1DB1A} 2011-11-17 22:45:37 ——– d—–w- C:\Users\Filip\AppData\Roaming\com.adobe.DC3Module.AdobeADC 2011-11-17 20:33:13 ——– d—–w- C:\Users\Filip\AppData\Local\{FAC9AAF4-5818-4705-B8F2-F8ACECC002B5} 2011-11-17 20:33:01 ——– d—–w- C:\Users\Filip\AppData\Local\{1E3435A7-79C4-4D93-A3AD-AEF27CE372DC} 2011-11-17 16:10:46 ——– d—–w- C:\Users\Filip\AppData\Local\{CF990AF9-4577-41AB-84F6-270626A0E3E1} 2011-11-16 18:49:37 ——– d—–w- C:\Program Files (x86)\Sol Edit 2011-11-16 16:05:46 ——– d—–w- C:\Users\Filip\AppData\Local\{5C4CBAC7-3F2F-4C53-BBA0-7E1382060F78} 2011-11-16 16:05:27 ——– d—–w- C:\Users\Filip\AppData\Local\{DAE489E5-3501-40D8-88A5-257297D5757B} 2011-11-15 21:17:23 ——– d—–w- C:\Users\Filip\AppData\Local\{C0A35800-646A-447B-98A2-792B0946E6CC} 2011-11-15 21:17:11 ——– d—–w- C:\Users\Filip\AppData\Local\{18E86E3F-F2F2-4A16-A642-B9DB76A4C4E2} 2011-11-15 18:35:27 ——– d—–w- C:\ProgramData\ALM 2011-11-14 21:18:55 ——– d—–w- C:\Users\Filip\AppData\Roaming\Blender Foundation 2011-11-14 21:09:52 ——– d—–w- C:\Users\Filip\AppData\Roaming\inkscape 2011-11-14 20:59:48 ——– d—–w- C:\Users\Filip\.thumbnails 2011-11-14 20:59:35 ——– d—–w- C:\Program Files\Blender Foundation 2011-11-14 19:33:25 ——– d—–w- C:\Users\Filip\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2011-11-14 18:38:56 32256 —-a-w- C:\ProgramData\l9gfqw6lai.exe 2011-11-13 21:44:58 235 —-a-w- C:\Windows\SysWow64\nxEuUninstall.bat 2011-11-13 21:44:53 446464 —-a-w- C:\Windows\NEXON_EU_DownloaderUpdater.exe 2011-11-13 21:24:38 1700352 —-a-w- C:\Windows\SysWow64\gdiplus.dll 2011-11-13 21:02:08 ——– d—–w- C:\Nexon 2011-11-13 13:06:29 ——– d—–w- C:\Users\Filip\AppData\Roaming\Spam Monitor 2011-11-13 13:06:29 ——– d—–w- C:\Users\Filip\AppData\Roaming\PCToolsFirewallPlus 2011-11-13 12:57:40 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools 2011-11-13 12:39:06 ——– d—–w- C:\Users\Filip\AppData\Roaming\pymclevel 2011-11-13 12:38:37 ——– d—–w- C:\Users\Filip\AppData\Local\MCEdit-64bit 2011-11-13 12:33:19 ——– d—–w- C:\ProgramData\PC Tools 2011-11-13 10:18:45 ——– d—–w- C:\Users\Filip\AppData\Local\{B5EE657B-F0BD-42FE-A8DA-35125B472AE8} 2011-11-13 10:18:30 ——– d—–w- C:\Users\Filip\AppData\Local\{449B85E7-D03A-4EB9-9F04-79FE4D84C1B0} 2011-11-12 17:37:43 ——– d—–w- C:\Users\Filip\AppData\Local\{310251F6-4F2F-4954-AF79-C65579238B1A} 2011-11-12 17:37:24 ——– d—–w- C:\Users\Filip\AppData\Local\{2227EF0A-927F-487C-9320-EE263E5C3122} 2011-11-12 13:03:21 ——– d—–w- C:\Users\Filip\AppData\Local\{891C11B5-3B35-48B6-A551-0F9651572B8F} 2011-11-11 22:30:43 ——– d—–w- C:\Users\Filip\AppData\Local\Skyrim 2011-11-11 19:45:23 21992 —-a-w- C:\Windows\System32\drivers\cpuz135_x64.sys 2011-11-11 19:45:23 ——– d—–w- C:\Program Files\CPUID 2011-11-11 19:27:10 ——– d—–w- C:\ProgramData\Comodo Downloader 2011-11-11 16:27:45 ——– d—–we C:\Windows\system64 2011-11-11 16:23:43 ——– d—–w- C:\Users\Filip\AppData\Local\{706470F3-146E-4A5D-96E8-870585A8B18F} 2011-11-11 16:23:32 ——– d—–w- C:\Users\Filip\AppData\Local\{C5CA3EEB-5573-470F-962B-B703B3F39A72} 2011-11-10 18:40:16 ——– d—–w- C:\Users\Filip\AppData\Local\GForce 2011-11-10 18:40:12 ——– d—–w- C:\Program Files (x86)\ASIO4ALL v2 2011-11-10 18:39:11 ——– d—–w- C:\Program Files (x86)\VstPlugins 2011-11-10 18:39:08 ——– d—–w- C:\Program Files (x86)\GForce 2011-11-10 16:25:13 ——– d—–w- C:\Users\Filip\AppData\Local\{528B5662-1B42-40DE-A826-127DA9D55516} 2011-11-10 16:25:02 ——– d—–w- C:\Users\Filip\AppData\Local\{AF5194A8-B56B-480E-BF0D-BE37F9EC0632} 2011-11-09 17:41:59 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll 2011-11-09 17:41:59 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll 2011-11-09 17:41:56 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-11-09 17:41:52 3144704 —-a-w- C:\Windows\System32\win32k.sys 2011-11-09 15:46:24 ——– d—–w- C:\Users\Filip\AppData\Local\{95575238-7D0A-47A5-AD6D-096B1C6C4046} 2011-11-09 15:46:11 ——– d—–w- C:\Users\Filip\AppData\Local\{639CC487-6A09-4958-8591-CCA7D3298004} 2011-11-08 17:35:57 ——– d—–w- C:\Users\Filip\AppData\Local\{8B64D692-7869-4B14-AB6D-4A15BF51DF1D} 2011-11-08 17:35:43 ——– d—–w- C:\Users\Filip\AppData\Local\{A4BADC77-D106-4CC7-A2F9-7F0A084F871B} 2011-11-07 19:50:49 ——– d—–w- C:\Program Files (x86)\Yontoo Layers Runtime 2011-11-07 19:50:04 ——– d—–w- C:\Downloads 2011-11-07 19:40:30 ——– d—–w- C:\Users\Filip\AppData\Roaming\Free Download Manager 2011-11-07 16:22:43 ——– d—–w- C:\Users\Filip\AppData\Local\{3DCBC98D-27E5-4B8D-A611-B35BE9430A9D} 2011-11-07 16:22:32 ——– d—–w- C:\Users\Filip\AppData\Local\{D40E7156-DFAF-4089-A1AD-A74C206DC980} 2011-11-06 19:13:12 3074368 —-a-w- C:\Windows\System32\nvsvcr.dll 2011-11-05 20:55:59 529424 —-a-w- C:\Windows\System32\d3dx10_37.dll 2011-11-05 16:16:15 ——– d—–w- C:\Users\Filip\AppData\Roaming\Polynomial 2011-11-05 16:16:06 ——– d—–w- C:\Program Files (x86)\The Polynomial 2011-11-05 13:36:25 ——– d—–w- C:\data 2011-11-05 10:40:46 ——– d—–w- C:\Users\Filip\AppData\Local\{6C5390A8-344E-4E2A-B7C7-AC06A3AB689F} 2011-11-05 10:40:33 ——– d—–w- C:\Users\Filip\AppData\Local\{A2388B35-93A8-4701-A6F5-9A1C4B83A05B} 2011-11-04 20:18:44 ——– d—–w- C:\Users\Filip\AppData\Roaming\AtomZombieData 2011-11-04 20:11:53 ——– d—–w- C:\Users\Filip\AppData\Roaming\Voxatron 2011-11-04 18:21:14 ——– d—–w- C:\Users\Filip\AppData\Local\{A30D4DB5-D91E-4F5A-B511-12AF3135EBC6} 2011-11-04 18:21:03 ——– d—–w- C:\Users\Filip\AppData\Local\{8A0A44CF-9CBD-43D4-A7E2-E89399B60E4F} 2011-11-03 18:48:24 ——– d—–w- C:\Users\Filip\AppData\Local\Apple Computer 2011-11-03 18:40:39 ——– d—–w- C:\Program Files (x86)\Combined Community Codec Pack 2011-11-03 18:20:18 ——– d—–w- C:\Program Files\Media Player Classic - Home Cinema 2011-11-03 17:31:18 ——– d—–w- C:\Users\Filip\AppData\Local\{2FBDCE59-96F8-4B3D-BD95-B63221E308D0} 2011-11-03 17:31:05 ——– d—–w- C:\Users\Filip\AppData\Local\{6C1F5BBB-05C8-4F73-A254-2F7E45931266} 2011-11-03 08:11:07 ——– d—–w- C:\Users\Filip\AppData\Local\{65C9E9D2-262C-4EE2-B508-9823D3B12F4E} 2011-11-02 17:56:03 ——– d—–w- C:\Users\Filip\AppData\Local\Nero_AG 2011-11-02 17:55:28 ——– d—–w- C:\Users\Filip\AppData\Local\Nero 2011-11-02 17:54:19 ——– d—–w- C:\Users\Filip\AppData\Local\{473ECC4E-454E-41F5-8B6B-05A5E88D32FD} 2011-11-02 17:54:08 ——– d—–w- C:\Users\Filip\AppData\Local\{2C438F03-51E5-4AB5-B8F0-02400A9E134D} 2011-11-01 17:09:46 ——– d—–w- C:\Users\Filip\AppData\Local\{D47D465E-6BB0-4322-BE5D-8055AFFBC669} 2011-11-01 17:09:28 ——– d—–w- C:\Users\Filip\AppData\Local\{007A31D0-E416-42BD-B6AD-FFC9E101DF2F} 2011-10-31 18:06:52 ——– d—–w- C:\Users\Filip\AppData\Local\{106CC801-F100-43FA-A1D3-9C88F8462D06} 2011-10-31 18:06:29 ——– d—–w- C:\Users\Filip\AppData\Local\{284BB6A4-2BF1-4840-AD9B-B024BB34FF58} 2011-10-30 09:14:27 ——– d—–w- C:\Users\Filip\AppData\Local\{49828ABD-0040-49AE-9229-E5546FFE1E33} 2011-10-30 09:14:02 ——– d—–w- C:\Users\Filip\AppData\Local\{4C981980-300D-4C97-8F76-C4BF52901C14} 2011-10-29 17:35:56 ——– d—–w- C:\Users\Filip\AppData\Local\{73DF0A1B-FEBC-40B6-8254-763A32AC06A5} 2011-10-29 17:35:35 ——– d—–w- C:\Users\Filip\AppData\Local\{3A2FDC50-6705-4E61-BF4B-9A4629DF56DA} 2011-10-29 09:47:00 ——– d—–w- C:\Users\Filip\AppData\Local\APN 2011-10-29 09:46:44 ——– d—–w- C:\Users\Filip\AppData\Roaming\ManyCam 2011-10-29 09:46:36 ——– d—–w- C:\ProgramData\Ask 2011-10-29 09:36:52 ——– d—–w- C:\Users\Filip\AppData\Local\{276925AF-CF6F-4F49-AAD3-6637D70FA15E} 2011-10-28 17:33:34 810496 —-a-w- C:\Windows\System32\xvidcore.dll 2011-10-28 17:33:34 80896 —-a-w- C:\Windows\System32\ff_vfw.dll 2011-10-28 17:33:34 183808 —-a-w- C:\Windows\System32\xvidvfw.dll 2011-10-28 17:33:00 389120 —-a-w- C:\Windows\SysWow64\actskn43.ocx 2011-10-28 17:33:00 389120 —-a-w- C:\Windows\System32\actskn43.ocx 2011-10-28 10:28:10 ——– d—–w- C:\Users\Filip\AppData\Local\{864C829F-D53A-4B18-83E0-99B752BD7993} 2011-10-28 10:27:58 ——– d—–w- C:\Users\Filip\AppData\Local\{2351F912-0E2A-4175-99DA-87B0AB8A0671} 2011-10-27 08:59:16 ——– d—–w- C:\Users\Filip\AppData\Local\{7BCEF7FF-0A87-4A05-AA91-597DEC255EC6} 2011-10-27 08:58:51 ——– d—–w- C:\Users\Filip\AppData\Local\{EA6EE90D-F77D-4896-BC8C-48F3B149E1C9} 2011-10-26 12:36:20 6144 —-a-w- C:\Program Files\Internet Explorer\iecompat.dll 2011-10-26 12:36:20 6144 —-a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll 2011-10-26 12:26:36 ——– d—–w- C:\Users\Filip\AppData\Local\{6C2BE5E5-01B8-4D6E-85B6-12164301E01E} 2011-10-26 12:26:22 ——– d—–w- C:\Users\Filip\AppData\Local\{F43BD921-F76E-487B-9E77-8CDC92C93491} 2011-10-25 09:27:25 ——– d—–w- C:\Users\Filip\AppData\Local\{853493E7-6E58-4E16-82D7-73BCEA87972F} 2011-10-25 09:27:04 ——– d—–w- C:\Users\Filip\AppData\Local\{35050DF5-5C72-4FF5-B22D-457BA09F8839} . ==================== Find3M ==================== . 2011-11-14 18:06:57 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-11 19:50:11 6656 —-a-w- C:\Windows\System32\lpcio.dll 2011-11-09 18:25:38 850152 —-a-w- C:\Windows\SysWow64\SpoonUninstall.exe 2011-11-05 12:59:55 466456 —-a-w- C:\Windows\System32\wrap_oal.dll 2011-11-05 12:59:55 444952 —-a-w- C:\Windows\SysWow64\wrap_oal.dll 2011-11-05 12:59:55 122904 —-a-w- C:\Windows\System32\OpenAL32.dll 2011-11-05 12:59:55 109080 —-a-w- C:\Windows\SysWow64\OpenAL32.dll 2011-10-15 00:54:52 321856 —-a-w- C:\Windows\SysWow64\nvStreaming.exe 2011-10-05 17:43:38 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr 2011-10-05 17:43:38 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe 2011-10-04 20:29:42 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.ex0 2011-10-04 16:38:17 75136 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe 2011-10-03 05:06:03 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-10-02 11:58:11 18960 —-a-w- C:\Windows\System32\drivers\LNonPnP.sys 2011-10-01 03:25:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2011-10-01 02:42:56 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-08-31 17:00:50 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-08-27 05:37:49 861696 —-a-w- C:\Windows\System32\oleaut32.dll 2011-08-27 05:37:48 331776 —-a-w- C:\Windows\System32\oleacc.dll 2011-08-27 04:26:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-27 04:26:27 233472 —-a-w- C:\Windows\SysWow64\oleacc.dll . ============= FINISH: 20:47:14.40 =============== Attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 24/04/2011 15:55:58 System Uptime: 23/11/2011 15:58:10 (5 hours ago) . Motherboard: ASUSTeK Computer INC. | | P5G41TD-M PRO Processor: Intel® Core™2 Duo CPU E8400 @ 3.00GHz | LGA775 | 3003/333mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 186 GiB total, 58.885 GiB free. D: is FIXED (NTFS) - 373 GiB total, 11.06 GiB free. E: is CDROM () F: is Removable H: is Removable I: is Removable J: is Removable K: is FIXED (HFSJ) - 233 GiB total, 156.503 GiB free. L: is FIXED (NTFS) - 140 GiB total, 19.192 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VMware Virtual Ethernet Adapter for VMnet1 Device ID: ROOT\VMWARE\0000 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet1 PNP Device ID: ROOT\VMWARE\0000 Service: VMnetAdapter . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VMware Virtual Ethernet Adapter for VMnet8 Device ID: ROOT\VMWARE\0001 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet8 PNP Device ID: ROOT\VMWARE\0001 Service: VMnetAdapter . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: TeamViewer VPN Adapter Device ID: ROOT\NET\0001 Manufacturer: TeamViewer GmbH Name: TeamViewer VPN Adapter PNP Device ID: ROOT\NET\0001 Service: teamviewervpn . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VirtualBox Host-Only Ethernet Adapter Device ID: ROOT\NET\0002 Manufacturer: Oracle Corporation Name: VirtualBox Host-Only Ethernet Adapter PNP Device ID: ROOT\NET\0002 Service: VBoxNetAdp . Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: Windows Firewall Authorization Driver Device ID: ROOT\LEGACY_MPSDRV\0000 Manufacturer: Name: Windows Firewall Authorization Driver PNP Device ID: ROOT\LEGACY_MPSDRV\0000 Service: mpsdrv . ==== System Restore Points =================== . RP254: 23/11/2011 16:01:35 - Windows Update . ==== Installed Programs ====================== . .sol Editor 1.1.0.1 Adobe AIR Adobe Community Help Adobe Flash Player 10 ActiveX Adobe Illustrator CS5.1 Adobe Photoshop CS5.1 Adobe Reader X (10.1.1) Adobe Shockwave Player 11.6 Aerosoft's - Aerosoft Launcher Algodoo v2.0.0 Apple Application Support Apple Software Update ASIO4ALL Assassin's Creed Brotherhood ASUSUpdate Audacity 1.3.13 (Unicode) Audiograbber 1.83 SE Audiograbber MP3 Plugin AutoHotkey 1.1.04.01 Bandisoft MPEG-1 Decoder Bastion Call of Juarez - Bound in Blood Cheat Engine 6.0 Combined Community Codec Pack 2011-07-30 CraftBukkit Crysis® 2 D3DX10 dBpoweramp [Calculate Audio CRC] Codec dBpoweramp [ID Tag Update] Codec dBpoweramp Dalet Codec dBpoweramp DSP Effects dBpoweramp FLAC Codec dBpoweramp m4a Codec dBpoweramp Monkeys Audio Codec dBpoweramp Mp2 and BwfMp2 codec dBpoweramp mp3 (Fraunhofer IIS) Codec dBpoweramp Music Converter dBpoweramp Ogg Vorbis Codec dBpoweramp Real Audio (Helix) Encoder dBPoweramp tooLame MP2 codec dBpoweramp Wave64 Codec dBpoweramp WavPack Codec Dead Rising 2: OTR Deus Ex Deus Ex - Human Revolution version 1.0 Dev-C++ 5 beta 9 release (4.9.9.2) Diagnostic Utility Drift City Driver San Francisco Driver San Francisco version 1.0 Dropbox Dungeon Defenders EasyBCD 2.0 EPU-4 Engine eReg Express Gate Fable III Flight Simulator X Flight Simulator X Service Pack 1 FOTONICA version 1.2 Freespace 2 Freespace with Silent Threat Expansion From Dust Gadu-Gadu 10 Garry's Mod gedit 2.30.1 Google Chrome Grand Theft Auto IV HandBrake 0.9.5 Hard Reset High-Definition Video Playback IrfanView (remove only) Java Auto Updater Java™ 6 Update 29 JDownloader 0.9 LAME v3.98.3 for Audacity League of Legends Left 4 Dead 2 LogMeIn Hamachi Magic The Gathering - Duels of the Planeswalkers 2012 Malwarebytes' Anti-Malware version 1.51.2.1300 ManiaPlanet Microsoft .NET Framework 1.1 Microsoft .NET Framework 4 Multi-Targeting Pack Microsoft Application Error Reporting Microsoft Flight Simulator X Microsoft Flight Simulator X Service Pack 1 Microsoft Flight Simulator X: Acceleration Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft Silverlight Microsoft SQL Server Compact 3.5 SP2 ENU Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft XNA Framework Redistributable 3.1 Microsoft XNA Framework Redistributable 4.0 Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFCLOC_x86 Might and Magic: Clash of Heroes Miners4k Mozilla Firefox 5.0 (x86 en-GB) Mp3tag v2.49 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK Nero 10 Menu TemplatePack Basic Nero 10 Movie ThemePack Basic Nero BackItUp 10 Nero Burning ROM 10 Nero BurnRights 10 Nero Control Center 10 Nero Core Components 10 Nero CoverDesigner 10 Nero DiscSpeed 10 Nero Dolby Files 10 Nero Express 10 Nero InfoTool 10 Nero Kwik Media Nero Multimedia Suite 10 Nero Recode 10 Nero RescueAgent 10 Nero SoundTrax 10 Nero StartSmart 10 Nero Update Nero Vision 10 Nero WaveEditor 10 NVIDIA PhysX NVIDIA Stereoscopic 3D Driver Oblivion Oblivion - Horse Armor Pack Oblivion - Knights of the Nine Oblivion - Mehrunes Razor Oblivion - Orrery Oblivion - Spell Tomes Oblivion - Thieves Den Oblivion - Vile Lair Oblivion - Wizard's Tower Octoshape add-in for Adobe Flash Player OnLive OpenAL Pando Media Booster PC Probe II PDF Settings CS5 PowerISO PSPad editor PunkBuster Services QuickTime Realtek High Definition Audio Driver Rock of Ages SanDiskSecureAccess_Manager.exe Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Sentinel System Driver Skype Toolbars Skype™ 5.5 Sony Ericsson PC Companion 2.01.192 Sony Ericsson Update Engine Sony Ericsson Update Service Spotify Steam Steam Engine Simulator Stronghold 3 System Requirements Lab CYRI System Requirements Lab for Intel Tag - IGF Professional 2008 Team Fortress 2 TeamViewer 6 Terraria TES Construction Set TmUnitedForever TomTom HOME 2.8.1.2218 TomTom HOME Visual Studio Merge Modules tools-freebsd tools-linux tools-netware tools-solaris tools-windows tools-winPre2k TrackMania Nations Forever Turbo Key Twierdza Krzy¿owiec (Warchest) Twierdza Warchest Ubisoft Game Launcher Unity Web Player Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) VMware Workstation Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Messenger Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Media Player Firefox Plugin WinX DVD Ripper Platinum 6.5.0 . ==== Event Viewer Messages From Past Week ======== . 23/11/2011 18:09:08, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file. 23/11/2011 16:02:46, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143. 23/11/2011 15:58:58, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: TfFsMon TFSysMon 23/11/2011 15:58:39, Error: Service Control Manager [7001] - The Windows Firewall service depends on the Windows Firewall Authorization Driver service which failed to start because of the following error: Cannot create a file when that file already exists. 23/11/2011 15:58:39, Error: Service Control Manager [7000] - The Windows Firewall Authorization Driver service failed to start due to the following error: Cannot create a file when that file already exists. 23/11/2011 15:58:39, Error: Service Control Manager [7000] - The Sentinel service failed to start due to the following error: This driver has been blocked from loading 23/11/2011 15:58:39, Error: Application Popup [1060] - \SystemRoot\SysWow64\Drivers\SENTINEL.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. 22/11/2011 17:42:14, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 22/11/2011 16:13:49, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004 21/11/2011 11:36:50, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the VMware Workstation Server service to connect. 21/11/2011 11:36:50, Error: Service Control Manager [7000] - The VMware Workstation Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 19/11/2011 13:29:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F} 19/11/2011 13:29:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 19/11/2011 13:28:52, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 19/11/2011 13:28:51, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. 19/11/2011 13:28:51, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 19/11/2011 13:28:48, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 19/11/2011 13:28:37, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 19/11/2011 13:28:31, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AsIO AsUpIO CBDisk discache ehdrv MDFSYSNT SCDEmu spldr TfFsMon TFSysMon VBoxDrv VBoxUSBMon vmm Wanarpv6 19/11/2011 13:02:51, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000024 (0x00000000001904fb, 0xfffff88007f3a1d0, 0xfffff88007f3a270, 0xfffff8000210f590). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 111911-15397-01. . ==== End Of File ===========================
Hi,

1. Download TDSSKiller and extract its contents into a folder in desired location (i.e. c:\tdsskiller).
2. Execute the file TDSSKiller.exe.
3. Click Start Scan. If threats are found, select skip and click Continue (tool may prompt for a reboot).
4. Post back contents of log file in c: drive root (name should be in UtilityName.Version_Date_Time_log.txt format)
I did forget to add that I did scan with TDSSkiller before and it did not detect anything, here's the new log 17:30:11.0232 6640 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44 17:30:11.0982 6640 ============================================================ 17:30:11.0982 6640 Current date / time: 2011/11/24 17:30:11.0982 17:30:11.0982 6640 SystemInfo: 17:30:11.0982 6640 17:30:11.0982 6640 OS Version: 6.1.7601 ServicePack: 1.0 17:30:11.0982 6640 Product type: Workstation 17:30:11.0982 6640 ComputerName: FILIP-PC 17:30:11.0982 6640 UserName: Filip 17:30:11.0982 6640 Windows directory: C:\Windows 17:30:11.0982 6640 System windows directory: C:\Windows 17:30:11.0982 6640 Running under WOW64 17:30:11.0982 6640 Processor architecture: Intel x64 17:30:11.0982 6640 Number of processors: 2 17:30:11.0982 6640 Page size: 0x1000 17:30:11.0982 6640 Boot type: Normal boot 17:30:11.0982 6640 ============================================================ 17:30:13.0691 6640 Initialize success 17:30:24.0832 7064 ============================================================ 17:30:24.0832 7064 Scan started 17:30:24.0832 7064 Mode: Manual; 17:30:24.0832 7064 ============================================================ 17:30:26.0926 7064 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 17:30:26.0929 7064 1394ohci - ok 17:30:26.0985 7064 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 17:30:26.0988 7064 ACPI - ok 17:30:27.0024 7064 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 17:30:27.0025 7064 AcpiPmi - ok 17:30:27.0151 7064 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 17:30:27.0156 7064 adp94xx - ok 17:30:27.0211 7064 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 17:30:27.0215 7064 adpahci - ok 17:30:27.0237 7064 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 17:30:27.0240 7064 adpu320 - ok 17:30:27.0312 7064 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys 17:30:27.0317 7064 AFD - ok 17:30:27.0355 7064 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 17:30:27.0356 7064 agp440 - ok 17:30:27.0385 7064 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 17:30:27.0385 7064 aliide - ok 17:30:27.0408 7064 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 17:30:27.0409 7064 amdide - ok 17:30:27.0430 7064 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 17:30:27.0432 7064 AmdK8 - ok 17:30:27.0441 7064 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 17:30:27.0443 7064 AmdPPM - ok 17:30:27.0476 7064 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 17:30:27.0478 7064 amdsata - ok 17:30:27.0500 7064 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 17:30:27.0503 7064 amdsbs - ok 17:30:27.0525 7064 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 17:30:27.0526 7064 amdxata - ok 17:30:27.0623 7064 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 17:30:27.0625 7064 AppID - ok 17:30:27.0666 7064 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 17:30:27.0668 7064 arc - ok 17:30:27.0681 7064 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 17:30:27.0683 7064 arcsas - ok 17:30:27.0700 7064 AsIO - ok 17:30:27.0748 7064 AsUpIO - ok 17:30:27.0766 7064 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 17:30:27.0767 7064 AsyncMac - ok 17:30:27.0806 7064 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 17:30:27.0807 7064 atapi - ok 17:30:27.0863 7064 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 17:30:27.0868 7064 b06bdrv - ok 17:30:27.0885 7064 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 17:30:27.0889 7064 b57nd60a - ok 17:30:27.0917 7064 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 17:30:27.0917 7064 Beep - ok 17:30:27.0983 7064 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 17:30:27.0984 7064 blbdrive - ok 17:30:28.0023 7064 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 17:30:28.0024 7064 bowser - ok 17:30:28.0031 7064 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 17:30:28.0033 7064 BrFiltLo - ok 17:30:28.0042 7064 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 17:30:28.0043 7064 BrFiltUp - ok 17:30:28.0055 7064 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 17:30:28.0059 7064 Brserid - ok 17:30:28.0066 7064 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 17:30:28.0067 7064 BrSerWdm - ok 17:30:28.0079 7064 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 17:30:28.0080 7064 BrUsbMdm - ok 17:30:28.0087 7064 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 17:30:28.0088 7064 BrUsbSer - ok 17:30:28.0097 7064 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 17:30:28.0099 7064 BTHMODEM - ok 17:30:28.0129 7064 CBDisk (b99d91e4cd9017f213645aa2e80eb425) C:\Windows\system32\drivers\CBDisk.sys 17:30:28.0130 7064 CBDisk - ok 17:30:28.0148 7064 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 17:30:28.0149 7064 cdfs - ok 17:30:28.0189 7064 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys 17:30:28.0191 7064 cdrom - ok 17:30:28.0202 7064 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 17:30:28.0203 7064 circlass - ok 17:30:28.0240 7064 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 17:30:28.0245 7064 CLFS - ok 17:30:28.0260 7064 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 17:30:28.0261 7064 CmBatt - ok 17:30:28.0278 7064 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 17:30:28.0279 7064 cmdide - ok 17:30:28.0323 7064 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys 17:30:28.0329 7064 CNG - ok 17:30:28.0370 7064 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 17:30:28.0370 7064 Compbatt - ok 17:30:28.0412 7064 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys 17:30:28.0413 7064 CompositeBus - ok 17:30:28.0473 7064 cpuz135 (76355d5eafdfa3e9b7580b9153de1f30) C:\Windows\system32\drivers\cpuz135_x64.sys 17:30:28.0474 7064 cpuz135 - ok 17:30:28.0488 7064 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 17:30:28.0489 7064 crcdisk - ok 17:30:28.0570 7064 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys 17:30:28.0576 7064 CSC - ok 17:30:28.0640 7064 dc3d (15c2afd86d8a58354fc100434c78b621) C:\Windows\system32\DRIVERS\dc3d.sys 17:30:28.0641 7064 dc3d - ok 17:30:28.0685 7064 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 17:30:28.0687 7064 DfsC - ok 17:30:28.0709 7064 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 17:30:28.0709 7064 discache - ok 17:30:28.0756 7064 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 17:30:28.0757 7064 Disk - ok 17:30:28.0833 7064 DKRtWrt (20c394c80113d77406df8f1adc720b01) C:\Windows\system32\DRIVERS\DKRtWrt.sys 17:30:28.0834 7064 DKRtWrt - ok 17:30:28.0882 7064 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 17:30:28.0882 7064 drmkaud - ok 17:30:28.0897 7064 dump_wmimmc - ok 17:30:28.0946 7064 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 17:30:28.0952 7064 DXGKrnl - ok 17:30:28.0990 7064 E1G60 (edc6e9c057c9d7f83eea22b4cef5dcad) C:\Windows\system32\DRIVERS\E1G6032E.sys 17:30:28.0992 7064 E1G60 - ok 17:30:29.0013 7064 EagleX64 - ok 17:30:29.0042 7064 eamon (55851f4864f8ad6e98b02307eca29db4) C:\Windows\system32\DRIVERS\eamon.sys 17:30:29.0043 7064 eamon - ok 17:30:29.0112 7064 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 17:30:29.0170 7064 ebdrv - ok 17:30:29.0244 7064 ehdrv (62c96b617ac7c4c8a9c29d57a36aa874) C:\Windows\system32\DRIVERS\ehdrv.sys 17:30:29.0245 7064 ehdrv - ok 17:30:29.0333 7064 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 17:30:29.0339 7064 elxstor - ok 17:30:29.0393 7064 epfw (9c4476159ccdef1a9b3f91dc580f1c46) C:\Windows\system32\DRIVERS\epfw.sys 17:30:29.0394 7064 epfw - ok 17:30:29.0421 7064 Epfwndis (34f666bf6387210034e4bcc5be6a3e45) C:\Windows\system32\DRIVERS\Epfwndis.sys 17:30:29.0421 7064 Epfwndis - ok 17:30:29.0455 7064 epfwwfp (bf2cb1efb98a888d6f676683cd48936f) C:\Windows\system32\DRIVERS\epfwwfp.sys 17:30:29.0456 7064 epfwwfp - ok 17:30:29.0491 7064 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 17:30:29.0492 7064 ErrDev - ok 17:30:29.0537 7064 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 17:30:29.0539 7064 exfat - ok 17:30:29.0557 7064 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 17:30:29.0560 7064 fastfat - ok 17:30:29.0591 7064 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 17:30:29.0592 7064 fdc - ok 17:30:29.0611 7064 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 17:30:29.0612 7064 FileInfo - ok 17:30:29.0632 7064 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 17:30:29.0633 7064 Filetrace - ok 17:30:29.0641 7064 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 17:30:29.0642 7064 flpydisk - ok 17:30:29.0697 7064 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 17:30:29.0700 7064 FltMgr - ok 17:30:29.0717 7064 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 17:30:29.0718 7064 FsDepends - ok 17:30:29.0731 7064 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 17:30:29.0731 7064 Fs_Rec - ok 17:30:29.0794 7064 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 17:30:29.0796 7064 fvevol - ok 17:30:29.0820 7064 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 17:30:29.0821 7064 gagp30kx - ok 17:30:29.0887 7064 ggflt (a4198f2bd8aa592cb90476277a81b5e1) C:\Windows\system32\DRIVERS\ggflt.sys 17:30:29.0888 7064 ggflt - ok 17:30:29.0923 7064 ggsemc (d266350bdaab9eb6c1aec370eeaaff3a) C:\Windows\system32\DRIVERS\ggsemc.sys 17:30:29.0924 7064 ggsemc - ok 17:30:29.0968 7064 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys 17:30:29.0968 7064 hamachi - ok 17:30:30.0031 7064 hcmon (5bf776abedea06b0779c82e9d54b58d7) C:\Windows\system32\drivers\hcmon.sys 17:30:30.0031 7064 hcmon - ok 17:30:30.0048 7064 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 17:30:30.0049 7064 hcw85cir - ok 17:30:30.0111 7064 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 17:30:30.0115 7064 HdAudAddService - ok 17:30:30.0159 7064 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys 17:30:30.0176 7064 HDAudBus - ok 17:30:30.0195 7064 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 17:30:30.0196 7064 HidBatt - ok 17:30:30.0210 7064 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 17:30:30.0212 7064 HidBth - ok 17:30:30.0225 7064 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 17:30:30.0226 7064 HidIr - ok 17:30:30.0245 7064 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys 17:30:30.0246 7064 HidUsb - ok 17:30:30.0285 7064 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 17:30:30.0287 7064 HpSAMD - ok 17:30:30.0351 7064 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 17:30:30.0359 7064 HTTP - ok 17:30:30.0398 7064 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 17:30:30.0398 7064 hwpolicy - ok 17:30:30.0437 7064 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 17:30:30.0438 7064 i8042prt - ok 17:30:30.0463 7064 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 17:30:30.0468 7064 iaStorV - ok 17:30:30.0516 7064 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 17:30:30.0517 7064 iirsp - ok 17:30:30.0613 7064 IntcAzAudAddService (f04d22d7a49a1b2210dbadf0b803e870) C:\Windows\system32\drivers\RTKVHD64.sys 17:30:30.0625 7064 IntcAzAudAddService - ok 17:30:30.0646 7064 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 17:30:30.0646 7064 intelide - ok 17:30:30.0667 7064 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 17:30:30.0668 7064 intelppm - ok 17:30:30.0720 7064 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:30:30.0722 7064 IpFilterDriver - ok 17:30:30.0755 7064 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 17:30:30.0757 7064 IPMIDRV - ok 17:30:30.0779 7064 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 17:30:30.0781 7064 IPNAT - ok 17:30:30.0829 7064 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 17:30:30.0830 7064 IRENUM - ok 17:30:30.0862 7064 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 17:30:30.0863 7064 isapnp - ok 17:30:30.0892 7064 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 17:30:30.0895 7064 iScsiPrt - ok 17:30:30.0933 7064 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 17:30:30.0933 7064 kbdclass - ok 17:30:30.0969 7064 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys 17:30:30.0970 7064 kbdhid - ok 17:30:31.0012 7064 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys 17:30:31.0013 7064 KSecDD - ok 17:30:31.0050 7064 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys 17:30:31.0052 7064 KSecPkg - ok 17:30:31.0070 7064 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 17:30:31.0071 7064 ksthunk - ok 17:30:31.0171 7064 LHidFilt (1074c77a47835e03c15bf92452f9a750) C:\Windows\system32\DRIVERS\LHidFilt.Sys 17:30:31.0172 7064 LHidFilt - ok 17:30:31.0223 7064 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 17:30:31.0225 7064 lltdio - ok 17:30:31.0268 7064 LMouFilt (96999c364c649e2866a268f7420a304a) C:\Windows\system32\DRIVERS\LMouFilt.Sys 17:30:31.0269 7064 LMouFilt - ok 17:30:31.0304 7064 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 17:30:31.0306 7064 LSI_FC - ok 17:30:31.0324 7064 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 17:30:31.0326 7064 LSI_SAS - ok 17:30:31.0348 7064 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 17:30:31.0350 7064 LSI_SAS2 - ok 17:30:31.0363 7064 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 17:30:31.0365 7064 LSI_SCSI - ok 17:30:31.0411 7064 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 17:30:31.0413 7064 luafv - ok 17:30:31.0492 7064 ManyCam (d33e2b74cf8b3a652bf0a9fbd068e87a) C:\Windows\system32\DRIVERS\ManyCam_x64.sys 17:30:31.0493 7064 ManyCam - ok 17:30:31.0544 7064 MBAMProtector (23a854450dab5c9b7a42ab9be6f2e4bd) C:\Windows\system32\drivers\mbam.sys 17:30:31.0545 7064 MBAMProtector - ok 17:30:31.0616 7064 MDFSYSNT (72040607e6e4115c154d730219bafab3) C:\Windows\system32\drivers\MDFSYSNT.sys 17:30:31.0619 7064 MDFSYSNT - ok 17:30:31.0652 7064 MDPMGRNT (f2ef49c3e47bd3fb6ee71371e7eee0af) C:\Windows\system32\DRIVERS\MDPMGRNT.SYS 17:30:31.0652 7064 MDPMGRNT - ok 17:30:31.0671 7064 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 17:30:31.0672 7064 megasas - ok 17:30:31.0695 7064 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 17:30:31.0699 7064 MegaSR - ok 17:30:31.0743 7064 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 17:30:31.0744 7064 Modem - ok 17:30:31.0775 7064 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 17:30:31.0775 7064 monitor - ok 17:30:32.0123 7064 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 17:30:32.0123 7064 mouclass - ok 17:30:32.0187 7064 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 17:30:32.0187 7064 mouhid - ok 17:30:32.0227 7064 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 17:30:32.0228 7064 mountmgr - ok 17:30:32.0267 7064 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 17:30:32.0269 7064 mpio - ok 17:30:32.0286 7064 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 17:30:32.0287 7064 mpsdrv - ok 17:30:32.0322 7064 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 17:30:32.0324 7064 MRxDAV - ok 17:30:32.0360 7064 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 17:30:32.0362 7064 mrxsmb - ok 17:30:32.0392 7064 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:30:32.0396 7064 mrxsmb10 - ok 17:30:32.0421 7064 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:30:32.0422 7064 mrxsmb20 - ok 17:30:32.0445 7064 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 17:30:32.0446 7064 msahci - ok 17:30:32.0467 7064 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 17:30:32.0469 7064 msdsm - ok 17:30:32.0498 7064 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 17:30:32.0499 7064 Msfs - ok 17:30:32.0518 7064 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 17:30:32.0518 7064 mshidkmdf - ok 17:30:32.0530 7064 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 17:30:32.0531 7064 msisadrv - ok 17:30:32.0570 7064 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 17:30:32.0571 7064 MSKSSRV - ok 17:30:32.0589 7064 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 17:30:32.0590 7064 MSPCLOCK - ok 17:30:32.0600 7064 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 17:30:32.0601 7064 MSPQM - ok 17:30:32.0637 7064 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 17:30:32.0641 7064 MsRPC - ok 17:30:32.0683 7064 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys 17:30:32.0684 7064 mssmbios - ok 17:30:32.0701 7064 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 17:30:32.0702 7064 MSTEE - ok 17:30:32.0710 7064 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 17:30:32.0711 7064 MTConfig - ok 17:30:32.0752 7064 MTsensor (19b006b181e3875fd254f7b67acf1e7c) C:\Windows\system32\DRIVERS\ASACPI.sys 17:30:32.0753 7064 MTsensor - ok 17:30:32.0780 7064 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 17:30:32.0780 7064 Mup - ok 17:30:32.0821 7064 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 17:30:32.0825 7064 NativeWifiP - ok 17:30:32.0892 7064 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 17:30:32.0902 7064 NDIS - ok 17:30:32.0937 7064 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 17:30:32.0938 7064 NdisCap - ok 17:30:32.0975 7064 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 17:30:32.0976 7064 NdisTapi - ok 17:30:33.0024 7064 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 17:30:33.0026 7064 Ndisuio - ok 17:30:33.0066 7064 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 17:30:33.0068 7064 NdisWan - ok 17:30:33.0099 7064 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 17:30:33.0100 7064 NDProxy - ok 17:30:33.0111 7064 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 17:30:33.0112 7064 NetBIOS - ok 17:30:33.0159 7064 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 17:30:33.0162 7064 NetBT - ok 17:30:33.0232 7064 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 17:30:33.0233 7064 nfrd960 - ok 17:30:33.0271 7064 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 17:30:33.0271 7064 Npfs - ok 17:30:33.0294 7064 NPPTNT2 - ok 17:30:33.0305 7064 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 17:30:33.0305 7064 nsiproxy - ok 17:30:33.0373 7064 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 17:30:33.0406 7064 Ntfs - ok 17:30:33.0463 7064 NuidFltr (317020d31f1696334679b9d0416eb62e) C:\Windows\system32\DRIVERS\NuidFltr.sys 17:30:33.0464 7064 NuidFltr - ok 17:30:33.0486 7064 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 17:30:33.0487 7064 Null - ok 17:30:33.0724 7064 nvlddmkm (b15258b1f45f9571758ac6bb2f043b01) C:\Windows\system32\DRIVERS\nvlddmkm.sys 17:30:33.0802 7064 nvlddmkm - ok 17:30:33.0855 7064 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 17:30:33.0858 7064 nvraid - ok 17:30:33.0878 7064 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 17:30:33.0880 7064 nvstor - ok 17:30:33.0942 7064 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 17:30:33.0944 7064 nv_agp - ok 17:30:33.0973 7064 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 17:30:33.0973 7064 ohci1394 - ok 17:30:34.0053 7064 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 17:30:34.0054 7064 Parport - ok 17:30:34.0102 7064 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys 17:30:34.0103 7064 partmgr - ok 17:30:34.0134 7064 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 17:30:34.0136 7064 pci - ok 17:30:34.0162 7064 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 17:30:34.0163 7064 pciide - ok 17:30:34.0191 7064 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 17:30:34.0194 7064 pcmcia - ok 17:30:34.0223 7064 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 17:30:34.0224 7064 pcw - ok 17:30:34.0248 7064 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 17:30:34.0257 7064 PEAUTH - ok 17:30:34.0364 7064 Point64 (33328fa8a580885ab0065be6db266e9f) C:\Windows\system32\DRIVERS\point64.sys 17:30:34.0365 7064 Point64 - ok 17:30:34.0432 7064 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 17:30:34.0434 7064 PptpMiniport - ok 17:30:34.0450 7064 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 17:30:34.0451 7064 Processor - ok 17:30:34.0517 7064 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 17:30:34.0518 7064 Psched - ok 17:30:34.0567 7064 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 17:30:34.0596 7064 ql2300 - ok 17:30:34.0629 7064 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 17:30:34.0631 7064 ql40xx - ok 17:30:34.0654 7064 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 17:30:34.0655 7064 QWAVEdrv - ok 17:30:34.0683 7064 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 17:30:34.0684 7064 RasAcd - ok 17:30:34.0743 7064 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 17:30:34.0744 7064 RasAgileVpn - ok 17:30:34.0774 7064 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 17:30:34.0776 7064 Rasl2tp - ok 17:30:34.0824 7064 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 17:30:34.0825 7064 RasPppoe - ok 17:30:34.0864 7064 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 17:30:34.0865 7064 RasSstp - ok 17:30:34.0906 7064 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 17:30:34.0909 7064 rdbss - ok 17:30:34.0927 7064 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 17:30:34.0927 7064 rdpbus - ok 17:30:34.0939 7064 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 17:30:34.0939 7064 RDPCDD - ok 17:30:34.0983 7064 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys 17:30:34.0986 7064 RDPDR - ok 17:30:35.0014 7064 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 17:30:35.0015 7064 RDPENCDD - ok 17:30:35.0034 7064 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 17:30:35.0035 7064 RDPREFMP - ok 17:30:35.0094 7064 RdpVideoMiniport (70cba1a0c98600a2aa1863479b35cb90) C:\Windows\system32\drivers\rdpvideominiport.sys 17:30:35.0095 7064 RdpVideoMiniport - ok 17:30:35.0120 7064 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys 17:30:35.0123 7064 RDPWD - ok 17:30:35.0148 7064 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 17:30:35.0151 7064 rdyboost - ok 17:30:35.0220 7064 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 17:30:35.0221 7064 rspndr - ok 17:30:35.0271 7064 RTL8167 (4fe1cef69d36e913738234303986fbb3) C:\Windows\system32\DRIVERS\Rt64win7.sys 17:30:35.0274 7064 RTL8167 - ok 17:30:35.0320 7064 RtNdPt60 (5532c4bf15173270757a75b46baeb960) C:\Windows\system32\DRIVERS\RtNdPt60.sys 17:30:35.0321 7064 RtNdPt60 - ok 17:30:35.0378 7064 RTTEAMPT (bc85bdc1c30066c78b8c67af1241d0b7) C:\Windows\system32\DRIVERS\RtTeam60.sys 17:30:35.0379 7064 RTTEAMPT - ok 17:30:35.0401 7064 RTVLANPT (8b6b42d782202363a562f82b0e13b1c0) C:\Windows\system32\DRIVERS\RtVlan60.sys 17:30:35.0402 7064 RTVLANPT - ok 17:30:35.0450 7064 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys 17:30:35.0451 7064 s3cap - ok 17:30:35.0499 7064 SaiK0836 (2b44ff231cac210a32904c310fb476cd) C:\Windows\system32\DRIVERS\SaiK0836.sys 17:30:35.0501 7064 SaiK0836 - ok 17:30:35.0560 7064 SaiMini (9e7e53891d1747a01f491ab25b95135d) C:\Windows\system32\DRIVERS\SaiMini.sys 17:30:35.0560 7064 SaiMini - ok 17:30:35.0596 7064 SaiNtBus (b3b86be19a0caf025f679c39fd21e735) C:\Windows\system32\drivers\SaiBus.sys 17:30:35.0597 7064 SaiNtBus - ok 17:30:35.0648 7064 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 17:30:35.0649 7064 sbp2port - ok 17:30:35.0687 7064 SCDEmu (4dfe7adb4188f01ace51f9aa7c6a2924) C:\Windows\system32\drivers\SCDEmu.sys 17:30:35.0688 7064 SCDEmu - ok 17:30:35.0722 7064 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 17:30:35.0723 7064 scfilter - ok 17:30:35.0767 7064 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 17:30:35.0768 7064 secdrv - ok 17:30:35.0795 7064 Sentinel - ok 17:30:35.0820 7064 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 17:30:35.0821 7064 Serenum - ok 17:30:35.0834 7064 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 17:30:35.0836 7064 Serial - ok 17:30:35.0874 7064 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 17:30:35.0875 7064 sermouse - ok 17:30:35.0923 7064 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 17:30:35.0924 7064 sffdisk - ok 17:30:35.0943 7064 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 17:30:35.0944 7064 sffp_mmc - ok 17:30:35.0959 7064 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 17:30:35.0960 7064 sffp_sd - ok 17:30:35.0980 7064 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 17:30:35.0982 7064 sfloppy - ok 17:30:36.0024 7064 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 17:30:36.0025 7064 SiSRaid2 - ok 17:30:36.0052 7064 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 17:30:36.0053 7064 SiSRaid4 - ok 17:30:36.0068 7064 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 17:30:36.0069 7064 Smb - ok 17:30:36.0128 7064 Sntnlusb - ok 17:30:36.0164 7064 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 17:30:36.0165 7064 spldr - ok 17:30:36.0225 7064 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 17:30:36.0230 7064 srv - ok 17:30:36.0261 7064 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 17:30:36.0265 7064 srv2 - ok 17:30:36.0280 7064 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 17:30:36.0282 7064 srvnet - ok 17:30:36.0402 7064 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 17:30:36.0403 7064 stexstor - ok 17:30:36.0445 7064 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys 17:30:36.0446 7064 storflt - ok 17:30:36.0469 7064 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys 17:30:36.0470 7064 storvsc - ok 17:30:36.0504 7064 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys 17:30:36.0505 7064 swenum - ok 17:30:36.0557 7064 Synth3dVsc - ok 17:30:36.0644 7064 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys 17:30:36.0677 7064 Tcpip - ok 17:30:36.0717 7064 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys 17:30:36.0729 7064 TCPIP6 - ok 17:30:36.0772 7064 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 17:30:36.0773 7064 tcpipreg - ok 17:30:36.0807 7064 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 17:30:36.0808 7064 TDPIPE - ok 17:30:36.0817 7064 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 17:30:36.0818 7064 TDTCP - ok 17:30:36.0855 7064 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 17:30:36.0858 7064 tdx - ok 17:30:36.0889 7064 TEAM (bc85bdc1c30066c78b8c67af1241d0b7) C:\Windows\system32\DRIVERS\RtTeam60.sys 17:30:36.0890 7064 TEAM - ok 17:30:36.0955 7064 teamviewervpn (f5520dbb47c60ee83024b38720abda24) C:\Windows\system32\DRIVERS\teamviewervpn.sys 17:30:36.0956 7064 teamviewervpn - ok 17:30:36.0988 7064 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys 17:30:36.0989 7064 TermDD - ok 17:30:37.0030 7064 TfFsMon - ok 17:30:37.0039 7064 TfNetMon - ok 17:30:37.0061 7064 TFSysMon - ok 17:30:37.0107 7064 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 17:30:37.0107 7064 tssecsrv - ok 17:30:37.0170 7064 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 17:30:37.0593 7064 TsUsbFlt - ok 17:30:37.0613 7064 tsusbhub - ok 17:30:37.0837 7064 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 17:30:37.0839 7064 tunnel - ok 17:30:37.0870 7064 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 17:30:37.0872 7064 uagp35 - ok 17:30:37.0920 7064 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 17:30:37.0924 7064 udfs - ok 17:30:37.0956 7064 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 17:30:37.0958 7064 uliagpkx - ok 17:30:38.0014 7064 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys 17:30:38.0015 7064 umbus - ok 17:30:38.0025 7064 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 17:30:38.0026 7064 UmPass - ok 17:30:38.0091 7064 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys 17:30:38.0092 7064 usbaudio - ok 17:30:38.0105 7064 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys 17:30:38.0105 7064 usbccgp - ok 17:30:38.0157 7064 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 17:30:38.0159 7064 usbcir - ok 17:30:38.0205 7064 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys 17:30:38.0206 7064 usbehci - ok 17:30:38.0222 7064 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 17:30:38.0226 7064 usbhub - ok 17:30:38.0250 7064 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys 17:30:38.0251 7064 usbohci - ok 17:30:38.0287 7064 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 17:30:38.0288 7064 usbprint - ok 17:30:38.0322 7064 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 17:30:38.0323 7064 usbscan - ok 17:30:38.0410 7064 usbser (4acee387fa8fd39f83564fcd2fc234f2) C:\Windows\system32\DRIVERS\usbser.sys 17:30:38.0412 7064 usbser - ok 17:30:38.0439 7064 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:30:38.0440 7064 USBSTOR - ok 17:30:38.0482 7064 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys 17:30:38.0483 7064 usbuhci - ok 17:30:38.0520 7064 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys 17:30:38.0523 7064 usbvideo - ok 17:30:38.0556 7064 V0260VID (49834961fcf5480f41496ce284e2b462) C:\Windows\system32\DRIVERS\V0260Vid.sys 17:30:38.0558 7064 V0260VID - ok 17:30:38.0617 7064 VBoxDrv (f8eb6f3a0a2ddf25be87bb934eaa7e74) C:\Windows\system32\DRIVERS\VBoxDrv.sys 17:30:38.0619 7064 VBoxDrv - ok 17:30:38.0652 7064 VBoxNetAdp (776e07b4248a19decc8642a81bc189cc) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys 17:30:38.0655 7064 VBoxNetAdp - ok 17:30:38.0679 7064 VBoxNetFlt (ffc9f0c1efb3a7f9a9f46d675396c59c) C:\Windows\system32\DRIVERS\VBoxNetFlt.sys 17:30:38.0681 7064 VBoxNetFlt - ok 17:30:38.0734 7064 VBoxUSBMon (b42d50aa0904954758b89d8dec92b034) C:\Windows\system32\DRIVERS\VBoxUSBMon.sys 17:30:38.0735 7064 VBoxUSBMon - ok 17:30:38.0779 7064 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 17:30:38.0780 7064 vdrvroot - ok 17:30:38.0811 7064 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 17:30:38.0813 7064 vga - ok 17:30:38.0835 7064 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 17:30:38.0836 7064 VgaSave - ok 17:30:38.0843 7064 VGPU - ok 17:30:38.0881 7064 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 17:30:38.0884 7064 vhdmp - ok 17:30:38.0908 7064 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 17:30:38.0909 7064 viaide - ok 17:30:38.0948 7064 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys 17:30:38.0951 7064 vmbus - ok 17:30:38.0975 7064 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys 17:30:38.0976 7064 VMBusHID - ok 17:30:39.0029 7064 vmci (87fc1dd880e8cac4faebb84af61a87c4) C:\Windows\system32\DRIVERS\vmci.sys 17:30:39.0030 7064 vmci - ok 17:30:39.0066 7064 vmkbd (76306d9523bc16baf01f1b71e3e174a9) C:\Windows\system32\drivers\VMkbd.sys 17:30:39.0067 7064 vmkbd - ok 17:30:39.0116 7064 vmm (b2e25db5a6a178c056342abd747b7326) C:\Windows\system32\Drivers\vmm.sys 17:30:39.0118 7064 vmm - ok 17:30:39.0133 7064 VMnetAdapter (b259c31378bc855afd1b53f59311c251) C:\Windows\system32\DRIVERS\vmnetadapter.sys 17:30:39.0133 7064 VMnetAdapter - ok 17:30:39.0185 7064 VMnetBridge (dec4ce720ffeda939cf1ba315cfbd993) C:\Windows\system32\DRIVERS\vmnetbridge.sys 17:30:39.0185 7064 VMnetBridge - ok 17:30:39.0260 7064 VMnetuserif (227982e986c02b710630d7fc570caa77) C:\Windows\system32\drivers\vmnetuserif.sys 17:30:39.0261 7064 VMnetuserif - ok 17:30:39.0280 7064 VMparport (7f0bd2ce08cbe993c539d237661050b4) C:\Windows\system32\drivers\VMparport.sys 17:30:39.0281 7064 VMparport - ok 17:30:39.0333 7064 vmx86 (86aa5eae57e2eaef3b6f5c16b27e0ec4) C:\Windows\system32\drivers\vmx86.sys 17:30:39.0334 7064 vmx86 - ok 17:30:39.0366 7064 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 17:30:39.0367 7064 volmgr - ok 17:30:39.0405 7064 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 17:30:39.0409 7064 volmgrx - ok 17:30:39.0442 7064 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 17:30:39.0445 7064 volsnap - ok 17:30:39.0484 7064 VPCNetS2 (6bdca00fc57cc40da3c8e88b2cea21ab) C:\Windows\system32\DRIVERS\VMNetSrv.sys 17:30:39.0485 7064 VPCNetS2 - ok 17:30:39.0516 7064 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 17:30:39.0519 7064 vsmraid - ok 17:30:39.0544 7064 vstor2-mntapi10-shared - ok 17:30:39.0574 7064 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys 17:30:39.0575 7064 vwifibus - ok 17:30:39.0602 7064 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 17:30:39.0603 7064 WacomPen - ok 17:30:39.0643 7064 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 17:30:39.0644 7064 WANARP - ok 17:30:39.0658 7064 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 17:30:39.0659 7064 Wanarpv6 - ok 17:30:39.0690 7064 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 17:30:39.0691 7064 Wd - ok 17:30:39.0714 7064 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 17:30:39.0721 7064 Wdf01000 - ok 17:30:39.0770 7064 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 17:30:39.0771 7064 WfpLwf - ok 17:30:39.0802 7064 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 17:30:39.0803 7064 WIMMount - ok 17:30:39.0896 7064 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 17:30:39.0898 7064 WinUsb - ok 17:30:39.0946 7064 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 17:30:39.0947 7064 WmiAcpi - ok 17:30:39.0993 7064 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 17:30:39.0994 7064 ws2ifsl - ok 17:30:40.0041 7064 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 17:30:40.0043 7064 WudfPf - ok 17:30:40.0060 7064 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 17:30:40.0062 7064 WUDFRd - ok 17:30:40.0104 7064 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 17:30:40.0109 7064 \Device\Harddisk0\DR0 - ok 17:30:40.0112 7064 Boot (0x1200) (d834e2a95c98c795ebe37d435fc59a56) \Device\Harddisk0\DR0\Partition0 17:30:40.0113 7064 \Device\Harddisk0\DR0\Partition0 - ok 17:30:40.0128 7064 Boot (0x1200) (f5aeae6e620a7b77264483ac812a49ee) \Device\Harddisk0\DR0\Partition1 17:30:40.0128 7064 \Device\Harddisk0\DR0\Partition1 - ok 17:30:40.0129 7064 ============================================================ 17:30:40.0129 7064 Scan finished 17:30:40.0129 7064 ============================================================ 17:30:40.0137 7052 Detected object count: 0 17:30:40.0137 7052 Actual detected object count: 0 17:30:44.0218 6624 Deinitialize success Also, I cannot start Windows Firewall as one of the drivers seem to be missing (Windows Firewall Authorization Driver i think)
Hi


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.

Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
Here is the log: ComboFix 11-11-24.01 - Filip 24/11/2011 18:10:27.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.8191.5898 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: ESET Smart Security 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5} FW: ESET Personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE} SP: ESET Smart Security 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\data c:\data\cmdline.cfg c:\programdata\l9gfqw6lai.exe c:\programdata\Tarma Installer c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setup.dll c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setupx.dll c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.dat c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.exe c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.ico c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico c:\users\Filip\AppData\Roaming\cacaoweb c:\users\Filip\AppData\Roaming\cacaoweb\cacaoweb.exe c:\users\Filip\AppData\Roaming\cacaoweb\npdfile.dat c:\users\Filip\AppData\Roaming\cacaoweb\storage.db c:\users\Filip\AppData\Roaming\chrtmp c:\users\Filip\AppData\Roaming\Love c:\users\Filip\AppData\Roaming\Love\not_tetris_2\highscoresA.txt c:\users\Filip\AppData\Roaming\Love\not_tetris_2\highscoresB.txt c:\users\Filip\AppData\Roaming\Love\not_tetris_2\options.txt c:\users\Filip\AppData\Roaming\SQLite3.dll c:\windows\system32\consrv.dll c:\windows\System64 . . ((((((((((((((((((((((((( Files Created from 2011-10-24 to 2011-11-24 ))))))))))))))))))))))))))))))) . . 2011-11-24 18:16 . 2011-11-24 18:16 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2011-11-24 18:16 . 2011-11-24 18:16 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-11-23 16:01 . 2011-11-24 15:49 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\offreg.dll 2011-11-23 16:01 . 2011-10-07 04:16 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\mpengine.dll 2011-11-22 20:00 . 2011-11-22 20:00 ——– d—–w- c:\program files (x86)\Algodoo 2011-11-19 13:16 . 2011-11-19 13:16 ——– d—–w- c:\program files\ESET 2011-11-18 22:41 . 2011-11-18 22:41 ——– d—–w- c:\users\Filip\AppData\Roaming\.minecraft 2011-11-18 21:56 . 2011-11-18 22:01 ——– d—–w- c:\users\Filip\AppData\Roaming\mctechnick 2011-11-17 22:48 . 2011-11-17 22:48 ——– d—–w- c:\users\Public\Roaming 2011-11-17 22:45 . 2011-11-17 22:45 ——– d—–w- c:\users\Filip\AppData\Roaming\com.adobe.DC3Module.AdobeADC 2011-11-16 18:49 . 2011-11-16 18:49 ——– d—–w- c:\program files (x86)\Sol Edit 2011-11-15 18:35 . 2011-11-15 18:35 ——– d—–w- c:\programdata\ALM 2011-11-14 21:18 . 2011-11-14 21:18 ——– d—–w- c:\users\Filip\AppData\Roaming\Blender Foundation 2011-11-14 21:09 . 2011-11-15 22:22 ——– d—–w- c:\users\Filip\AppData\Roaming\inkscape 2011-11-14 20:59 . 2011-11-14 20:59 ——– d—–w- c:\users\Filip\.thumbnails 2011-11-14 20:59 . 2011-11-14 20:59 ——– d—–w- c:\program files\Blender Foundation 2011-11-14 19:33 . 2011-11-14 19:33 ——– d—–w- c:\users\Filip\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2011-11-13 21:44 . 2011-11-13 21:44 235 —-a-w- c:\windows\SysWow64\nxEuUninstall.bat 2011-11-13 21:44 . 2011-11-13 21:44 446464 —-a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe 2011-11-13 21:24 . 2011-11-13 21:24 1700352 —-a-w- c:\windows\SysWow64\gdiplus.dll 2011-11-13 21:02 . 2011-11-16 16:08 ——– d—–w- C:\Nexon 2011-11-13 18:16 . 2011-11-13 18:18 ——– d—–w- c:\program files\Common Files\Adobe 2011-11-13 13:06 . 2011-11-13 13:06 ——– d—–w- c:\users\Filip\AppData\Roaming\Spam Monitor 2011-11-13 13:06 . 2011-11-13 13:06 ——– d—–w- c:\users\Filip\AppData\Roaming\PCToolsFirewallPlus 2011-11-13 12:57 . 2011-11-14 11:22 ——– d—–w- c:\program files (x86)\Common Files\PC Tools 2011-11-13 12:39 . 2011-11-13 12:39 ——– d—–w- c:\users\Filip\AppData\Roaming\pymclevel 2011-11-13 12:38 . 2011-11-13 12:38 ——– d—–w- c:\users\Filip\AppData\Local\MCEdit-64bit 2011-11-13 12:33 . 2011-11-13 21:25 ——– d—–w- c:\programdata\PC Tools 2011-11-11 22:30 . 2011-11-11 22:30 ——– d—–w- c:\users\Filip\AppData\Local\Skyrim 2011-11-11 19:45 . 2011-11-11 19:45 ——– d—–w- c:\program files\CPUID 2011-11-11 19:45 . 2010-12-27 14:36 21992 —-a-w- c:\windows\system32\drivers\cpuz135_x64.sys 2011-11-11 19:27 . 2011-11-13 21:24 ——– d—–w- c:\programdata\Comodo Downloader 2011-11-11 17:14 . 2011-11-11 17:14 ——– d—–w- c:\windows\Sun 2011-11-10 18:40 . 2011-11-10 18:40 ——– d—–w- c:\users\Filip\AppData\Local\GForce 2011-11-10 18:40 . 2011-11-10 18:40 ——– d—–w- c:\program files (x86)\ASIO4ALL v2 2011-11-10 18:39 . 2011-11-10 18:39 ——– d—–w- c:\program files (x86)\VstPlugins 2011-11-10 18:39 . 2011-11-10 18:39 ——– d—–w- c:\program files (x86)\GForce 2011-11-09 17:41 . 2011-10-01 05:45 886784 —-a-w- c:\program files\Common Files\System\wab32.dll 2011-11-09 17:41 . 2011-10-01 04:37 708608 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll 2011-11-09 17:41 . 2011-09-29 16:29 1923952 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-09 17:41 . 2011-09-29 04:03 3144704 —-a-w- c:\windows\system32\win32k.sys 2011-11-07 19:50 . 2011-11-19 13:41 ——– d—–w- c:\program files (x86)\Yontoo Layers Runtime 2011-11-07 19:50 . 2011-11-07 19:50 ——– d—–w- C:\Downloads 2011-11-07 19:40 . 2011-11-18 22:32 ——– d—–w- c:\users\Filip\AppData\Roaming\Free Download Manager 2011-11-06 19:13 . 2011-10-15 08:53 3074368 —-a-w- c:\windows\system32\nvsvcr.dll 2011-11-06 18:25 . 2011-11-06 18:25 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-11-05 20:55 . 2008-03-05 16:03 238088 —-a-w- c:\windows\SysWow64\xactengine3_0.dll 2011-11-05 16:16 . 2011-11-05 16:29 ——– d—–w- c:\users\Filip\AppData\Roaming\Polynomial 2011-11-05 16:16 . 2011-11-05 16:16 ——– d—–w- c:\program files (x86)\The Polynomial 2011-11-04 20:18 . 2011-11-04 20:19 ——– d—–w- c:\users\Filip\AppData\Roaming\AtomZombieData 2011-11-04 20:11 . 2011-11-04 20:11 ——– d—–w- c:\users\Filip\AppData\Roaming\Voxatron 2011-11-03 18:48 . 2011-11-03 18:48 ——– d—–w- c:\users\Filip\AppData\Local\Apple Computer 2011-11-03 18:40 . 2011-11-03 18:40 ——– d—–w- c:\program files (x86)\Combined Community Codec Pack 2011-11-03 18:26 . 2011-11-03 18:26 ——– d—–w- c:\users\Filip\AppData\Roaming\Media Player Classic 2011-11-03 18:20 . 2011-11-03 18:20 ——– d—–w- c:\program files\Media Player Classic - Home Cinema 2011-11-02 17:55 . 2011-11-02 18:14 ——– d—–w- c:\users\Filip\AppData\Local\Nero 2011-10-29 09:47 . 2011-10-29 09:47 ——– d—–w- c:\users\Filip\AppData\Local\APN 2011-10-29 09:46 . 2011-10-29 09:47 ——– d—–w- c:\users\Filip\AppData\Roaming\ManyCam 2011-10-29 09:46 . 2011-10-29 09:46 ——– d—–w- c:\programdata\Ask 2011-10-28 17:33 . 2011-03-25 11:24 810496 —-a-w- c:\windows\system32\xvidcore.dll 2011-10-28 17:33 . 2011-03-25 11:24 80896 —-a-w- c:\windows\system32\ff_vfw.dll 2011-10-28 17:33 . 2011-03-25 11:24 183808 —-a-w- c:\windows\system32\xvidvfw.dll 2011-10-28 17:33 . 2011-03-11 15:06 389120 —-a-w- c:\windows\SysWow64\actskn43.ocx 2011-10-28 17:33 . 2011-03-11 15:06 389120 —-a-w- c:\windows\system32\actskn43.ocx 2011-10-26 12:36 . 2011-08-13 05:27 6144 —-a-w- c:\program files\Internet Explorer\iecompat.dll 2011-10-26 12:36 . 2011-08-13 04:18 6144 —-a-w- c:\program files (x86)\Internet Explorer\iecompat.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-14 18:06 . 2011-05-17 16:24 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-11 19:50 . 2011-08-13 11:19 6656 —-a-w- c:\windows\system32\lpcio.dll 2011-11-09 18:25 . 2011-09-04 14:58 850152 —-a-w- c:\windows\SysWow64\SpoonUninstall.exe 2011-11-05 12:59 . 2011-05-21 13:12 466456 —-a-w- c:\windows\system32\wrap_oal.dll 2011-11-05 12:59 . 2011-05-21 13:12 444952 —-a-w- c:\windows\SysWow64\wrap_oal.dll 2011-11-05 12:59 . 2011-05-21 13:12 122904 —-a-w- c:\windows\system32\OpenAL32.dll 2011-11-05 12:59 . 2011-05-21 13:12 109080 —-a-w- c:\windows\SysWow64\OpenAL32.dll 2011-10-15 08:53 . 2011-10-08 14:06 2458432 —-a-w- c:\windows\SysWow64\nvapi.dll 2011-10-15 08:53 . 2011-10-01 10:16 837952 —-a-w- c:\windows\system32\easyupdatusapiu64.dll 2011-10-15 08:53 . 2011-10-01 10:16 5067584 —-a-w- c:\windows\system32\nvsvc64.dll 2011-10-15 08:53 . 2011-10-01 10:16 222528 —-a-w- c:\windows\system32\nvmctray.dll 2011-10-15 08:53 . 2011-10-01 10:16 1640768 —-a-w- c:\windows\system32\nvvsvc.exe 2011-10-15 08:53 . 2011-10-01 10:16 137536 —-a-w- c:\windows\system32\nvshext.dll 2011-10-15 08:53 . 2011-10-01 10:16 10406208 —-a-w- c:\windows\system32\nvcpl.dll 2011-10-15 08:53 . 2011-10-01 10:15 2808128 —-a-w- c:\windows\system32\nvapi64.dll 2011-10-15 08:53 . 2011-10-01 10:15 15693120 —-a-w- c:\windows\system32\nvd3dumx.dll 2011-10-15 08:53 . 2011-10-01 10:15 1533248 —-a-w- c:\windows\system32\nvdispco64.dll 2011-10-15 08:53 . 2011-10-01 10:15 1454400 —-a-w- c:\windows\system32\nvgenco64.dll 2011-10-15 08:53 . 2009-07-13 21:59 8791360 —-a-w- c:\windows\system32\nvwgf2umx.dll 2011-10-15 08:53 . 2009-06-10 20:37 13205312 —-a-w- c:\windows\SysWow64\nvd3dum.dll 2011-10-15 00:54 . 2011-10-15 00:54 321856 —-a-w- c:\windows\SysWow64\nvStreaming.exe 2011-10-05 17:43 . 2011-10-04 16:37 270408 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2011-10-05 17:43 . 2011-10-02 17:45 270408 —-a-w- c:\windows\SysWow64\PnkBstrB.exe 2011-10-04 20:29 . 2011-10-02 17:45 270408 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0 2011-10-04 16:38 . 2011-10-02 17:45 75136 —-a-w- c:\windows\SysWow64\PnkBstrA.exe 2011-10-03 05:06 . 2011-04-27 17:48 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-10-02 12:56 . 2011-10-02 12:56 2301208 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-10-02 12:56 . 2011-10-02 12:56 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-10-02 12:56 . 2011-10-02 12:56 710976 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2011-10-02 12:21 . 2011-10-02 12:21 53248 —-a-w- c:\users\Filip\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2011-10-02 11:58 . 2011-10-02 11:58 18960 —-a-w- c:\windows\system32\drivers\LNonPnP.sys 2011-10-01 03:25 . 2011-10-13 15:49 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-10-01 02:42 . 2011-10-13 15:49 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-08-31 17:00 . 2011-10-07 20:10 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-27 05:37 . 2011-10-13 15:48 861696 —-a-w- c:\windows\system32\oleaut32.dll 2011-08-27 05:37 . 2011-10-13 15:48 331776 —-a-w- c:\windows\system32\oleacc.dll 2011-08-27 04:26 . 2011-10-13 15:48 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-08-27 04:26 . 2011-10-13 15:48 233472 —-a-w- c:\windows\SysWow64\oleacc.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}] 2011-09-16 02:46 367384 —-a-w- c:\program files\Logitech\ScrollApp\32-bit\LogiSmooth.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Turbo Key"="c:\program files\ASUS\Turbo Key\TurboKey.exe" [2009-06-02 1769472] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608] . c:\users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-10-31 24241928] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x] R0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [x] R2 AMService;AMService;c:\windows\TEMP\dbnwjd\setup.exe run [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x] R3 dump_wmimmc;dump_wmimmc;l:\gamescampus\DriftCity\GameGuard\dump_wmimmc.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x] R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys [x] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [x] R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.0);c:\windows\system32\DRIVERS\RtVlan60.sys [x] R3 SaiK0836;SaiK0836;c:\windows\system32\DRIVERS\SaiK0836.sys [x] R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-04-20 152064] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [x] R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [x] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 MDFSYSNT;MacDrive file system driver; [x] S0 MDPMGRNT;MacDrive Partition Driver;c:\windows\system32\DRIVERS\MDPMGRNT.SYS [x] S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [x] S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x] S1 CBDisk;CBDisk;c:\windows\system32\drivers\CBDisk.sys [x] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x] S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [x] S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x] S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [2009-10-14 319488] S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2009-05-14 731840] S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 2329480] S2 M4LIC;Mediafour M4LIC service;c:\program files (x86)\Common Files\Mediafour\M4LIC.EXE [2009-07-29 205312] S2 MacDrive8Service;MacDrive 8 service;c:\program files\Mediafour\MacDrive 8\MacDrive8Service.exe [2010-01-07 218112] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-03-29 598312] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120] S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-15 2280312] S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-03-09 92592] S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-21 846448] S2 VMwareHostd;VMware Workstation Server;l:\program files (x86)\VMware Workstation\vmware-hostd.exe [2011-08-22 11837440] S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x] S3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 V0260VID;Live! Cam Vista IM;c:\windows\system32\DRIVERS\V0260Vid.sys [x] S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-11-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1597807966-2542162096-940782561-1001Core.job - c:\users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-30 16:02] . 2011-11-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1597807966-2542162096-940782561-1001UA.job - c:\users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-30 16:02] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}] 2011-09-16 02:46 435992 —-a-w- c:\program files\Logitech\ScrollApp\LogiSmooth.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MacDrive 8 application"="c:\program files\Mediafour\MacDrive 8\MacDrive.exe" [2010-02-04 345688] "Getting started with MacDrive 8"="c:\program files\Mediafour\MacDrive 8\MDGetStarted.exe" [2009-03-31 151040] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-18 8067616] "SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2010-07-29 158208] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1744152] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-11-19 2692520] "combofix"="c:\combofix\CF2187.3XE" [2010-11-20 345088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105 LSP: %SystemRoot%\system32\vsocklib.dll TCP: DhcpNameServer = 192.168.1.254 . . ——- File Associations ——- . txtfile="c:\program files (x86)\PSPad editor\PSPad.exe" "%1" . - - - - ORPHANS REMOVED - - - - . BHO-{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - (no file) Wow6432Node-HKCU-Run-AdobeBridge - (no file) SafeBoot-95649713.sys ShellIconOverlayIdentifiers-MacDrive volume icons - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-CraftBukkit - 0:\users\Filip\CraftBukkit Server\Uninstall.exe AddRemove-dBpoweramp Dalet Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp FLAC Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp m4a Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Monkeys Audio Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Mp2 and BwfMp2 codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp mp3 (Fraunhofer IIS) Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Ogg Vorbis Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Real Audio (Helix) Encoder - c:\windows\system32\SpoonUninstall.exe AddRemove-dBPoweramp tooLame MP2 codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Wave64 Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp WavPack Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [Calculate Audio CRC] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [ID Tag Update] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-Dungeon Defenders_is1 - l:\program files (x86)\Trendy Entertainment\Dungeon Defenders\unins000.exe AddRemove-Rainbow Sentinel Driver - c:\windows\SYSTEM32\RNBOSENT\SETUPX86.EXE AddRemove-Steam App 105600 - c:\pacsteamt\steam.exe AddRemove-Steam App 11020 - c:\program files (x86)\Steam\steam.exe AddRemove-Steam App 12210 - c:\program files (x86)\Steam\steam.exe AddRemove-Steam App 22230 - c:\pacsteamt\steam.exe AddRemove-Steam App 4000 - c:\program files (x86)\Steam\steam.exe AddRemove-Steam App 440 - c:\program files (x86)\Steam\steam.exe AddRemove-Steam App 550 - c:\program files (x86)\Steam\steam.exe AddRemove-UnityWebPlayer - c:\users\Filip\AppData\Local\Unity\WebPlayer\Uninstall.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1597807966-2542162096-940782561-1001\Software\SecuROM\License information*] "datasecu"=hex:7f,a0,e3,1b,e4,c7,a4,67,7e,26,ec,70,c4,ea,4d,64,78,46,1a,1a,21, 25,f9,cc,2e,e0,5c,9d,35,08,0c,28,40,e7,ba,d9,cf,6e,5c,cb,7f,db,cd,4b,79,6b,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_USERS\S-1-5-21-1597807966-2542162096-940782561-1001_Classes\vid386vw*] @Allowed: (Read) (RestrictedCode) "F7289ADB-F0FA-11D3-851E-00600857F6CE"="4CDE 65C5 F954 4080 3EA4 7A9B 8CA0 A30D 8987 680E 2952 9FCC F934 9B65 4F96 E76E " . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info] @Denied: (2) (LocalSystem) "AppDataDir"="c:\\ProgramData\\ESET\\ESET Smart Security\\" "DataDir"="ESET\\ESET Smart Security\\" "EditionName"=" " "InstallDir"="c:\\Program Files\\ESET\\ESET Smart Security\\" "LanguageId"=dword:00000409 "PackageTag"=dword:00000000 "ProductBase"=dword:00000001 "ProductCode"="{6378ABCE-F816-4330-A7B1-FBEBCD50B746}" "ProductName"="ESET Smart Security" "ProductType"="ess" "ProductVersion"="4.0.437.0" "UniqueId"="000DD2D84EC7AC71" "ScannerBuild"=dword:00001329 "ScannerVersionId"=dword:00000feb "ScannerVersion"="ready" "FixId"=dword:00000009 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\windows\SysWOW64\PnkBstrA.exe c:\windows\SysWOW64\vmnat.exe l:\program files (x86)\VMware Workstation\vmware-authd.exe c:\windows\SysWOW64\vmnetdhcp.exe c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe c:\program files (x86)\ASUS\EPU-4 Engine\FourEngine.exe . ************************************************************************** . Completion time: 2011-11-24 18:25:41 - machine was rebooted ComboFix-quarantined-files.txt 2011-11-24 18:25 . Pre-Run: 61,695,336,448 bytes free Post-Run: 65,913,376,768 bytes free . - - End Of File - - 1500E7A35A2EC181BC54BA70E885172E There is a slight problem, I can only launch applications as administrator, otherwise this error pops up C:/pathtoapplication/example.exe Illegal operation attempted on a registry key that has been marked for deletion Not the worst I've seen, but if that can be fixed in any way then please offer some advice.
Here are the dds logs: . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 18:38:07.22 on 24/11/2011 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.8191.6186 [GMT 0:00] . AV: ESET Smart Security 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5} SP: ESET Smart Security 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe C:\ASUS.SYS\config\DVMExportService.exe C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe C:\Program Files (x86)\Common Files\Mediafour\M4LIC.EXE C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe C:\Windows\SysWOW64\vmnat.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe L:\Program Files (x86)\VMware Workstation\vmware-authd.exe C:\Windows\SysWOW64\vmnetdhcp.exe L:\Program Files (x86)\VMware Workstation\vmware-hostd.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Windows\system32\DllHost.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Nero\Update\NASvc.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Filip\Downloads\dds.scr C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: Logitech Scroll App: {e11db59d-5008-42ff-9069-535843bc0be1} - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - Yontoo Layers mRun: [Turbo Key] "C:\Program Files\ASUS\Turbo Key\TurboKey.exe" mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray StartupFolder: C:\Users\Filip\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: EnableLinkedConnections = 1 (0x1) IE: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm IE: E&xport; to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd; to OneNote - C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll LSP: %SystemRoot%\system32\vsocklib.dll DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll BHO-X64: Logitech Scroll App: {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\ScrollApp\LogiSmooth.dll mRun-x64: [MacDrive 8 application] "C:\Program Files\Mediafour\MacDrive 8\MacDrive.exe" mRun-x64: [Getting started with MacDrive 8] "C:\Program Files\Mediafour\MacDrive 8\MDGetStarted.exe" /auto mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s mRun-x64: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe mRun-x64: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming mRun-x64: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" mRun-x64: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL . ============= SERVICES / DRIVERS =============== . R0 MDFSYSNT;MacDrive file system driver;C:\Windows\System32\drivers\MDFSYSNT.SYS [2010-2-4 304232] R0 MDPMGRNT;MacDrive Partition Driver;C:\Windows\System32\drivers\MDPMGRNT.SYS [2011-4-25 32352] R1 CBDisk;CBDisk;C:\Windows\System32\drivers\CBDisk.sys [2011-4-25 70344] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952] R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2011-4-26 90112] R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2011-11-11 21992] R2 DvmMDES;DeviceVM Meta Data Export Service;C:\ASUS.SYS\config\DVMExportService.exe [2009-10-14 319488] R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-5-14 731840] R2 epfwwfp;epfwwfp;C:\Windows\System32\drivers\epfwwfp.sys [2009-5-14 44944] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-8-15 2329480] R2 M4LIC;Mediafour M4LIC service;C:\Program Files (x86)\Common Files\Mediafour\M4LIC.EXE [2009-7-29 205312] R2 MacDrive8Service;MacDrive 8 service;C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe [2010-1-7 218112] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-13 366152] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-3-29 598312] R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-1 2253120] R2 RtNdPt60;Realtek NDIS Protocol Driver;C:\Windows\System32\drivers\RtNdPt60.sys [2011-4-26 26624] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-4-27 2280312] R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-3-9 92592] R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-8-21 846448] R2 VMwareHostd;VMware Workstation Server;L:\Program Files (x86)\VMware Workstation\vmware-hostd.exe [2011-8-22 11837440] R3 DKRtWrt;DKRtWrt;C:\Windows\System32\drivers\DKRtWrt.sys [2011-9-8 44624] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-10-7 25416] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-1-21 413800] R3 V0260VID;Live! Cam Vista IM;C:\Windows\System32\drivers\V0260Vid.sys [2011-5-8 189664] S2 AMService;AMService;C:\Windows\TEMP\dbnwjd\setup.exe run –> C:\Windows\TEMP\dbnwjd\setup.exe run [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 KMService;KMService;C:\Windows\system32\srvany.exe –> C:\Windows\system32\srvany.exe [?] S2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688] S3 ggflt;SEMC USB Flash Driver Filter;C:\Windows\System32\drivers\ggflt.sys [2011-6-5 13352] S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\System32\drivers\ManyCam_x64.sys [2008-3-13 27136] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536] S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?] S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-6-7 20992] S3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0);C:\Windows\System32\drivers\RtTeam60.sys [2011-4-26 43008] S3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.0);C:\Windows\System32\drivers\RtVlan60.sys [2011-4-26 24064] S3 SaiK0836;SaiK0836;C:\Windows\System32\drivers\SaiK0836.sys [2010-6-17 172040] S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-6-5 152064] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);C:\Windows\System32\drivers\RtTeam60.sys [2011-4-26 43008] S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\System32\drivers\teamviewervpn.sys [2011-4-27 35112] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-7 59392] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-4-24 1255736] . =============== File Associations =============== . txtfile="C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1" . =============== Created Last 30 ================ . 2011-11-24 18:20:08 ——– d—–w- C:\$RECYCLE.BIN 2011-11-24 18:09:05 98816 —-a-w- C:\Windows\sed.exe 2011-11-24 18:09:05 518144 —-a-w- C:\Windows\SWREG.exe 2011-11-24 18:09:05 256000 —-a-w- C:\Windows\PEV.exe 2011-11-24 18:09:05 208896 —-a-w- C:\Windows\MBR.exe 2011-11-24 15:51:35 ——– d—–w- C:\Users\Filip\AppData\Local\{0A2968BC-4E7B-4FD7-B9D3-D03A9330DABC} 2011-11-24 15:51:10 ——– d—–w- C:\Users\Filip\AppData\Local\{E3BD6A57-093D-47F9-8EA5-4D8B9AD9A87E} 2011-11-23 16:03:07 ——– d—–w- C:\Users\Filip\AppData\Local\{6BC45846-2F67-4C15-BDD1-C5D2A2FBC217} 2011-11-23 16:01:55 69000 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\offreg.dll 2011-11-23 16:01:53 8570192 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\mpengine.dll 2011-11-22 20:00:23 ——– d—–w- C:\Program Files (x86)\Algodoo 2011-11-22 16:17:21 ——– d—–w- C:\Users\Filip\AppData\Local\{5BBBAA24-90DC-4480-B395-3D9BFB8CA64D} 2011-11-21 11:37:37 ——– d—–w- C:\Users\Filip\AppData\Local\{93B1615B-A5E3-4B30-B9B2-5D4DB12D7A28} 2011-11-21 11:37:20 ——– d—–w- C:\Users\Filip\AppData\Local\{BAFAB55A-00BE-4B8A-84F5-7907B0ECA4E4} 2011-11-20 12:12:00 ——– d—–w- C:\Users\Filip\AppData\Local\{7A24CF98-A65E-49E5-ADF6-B44547BF6966} 2011-11-20 12:11:38 ——– d—–w- C:\Users\Filip\AppData\Local\{17350408-A3DC-4C50-B653-753D232313A6} 2011-11-20 12:06:10 ——– d—–w- C:\Users\Filip\AppData\Local\{6D42D460-61A4-4437-8BAE-BF616E563E38} 2011-11-19 13:18:13 ——– d—–w- C:\Users\Filip\AppData\Roaming\ESET 2011-11-19 13:16:48 ——– d—–w- C:\Program Files\ESET 2011-11-19 09:42:18 ——– d—–w- C:\Users\Filip\AppData\Local\{754C8F4A-1768-4214-9CE0-015947FBB78B} 2011-11-19 09:41:53 ——– d—–w- C:\Users\Filip\AppData\Local\{0EA356A3-4CF1-48A1-8CBF-39CC02C53E52} 2011-11-18 22:41:50 ——– d—–w- C:\Users\Filip\AppData\Roaming\.minecraft 2011-11-18 21:56:13 ——– d—–w- C:\Users\Filip\AppData\Roaming\mctechnick 2011-11-18 17:55:32 ——– d—–w- C:\Users\Filip\AppData\Local\{51A67855-334F-4988-8A54-7FAECA7FDC98} 2011-11-18 17:55:08 ——– d—–w- C:\Users\Filip\AppData\Local\{8E705346-414A-40F1-88BE-B68530E1DB1A} 2011-11-17 22:45:37 ——– d—–w- C:\Users\Filip\AppData\Roaming\com.adobe.DC3Module.AdobeADC 2011-11-17 20:33:13 ——– d—–w- C:\Users\Filip\AppData\Local\{FAC9AAF4-5818-4705-B8F2-F8ACECC002B5} 2011-11-17 20:33:01 ——– d—–w- C:\Users\Filip\AppData\Local\{1E3435A7-79C4-4D93-A3AD-AEF27CE372DC} 2011-11-17 16:10:46 ——– d—–w- C:\Users\Filip\AppData\Local\{CF990AF9-4577-41AB-84F6-270626A0E3E1} 2011-11-16 18:49:37 ——– d—–w- C:\Program Files (x86)\Sol Edit 2011-11-16 16:05:46 ——– d—–w- C:\Users\Filip\AppData\Local\{5C4CBAC7-3F2F-4C53-BBA0-7E1382060F78} 2011-11-16 16:05:27 ——– d—–w- C:\Users\Filip\AppData\Local\{DAE489E5-3501-40D8-88A5-257297D5757B} 2011-11-15 21:17:23 ——– d—–w- C:\Users\Filip\AppData\Local\{C0A35800-646A-447B-98A2-792B0946E6CC} 2011-11-15 21:17:11 ——– d—–w- C:\Users\Filip\AppData\Local\{18E86E3F-F2F2-4A16-A642-B9DB76A4C4E2} 2011-11-15 18:35:27 ——– d—–w- C:\PROGRA~3\ALM 2011-11-14 21:18:55 ——– d—–w- C:\Users\Filip\AppData\Roaming\Blender Foundation 2011-11-14 21:09:52 ——– d—–w- C:\Users\Filip\AppData\Roaming\inkscape 2011-11-14 20:59:48 ——– d—–w- C:\Users\Filip\.thumbnails 2011-11-14 20:59:35 ——– d—–w- C:\Program Files\Blender Foundation 2011-11-14 19:33:25 ——– d—–w- C:\Users\Filip\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2011-11-13 21:44:58 235 —-a-w- C:\Windows\SysWow64\nxEuUninstall.bat 2011-11-13 21:44:53 446464 —-a-w- C:\Windows\NEXON_EU_DownloaderUpdater.exe 2011-11-13 21:24:38 1700352 —-a-w- C:\Windows\SysWow64\gdiplus.dll 2011-11-13 21:02:08 ——– d—–w- C:\Nexon 2011-11-13 13:06:29 ——– d—–w- C:\Users\Filip\AppData\Roaming\Spam Monitor 2011-11-13 13:06:29 ——– d—–w- C:\Users\Filip\AppData\Roaming\PCToolsFirewallPlus 2011-11-13 12:57:40 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools 2011-11-13 12:39:06 ——– d—–w- C:\Users\Filip\AppData\Roaming\pymclevel 2011-11-13 12:38:37 ——– d—–w- C:\Users\Filip\AppData\Local\MCEdit-64bit 2011-11-13 12:33:19 ——– d—–w- C:\PROGRA~3\PC Tools 2011-11-13 10:18:45 ——– d—–w- C:\Users\Filip\AppData\Local\{B5EE657B-F0BD-42FE-A8DA-35125B472AE8} 2011-11-13 10:18:30 ——– d—–w- C:\Users\Filip\AppData\Local\{449B85E7-D03A-4EB9-9F04-79FE4D84C1B0} 2011-11-12 17:37:43 ——– d—–w- C:\Users\Filip\AppData\Local\{310251F6-4F2F-4954-AF79-C65579238B1A} 2011-11-12 17:37:24 ——– d—–w- C:\Users\Filip\AppData\Local\{2227EF0A-927F-487C-9320-EE263E5C3122} 2011-11-12 13:03:21 ——– d—–w- C:\Users\Filip\AppData\Local\{891C11B5-3B35-48B6-A551-0F9651572B8F} 2011-11-11 22:30:43 ——– d—–w- C:\Users\Filip\AppData\Local\Skyrim 2011-11-11 19:45:23 21992 —-a-w- C:\Windows\System32\drivers\cpuz135_x64.sys 2011-11-11 19:45:23 ——– d—–w- C:\Program Files\CPUID 2011-11-11 19:27:10 ——– d—–w- C:\PROGRA~3\Comodo Downloader 2011-11-11 16:23:43 ——– d—–w- C:\Users\Filip\AppData\Local\{706470F3-146E-4A5D-96E8-870585A8B18F} 2011-11-11 16:23:32 ——– d—–w- C:\Users\Filip\AppData\Local\{C5CA3EEB-5573-470F-962B-B703B3F39A72} 2011-11-10 18:40:16 ——– d—–w- C:\Users\Filip\AppData\Local\GForce 2011-11-10 18:40:12 ——– d—–w- C:\Program Files (x86)\ASIO4ALL v2 2011-11-10 18:39:11 ——– d—–w- C:\Program Files (x86)\VstPlugins 2011-11-10 18:39:08 ——– d—–w- C:\Program Files (x86)\GForce 2011-11-10 16:25:13 ——– d—–w- C:\Users\Filip\AppData\Local\{528B5662-1B42-40DE-A826-127DA9D55516} 2011-11-10 16:25:02 ——– d—–w- C:\Users\Filip\AppData\Local\{AF5194A8-B56B-480E-BF0D-BE37F9EC0632} 2011-11-09 17:41:59 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll 2011-11-09 17:41:59 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll 2011-11-09 17:41:56 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-11-09 17:41:52 3144704 —-a-w- C:\Windows\System32\win32k.sys 2011-11-09 15:46:24 ——– d—–w- C:\Users\Filip\AppData\Local\{95575238-7D0A-47A5-AD6D-096B1C6C4046} 2011-11-09 15:46:11 ——– d—–w- C:\Users\Filip\AppData\Local\{639CC487-6A09-4958-8591-CCA7D3298004} 2011-11-08 17:35:57 ——– d—–w- C:\Users\Filip\AppData\Local\{8B64D692-7869-4B14-AB6D-4A15BF51DF1D} 2011-11-08 17:35:43 ——– d—–w- C:\Users\Filip\AppData\Local\{A4BADC77-D106-4CC7-A2F9-7F0A084F871B} 2011-11-07 19:50:49 ——– d—–w- C:\Program Files (x86)\Yontoo Layers Runtime 2011-11-07 19:50:04 ——– d—–w- C:\Downloads 2011-11-07 19:40:30 ——– d—–w- C:\Users\Filip\AppData\Roaming\Free Download Manager 2011-11-07 16:22:43 ——– d—–w- C:\Users\Filip\AppData\Local\{3DCBC98D-27E5-4B8D-A611-B35BE9430A9D} 2011-11-07 16:22:32 ——– d—–w- C:\Users\Filip\AppData\Local\{D40E7156-DFAF-4089-A1AD-A74C206DC980} 2011-11-06 19:13:12 3074368 —-a-w- C:\Windows\System32\nvsvcr.dll 2011-11-05 20:55:59 529424 —-a-w- C:\Windows\System32\d3dx10_37.dll 2011-11-05 16:16:15 ——– d—–w- C:\Users\Filip\AppData\Roaming\Polynomial 2011-11-05 16:16:06 ——– d—–w- C:\Program Files (x86)\The Polynomial 2011-11-05 10:40:46 ——– d—–w- C:\Users\Filip\AppData\Local\{6C5390A8-344E-4E2A-B7C7-AC06A3AB689F} 2011-11-05 10:40:33 ——– d—–w- C:\Users\Filip\AppData\Local\{A2388B35-93A8-4701-A6F5-9A1C4B83A05B} 2011-11-04 20:18:44 ——– d—–w- C:\Users\Filip\AppData\Roaming\AtomZombieData 2011-11-04 20:11:53 ——– d—–w- C:\Users\Filip\AppData\Roaming\Voxatron 2011-11-04 18:21:14 ——– d—–w- C:\Users\Filip\AppData\Local\{A30D4DB5-D91E-4F5A-B511-12AF3135EBC6} 2011-11-04 18:21:03 ——– d—–w- C:\Users\Filip\AppData\Local\{8A0A44CF-9CBD-43D4-A7E2-E89399B60E4F} 2011-11-03 18:48:24 ——– d—–w- C:\Users\Filip\AppData\Local\Apple Computer 2011-11-03 18:40:39 ——– d—–w- C:\Program Files (x86)\Combined Community Codec Pack 2011-11-03 18:20:18 ——– d—–w- C:\Program Files\Media Player Classic - Home Cinema 2011-11-03 17:31:18 ——– d—–w- C:\Users\Filip\AppData\Local\{2FBDCE59-96F8-4B3D-BD95-B63221E308D0} 2011-11-03 17:31:05 ——– d—–w- C:\Users\Filip\AppData\Local\{6C1F5BBB-05C8-4F73-A254-2F7E45931266} 2011-11-03 08:11:07 ——– d—–w- C:\Users\Filip\AppData\Local\{65C9E9D2-262C-4EE2-B508-9823D3B12F4E} 2011-11-02 17:56:03 ——– d—–w- C:\Users\Filip\AppData\Local\Nero_AG 2011-11-02 17:55:28 ——– d—–w- C:\Users\Filip\AppData\Local\Nero 2011-11-02 17:54:19 ——– d—–w- C:\Users\Filip\AppData\Local\{473ECC4E-454E-41F5-8B6B-05A5E88D32FD} 2011-11-02 17:54:08 ——– d—–w- C:\Users\Filip\AppData\Local\{2C438F03-51E5-4AB5-B8F0-02400A9E134D} 2011-11-01 17:09:46 ——– d—–w- C:\Users\Filip\AppData\Local\{D47D465E-6BB0-4322-BE5D-8055AFFBC669} 2011-11-01 17:09:28 ——– d—–w- C:\Users\Filip\AppData\Local\{007A31D0-E416-42BD-B6AD-FFC9E101DF2F} 2011-10-31 18:06:52 ——– d—–w- C:\Users\Filip\AppData\Local\{106CC801-F100-43FA-A1D3-9C88F8462D06} 2011-10-31 18:06:29 ——– d—–w- C:\Users\Filip\AppData\Local\{284BB6A4-2BF1-4840-AD9B-B024BB34FF58} 2011-10-30 09:14:27 ——– d—–w- C:\Users\Filip\AppData\Local\{49828ABD-0040-49AE-9229-E5546FFE1E33} 2011-10-30 09:14:02 ——– d—–w- C:\Users\Filip\AppData\Local\{4C981980-300D-4C97-8F76-C4BF52901C14} 2011-10-29 17:35:56 ——– d—–w- C:\Users\Filip\AppData\Local\{73DF0A1B-FEBC-40B6-8254-763A32AC06A5} 2011-10-29 17:35:35 ——– d—–w- C:\Users\Filip\AppData\Local\{3A2FDC50-6705-4E61-BF4B-9A4629DF56DA} 2011-10-29 09:47:00 ——– d—–w- C:\Users\Filip\AppData\Local\APN 2011-10-29 09:46:44 ——– d—–w- C:\Users\Filip\AppData\Roaming\ManyCam 2011-10-29 09:46:36 ——– d—–w- C:\PROGRA~3\Ask 2011-10-29 09:36:52 ——– d—–w- C:\Users\Filip\AppData\Local\{276925AF-CF6F-4F49-AAD3-6637D70FA15E} 2011-10-28 17:33:34 810496 —-a-w- C:\Windows\System32\xvidcore.dll 2011-10-28 17:33:34 80896 —-a-w- C:\Windows\System32\ff_vfw.dll 2011-10-28 17:33:34 183808 —-a-w- C:\Windows\System32\xvidvfw.dll 2011-10-28 17:33:00 389120 —-a-w- C:\Windows\SysWow64\actskn43.ocx 2011-10-28 17:33:00 389120 —-a-w- C:\Windows\System32\actskn43.ocx 2011-10-28 10:28:10 ——– d—–w- C:\Users\Filip\AppData\Local\{864C829F-D53A-4B18-83E0-99B752BD7993} 2011-10-28 10:27:58 ——– d—–w- C:\Users\Filip\AppData\Local\{2351F912-0E2A-4175-99DA-87B0AB8A0671} 2011-10-27 08:59:16 ——– d—–w- C:\Users\Filip\AppData\Local\{7BCEF7FF-0A87-4A05-AA91-597DEC255EC6} 2011-10-27 08:58:51 ——– d—–w- C:\Users\Filip\AppData\Local\{EA6EE90D-F77D-4896-BC8C-48F3B149E1C9} 2011-10-26 12:36:20 6144 —-a-w- C:\Program Files\Internet Explorer\iecompat.dll 2011-10-26 12:36:20 6144 —-a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll 2011-10-26 12:26:36 ——– d—–w- C:\Users\Filip\AppData\Local\{6C2BE5E5-01B8-4D6E-85B6-12164301E01E} 2011-10-26 12:26:22 ——– d—–w- C:\Users\Filip\AppData\Local\{F43BD921-F76E-487B-9E77-8CDC92C93491} . ==================== Find3M ==================== . 2011-11-14 18:06:57 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-11 19:50:11 6656 —-a-w- C:\Windows\System32\lpcio.dll 2011-11-09 18:25:38 850152 —-a-w- C:\Windows\SysWow64\SpoonUninstall.exe 2011-11-05 12:59:55 466456 —-a-w- C:\Windows\System32\wrap_oal.dll 2011-11-05 12:59:55 444952 —-a-w- C:\Windows\SysWow64\wrap_oal.dll 2011-11-05 12:59:55 122904 —-a-w- C:\Windows\System32\OpenAL32.dll 2011-11-05 12:59:55 109080 —-a-w- C:\Windows\SysWow64\OpenAL32.dll 2011-10-15 00:54:52 321856 —-a-w- C:\Windows\SysWow64\nvStreaming.exe 2011-10-05 17:43:38 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr 2011-10-05 17:43:38 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe 2011-10-04 20:29:42 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.ex0 2011-10-04 16:38:17 75136 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe 2011-10-03 05:06:03 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-10-02 11:58:11 18960 —-a-w- C:\Windows\System32\drivers\LNonPnP.sys 2011-10-01 03:25:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2011-10-01 02:42:56 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-08-31 17:00:50 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-08-27 05:37:49 861696 —-a-w- C:\Windows\System32\oleaut32.dll 2011-08-27 05:37:48 331776 —-a-w- C:\Windows\System32\oleacc.dll 2011-08-27 04:26:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-27 04:26:27 233472 —-a-w- C:\Windows\SysWow64\oleacc.dll . ============= FINISH: 18:38:29.63 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 24/04/2011 15:55:58 System Uptime: 24/11/2011 18:18:24 (0 hours ago) . Motherboard: ASUSTeK Computer INC. | | P5G41TD-M PRO Processor: Intel® Core™2 Duo CPU E8400 @ 3.00GHz | LGA775 | 3003/333mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 186 GiB total, 57.092 GiB free. D: is FIXED (NTFS) - 373 GiB total, 11.063 GiB free. E: is CDROM () F: is Removable H: is Removable I: is Removable J: is Removable K: is FIXED (HFSJ) - 233 GiB total, 156.503 GiB free. L: is FIXED (NTFS) - 140 GiB total, 19.192 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VMware Virtual Ethernet Adapter for VMnet1 Device ID: ROOT\VMWARE\0000 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet1 PNP Device ID: ROOT\VMWARE\0000 Service: VMnetAdapter . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VMware Virtual Ethernet Adapter for VMnet8 Device ID: ROOT\VMWARE\0001 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet8 PNP Device ID: ROOT\VMWARE\0001 Service: VMnetAdapter . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: TeamViewer VPN Adapter Device ID: ROOT\NET\0001 Manufacturer: TeamViewer GmbH Name: TeamViewer VPN Adapter PNP Device ID: ROOT\NET\0001 Service: teamviewervpn . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VirtualBox Host-Only Ethernet Adapter Device ID: ROOT\NET\0002 Manufacturer: Oracle Corporation Name: VirtualBox Host-Only Ethernet Adapter PNP Device ID: ROOT\NET\0002 Service: VBoxNetAdp . ==== System Restore Points =================== . RP254: 23/11/2011 16:01:35 - Windows Update . ==== Installed Programs ====================== . .sol Editor 1.1.0.1 Adobe AIR Adobe Community Help Adobe Flash Player 10 ActiveX Adobe Illustrator CS5.1 Adobe Photoshop CS5.1 Adobe Reader X (10.1.1) Adobe Shockwave Player 11.6 Aerosoft's - Aerosoft Launcher Algodoo v2.0.0 Apple Application Support Apple Software Update ASIO4ALL Assassin's Creed Brotherhood ASUSUpdate Audacity 1.3.13 (Unicode) Audiograbber 1.83 SE Audiograbber MP3 Plugin AutoHotkey 1.1.04.01 Bandisoft MPEG-1 Decoder Bastion Call of Juarez - Bound in Blood Cheat Engine 6.0 Combined Community Codec Pack 2011-07-30 CraftBukkit Crysis® 2 D3DX10 dBpoweramp [Calculate Audio CRC] Codec dBpoweramp [ID Tag Update] Codec dBpoweramp Dalet Codec dBpoweramp DSP Effects dBpoweramp FLAC Codec dBpoweramp m4a Codec dBpoweramp Monkeys Audio Codec dBpoweramp Mp2 and BwfMp2 codec dBpoweramp mp3 (Fraunhofer IIS) Codec dBpoweramp Music Converter dBpoweramp Ogg Vorbis Codec dBpoweramp Real Audio (Helix) Encoder dBPoweramp tooLame MP2 codec dBpoweramp Wave64 Codec dBpoweramp WavPack Codec Dead Rising 2: OTR Deus Ex Deus Ex - Human Revolution version 1.0 Dev-C++ 5 beta 9 release (4.9.9.2) Diagnostic Utility Drift City Driver San Francisco Driver San Francisco version 1.0 Dropbox Dungeon Defenders EasyBCD 2.0 EPU-4 Engine eReg Express Gate Fable III Flight Simulator X Flight Simulator X Service Pack 1 FOTONICA version 1.2 Freespace 2 Freespace with Silent Threat Expansion From Dust Gadu-Gadu 10 Garry's Mod gedit 2.30.1 Google Chrome Grand Theft Auto IV HandBrake 0.9.5 Hard Reset High-Definition Video Playback IrfanView (remove only) Java Auto Updater Java™ 6 Update 29 JDownloader 0.9 LAME v3.98.3 for Audacity League of Legends Left 4 Dead 2 LogMeIn Hamachi Magic The Gathering - Duels of the Planeswalkers 2012 Malwarebytes' Anti-Malware version 1.51.2.1300 ManiaPlanet Microsoft .NET Framework 1.1 Microsoft .NET Framework 4 Multi-Targeting Pack Microsoft Application Error Reporting Microsoft Flight Simulator X Microsoft Flight Simulator X Service Pack 1 Microsoft Flight Simulator X: Acceleration Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft Silverlight Microsoft SQL Server Compact 3.5 SP2 ENU Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft XNA Framework Redistributable 3.1 Microsoft XNA Framework Redistributable 4.0 Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFCLOC_x86 Might and Magic: Clash of Heroes Miners4k Mozilla Firefox 5.0 (x86 en-GB) Mp3tag v2.49 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK Nero 10 Menu TemplatePack Basic Nero 10 Movie ThemePack Basic Nero BackItUp 10 Nero Burning ROM 10 Nero BurnRights 10 Nero Control Center 10 Nero Core Components 10 Nero CoverDesigner 10 Nero DiscSpeed 10 Nero Dolby Files 10 Nero Express 10 Nero InfoTool 10 Nero Kwik Media Nero Multimedia Suite 10 Nero Recode 10 Nero RescueAgent 10 Nero SoundTrax 10 Nero StartSmart 10 Nero Update Nero Vision 10 Nero WaveEditor 10 NVIDIA PhysX NVIDIA Stereoscopic 3D Driver Oblivion Oblivion - Horse Armor Pack Oblivion - Knights of the Nine Oblivion - Mehrunes Razor Oblivion - Orrery Oblivion - Spell Tomes Oblivion - Thieves Den Oblivion - Vile Lair Oblivion - Wizard's Tower Octoshape add-in for Adobe Flash Player OnLive OpenAL Pando Media Booster PC Probe II PDF Settings CS5 PowerISO PSPad editor PunkBuster Services QuickTime Realtek High Definition Audio Driver Rock of Ages SanDiskSecureAccess_Manager.exe Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Sentinel System Driver Skype Toolbars Skype™ 5.5 Sony Ericsson PC Companion 2.01.192 Sony Ericsson Update Engine Sony Ericsson Update Service Spotify Steam Steam Engine Simulator Stronghold 3 System Requirements Lab CYRI System Requirements Lab for Intel Tag - IGF Professional 2008 Team Fortress 2 TeamViewer 6 Terraria TES Construction Set TmUnitedForever TomTom HOME 2.8.1.2218 TomTom HOME Visual Studio Merge Modules tools-freebsd tools-linux tools-netware tools-solaris tools-windows tools-winPre2k TrackMania Nations Forever Turbo Key Twierdza Krzy¿owiec (Warchest) Twierdza Warchest Ubisoft Game Launcher Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) VMware Workstation Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Messenger Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Media Player Firefox Plugin WinX DVD Ripper Platinum 6.5.0 . ==== Event Viewer Messages From Past Week ======== . 3 is not a valid Win32 application. 24/11/2011 18:19:07, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: TfFsMon TFSysMon 24/11/2011 18:18:51, Error: Service Control Manager [7000] - The Sentinel service failed to start due to the following error: This driver has been blocked from loading 24/11/2011 18:18:51, Error: Application Popup [1060] - \SystemRoot\SysWow64\Drivers\SENTINEL.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. 24/11/2011 18:17:16, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 24/11/2011 18:16:45, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Run the configured recovery program) after the unexpected termination of the VMware Workstation Server service, but this action failed with the following error: 24/11/2011 18:16:18, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. 24/11/2011 18:15:44, Error: Service Control Manager [7031] - The VMware Workstation Server service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Run the configured recovery program. 24/11/2011 18:14:39, Error: Service Control Manager [7031] - The VMware Workstation Server service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 24/11/2011 18:10:26, Error: Service Control Manager [7034] - The ASUS System Control Service service terminated unexpectedly. It has done this 1 time(s). 24/11/2011 18:10:26, Error: Service Control Manager [7031] - The VMware Workstation Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 24/11/2011 18:09:55, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file. 24/11/2011 15:50:55, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143. 24/11/2011 15:47:04, Error: Service Control Manager [7001] - The Windows Firewall service depends on the Windows Firewall Authorization Driver service which failed to start because of the following error: Cannot create a file when that file already exists. 24/11/2011 15:47:04, Error: Service Control Manager [7000] - The Windows Firewall Authorization Driver service failed to start due to the following error: Cannot create a file when that file already exists. 22/11/2011 17:42:14, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 22/11/2011 16:13:49, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004 21/11/2011 11:36:50, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the VMware Workstation Server service to connect. 21/11/2011 11:36:50, Error: Service Control Manager [7000] - The VMware Workstation Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 19/11/2011 13:29:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F} 19/11/2011 13:29:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 19/11/2011 13:28:52, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 19/11/2011 13:28:51, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. 19/11/2011 13:28:51, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 19/11/2011 13:28:48, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 19/11/2011 13:28:37, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 19/11/2011 13:28:31, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AsIO AsUpIO CBDisk discache ehdrv MDFSYSNT SCDEmu spldr TfFsMon TFSysMon VBoxDrv VBoxUSBMon vmm Wanarpv6 19/11/2011 13:02:51, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000024 (0x00000000001904fb, 0xfffff88007f3a1d0, 0xfffff88007f3a270, 0xfffff8000210f590). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 111911-15397-01. . ==== End Of File ===========================
Sorry, seems that a reboot solved the previous issue with the apps not launching. Looks like all the problems are gone, from an intermediate user's point of view. Hosts file is back too.
Hi again,

A few more steps left to take.

Uninstall vulnerable Flash versions by following instructions here. Fresh version can be obtained here.

* Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is UNchecked and the option Scan unwanted applications is checkmarked.
  • Click Scan
  • Wait for the scan to finish.


Post back its report & a fresh dds.txt log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI