This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet randomly disconnects. [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Edit by paws: topic moved from Windows forum…(no reply made)

Hi,

I am having problems keeping my computer connected to the network/internet. I connect via my HTC Evo and use usb tethering. I never had a problem with it before, but last week it started acting up. So my internet works great on PS and I connect via router. So I eliminated it being my modem, router or any type of connection. I researched this a little and created a hijackthis
report. Malewarebytes reports no maleware. I just uninstalled Norton 360 because I though it was that, but that detected no threats.

I did make a few registry changes awhile ago, because my ps3 can't see my pc on network. Is there a way to restore my registry in system restore console?

Please, someone help me! It's driving me nuts.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:38:47 AM, on 11/29/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\GamersFirst\LIVE!\Live.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: TVersitybar Toolbar - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\prxtbTVer.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo0.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: TVersitybar - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\prxtbTVer.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Updater For XFIN_PORTAL - {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - C:\Program Files (x86)\xfin_portal\auxi\comcastAu.dll
O2 - BHO: uTorrentBar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo0.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: RebateRobot - {FA3FEDF6-1A34-4076-9F25-A26A2DE6A401} - C:\Program Files\RebateRobot\RebateRobot.dll
O3 - Toolbar: TVersitybar Toolbar - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files (x86)\TVersitybar\prxtbTVer.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo0.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [XFastUsb] C:\Program Files (x86)\XFastUsb\XFastUsb.exe
O4 - HKCU\..\Run: [ComcastAntispyClient] "C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Desura] C:\Program Files (x86)\Desura\desura.exe -autostart
O4 - HKCU\..\Run: [Google Update] "C:\Users\Dru\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Pando Media Booster] "C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: GamersFirst LIVE!.lnk = C:\Program Files (x86)\GamersFirst\LIVE!\Live.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E7DA7F8D-27AB-4EE9-8FC0-3FEC9ECFE758} (DynamicWebTwain Class) - https://www.benefitscalwin.org/DynamicWebTWAIN.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AMD FusionUtility Service - Advanced Micro Devices, Inc. - C:\Program Files (x86)\AMD\Fusion Utility for Desktop\FusionUtility2Service.exe
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files (x86)\AMD\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: Comcast AntiSpyware (AntiSpywareService) - Unknown owner - C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
O23 - Service: AODService - Unknown owner - C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe
O23 - Service: Desura Install Service - Desura Pty Ltd - C:\Program Files (x86)\Common Files\Desura\desura_service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PhoneMyPC_Helper - SoftwareForMe Inc - C:\Program Files\SoftwareForMe Inc\PhoneMyPC\PhoneMyPC_Helper.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PS3 Media Server - Tanuki Software, Ltd. - C:\Program Files (x86)\PS3 Media Server\win32\service\wrapper.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\RpcAgentSrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TVersity Media Server (TVersityMediaServer) - Unknown owner - C:\ProgramData\TVersity\Media Server\MediaServer.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: Windows Activation Technologies Service (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 9934 bytes
Here is my ComboFix report. ComboFix 11-11-29.04 - Dru 11/29/2011 9:53.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8188.5700 [GMT -8:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Dru\AppData\Roaming\vso_ts_preview.xml c:\windows\SysWow64\logs c:\windows\SysWow64\logs\debug.txt c:\windows\SysWow64\Settings c:\windows\TEMP\jna3272505889337828190.dll . . ((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-29 ))))))))))))))))))))))))))))))) . . 2011-11-29 17:57 . 2011-11-29 17:57 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-11-29 17:14 . 2011-11-29 17:14 ——– d—–w- c:\program files (x86)\Trend Micro 2011-11-29 11:00 . 2011-10-07 04:16 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6FF7F844-B70F-4665-9798-6FE880686577}\mpengine.dll 2011-11-29 00:03 . 2011-11-29 00:03 272448 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2011-11-28 21:02 . 2011-11-29 00:02 ——– d—–w- c:\users\Dru 2011-11-28 21:01 . 2011-11-28 21:01 0 —-a-w- c:\windows\ativpsrm.bin 2011-11-28 20:59 . 2011-11-28 20:59 ——– d—–w- c:\program files\Realtek 2011-11-28 20:59 . 2011-11-28 20:59 ——– d—–w- c:\windows\SysWow64\RTCOM 2011-11-28 20:56 . 2011-11-29 00:02 ——– d—–w- c:\windows\Panther 2011-11-28 20:35 . 2011-11-28 21:49 ——– d—–w- C:\$WINDOWS.~Q 2011-11-28 20:25 . 2011-11-28 20:31 ——– d—–w- C:\$INPLACE.~TR 2011-11-28 19:20 . 2011-11-28 21:05 ——– d—–w- c:\program files\Common Files\Little Registry Cleaner 2011-11-28 19:10 . 2011-11-28 19:10 ——– d—–w- C:\de07b437b20198d6d1e8fa4c02f8e3 2011-11-28 19:09 . 2011-11-28 21:16 ——– d—–w- c:\program files (x86)\Little Registry Cleaner 2011-11-28 19:09 . 2011-11-28 21:05 ——– d—–w- c:\program files\RebateRobot 2011-11-27 19:15 . 2011-08-17 20:44 53376 —-a-w- c:\windows\system32\drivers\usbfilter.sys 2011-11-27 19:14 . 2011-11-28 21:09 ——– d—–w- c:\program files (x86)\AMD 2011-11-27 19:11 . 2011-11-28 21:05 ——– d—–w- c:\program files\SiSoftware 2011-11-27 19:10 . 2011-11-28 21:19 ——– d—–w- c:\programdata\ATI 2011-11-26 22:06 . 2011-11-28 21:20 ——– d—–w- c:\windows\system32\appmgmt 2011-11-26 16:25 . 2005-11-14 07:19 5632 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe 2011-11-26 16:22 . 2011-11-26 16:22 ——– d—–w- C:\realkte2 2011-11-26 15:57 . 2011-11-26 15:57 ——– d—–w- C:\bios 2011-11-26 03:16 . 2011-11-28 21:16 ——– d—–w- c:\program files (x86)\Microsoft Silverlight 2011-11-26 02:48 . 2011-11-28 21:09 ——– d—–w- c:\program files (x86)\AMD APP 2011-11-25 15:06 . 2011-11-25 15:06 10497024 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2011-11-25 14:26 . 2011-11-25 14:26 24887808 —-a-w- c:\windows\system32\atio6axx.dll 2011-11-25 14:06 . 2011-11-25 14:06 18829312 —-a-w- c:\windows\SysWow64\atioglxx.dll 2011-11-25 14:04 . 2011-11-25 14:04 159744 —-a-w- c:\windows\system32\atiapfxx.exe 2011-11-25 14:04 . 2011-11-25 14:04 749568 —-a-w- c:\windows\SysWow64\aticfx32.dll 2011-11-25 14:03 . 2011-11-25 14:03 893440 —-a-w- c:\windows\system32\aticfx64.dll 2011-11-25 14:00 . 2011-11-25 14:00 466944 —-a-w- c:\windows\system32\ATIDEMGX.dll 2011-11-25 14:00 . 2011-11-25 14:00 517120 —-a-w- c:\windows\system32\atieclxx.exe 2011-11-25 14:00 . 2011-11-25 14:00 204288 —-a-w- c:\windows\system32\atiesrxx.exe 2011-11-25 13:59 . 2011-11-25 13:59 120320 —-a-w- c:\windows\system32\atitmm64.dll 2011-11-25 13:58 . 2011-11-25 13:58 423424 —-a-w- c:\windows\system32\atipdl64.dll 2011-11-25 13:58 . 2011-11-25 13:58 356352 —-a-w- c:\windows\SysWow64\atipdlxx.dll 2011-11-25 13:58 . 2011-11-25 13:58 278528 —-a-w- c:\windows\SysWow64\Oemdspif.dll 2011-11-25 13:58 . 2011-11-25 13:58 21504 —-a-w- c:\windows\system32\atimuixx.dll 2011-11-25 13:58 . 2011-11-25 13:58 59392 —-a-w- c:\windows\system32\atiedu64.dll 2011-11-25 13:58 . 2011-11-25 13:58 43520 —-a-w- c:\windows\SysWow64\ati2edxx.dll 2011-11-25 13:55 . 2011-11-25 13:55 4327936 —-a-w- c:\windows\SysWow64\atidxx32.dll 2011-11-25 13:50 . 2011-11-25 13:50 1113088 —-a-w- c:\windows\system32\atiumd6v.dll 2011-11-25 13:50 . 2011-11-25 13:50 1828864 —-a-w- c:\windows\SysWow64\atiumdmv.dll 2011-11-25 13:49 . 2011-11-25 13:49 4044288 —-a-w- c:\windows\system32\atiumd6a.dll 2011-11-25 13:46 . 2011-11-25 13:46 5079552 —-a-w- c:\windows\system32\atidxx64.dll 2011-11-25 13:40 . 2011-11-25 13:40 51200 —-a-w- c:\windows\system32\aticalrt64.dll 2011-11-25 13:40 . 2011-11-25 13:40 46080 —-a-w- c:\windows\SysWow64\aticalrt.dll 2011-11-25 13:40 . 2011-11-25 13:40 44544 —-a-w- c:\windows\system32\aticalcl64.dll 2011-11-25 13:40 . 2011-11-25 13:40 44032 —-a-w- c:\windows\SysWow64\aticalcl.dll 2011-11-25 13:40 . 2011-11-25 13:40 9978880 —-a-w- c:\windows\system32\aticaldd64.dll 2011-11-25 13:39 . 2011-11-25 13:39 4189184 —-a-w- c:\windows\SysWow64\atiumdva.dll 2011-11-25 13:36 . 2011-11-25 13:36 8449024 —-a-w- c:\windows\SysWow64\aticaldd.dll 2011-11-25 13:36 . 2011-11-25 13:36 4356096 —-a-w- c:\windows\SysWow64\atiumdag.dll 2011-11-25 13:30 . 2011-11-25 13:30 5512704 —-a-w- c:\windows\system32\atiumd64.dll 2011-11-25 13:30 . 2011-11-25 13:30 58880 —-a-w- c:\windows\system32\coinst.dll 2011-11-25 13:23 . 2011-11-25 13:23 486912 —-a-w- c:\windows\system32\atiadlxx.dll 2011-11-25 13:23 . 2011-11-25 13:23 339968 —-a-w- c:\windows\SysWow64\atiadlxy.dll 2011-11-25 13:23 . 2011-11-25 13:23 17408 —-a-w- c:\windows\system32\atig6pxx.dll 2011-11-25 13:23 . 2011-11-25 13:23 14336 —-a-w- c:\windows\SysWow64\atiglpxx.dll 2011-11-25 13:23 . 2011-11-25 13:23 14336 —-a-w- c:\windows\system32\atiglpxx.dll 2011-11-25 13:23 . 2011-11-25 13:23 39936 —-a-w- c:\windows\system32\atig6txx.dll 2011-11-25 13:23 . 2011-11-25 13:23 32768 —-a-w- c:\windows\SysWow64\atigktxx.dll 2011-11-25 13:23 . 2011-11-25 13:23 326656 —-a-w- c:\windows\system32\drivers\atikmpag.sys 2011-11-25 13:22 . 2011-11-25 13:22 40960 —-a-w- c:\windows\system32\atiuxp64.dll 2011-11-25 13:22 . 2011-11-25 13:22 31744 —-a-w- c:\windows\SysWow64\atiuxpag.dll 2011-11-25 13:22 . 2011-11-25 13:22 38912 —-a-w- c:\windows\system32\atiu9p64.dll 2011-11-25 13:22 . 2011-11-25 13:22 29184 —-a-w- c:\windows\SysWow64\atiu9pag.dll 2011-11-25 13:21 . 2011-11-25 13:21 54784 —-a-w- c:\windows\system32\atimpc64.dll 2011-11-25 13:21 . 2011-11-25 13:21 54784 —-a-w- c:\windows\system32\amdpcom64.dll 2011-11-25 13:21 . 2011-11-25 13:21 53760 —-a-w- c:\windows\SysWow64\atimpc32.dll 2011-11-25 13:21 . 2011-11-25 13:21 53760 —-a-w- c:\windows\SysWow64\amdpcom32.dll 2011-11-25 13:21 . 2011-11-25 13:21 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2011-11-20 19:03 . 2011-11-28 21:19 ——– d—–w- c:\program files (x86)\Xiph.Org 2011-11-20 19:03 . 2011-11-28 21:18 ——– d—–w- c:\program files (x86)\TVersity Codec Pack 2011-11-20 19:02 . 2011-11-28 21:18 ——– d—–w- c:\program files (x86)\TVersitybar 2011-11-20 19:02 . 2011-11-28 21:19 ——– d—–w- c:\programdata\TVersity 2011-11-19 23:41 . 2011-11-28 21:18 ——– d—–w- c:\program files (x86)\THQ 2011-11-19 00:52 . 2011-11-19 00:52 66560 —-a-w- c:\windows\system32\OpenVideo64.dll 2011-11-19 00:52 . 2011-11-19 00:52 56832 —-a-w- c:\windows\SysWow64\OpenVideo.dll 2011-11-19 00:52 . 2011-11-19 00:52 66560 —-a-w- c:\windows\system32\OVDecoder64.dll 2011-11-19 00:52 . 2011-11-19 00:52 56832 —-a-w- c:\windows\SysWow64\OVDecoder.dll 2011-11-19 00:52 . 2011-11-19 00:52 16991744 —-a-w- c:\windows\system32\amdocl64.dll 2011-11-19 00:51 . 2011-11-19 00:51 13950464 —-a-w- c:\windows\SysWow64\amdocl.dll 2011-11-16 01:48 . 2011-11-16 01:48 2309120 ——w- c:\windows\system32\jscript9.dll 2011-11-16 01:48 . 2011-11-16 01:48 1798144 ——w- c:\windows\SysWow64\jscript9.dll 2011-11-16 01:48 . 2011-11-16 01:48 135168 ——w- c:\windows\system32\IEAdvpack.dll 2011-11-16 01:48 . 2011-11-16 01:48 110592 ——w- c:\windows\SysWow64\IEAdvpack.dll 2011-11-15 23:22 . 2011-11-15 23:22 ——– d—–w- C:\Realtek2 2011-11-15 23:16 . 2011-11-28 21:12 ——– d—–w- c:\program files (x86)\Common Files\Desura 2011-11-15 23:16 . 2011-11-28 21:19 ——– d—–w- c:\programdata\Desura 2011-11-15 23:16 . 2011-11-28 21:12 ——– d—–w- c:\program files (x86)\Desura 2011-11-15 22:47 . 2011-11-28 21:16 ——– d—–w- c:\program files (x86)\Square Enix 2011-11-15 16:20 . 2011-11-15 16:20 627600 —-a-w- c:\windows\system32\deployJava1.dll 2011-11-15 16:18 . 2011-11-28 21:05 ——– d—–w- c:\program files\Java 2011-11-13 09:20 . 2011-11-13 09:20 ——– d—–w- C:\N360_BACKUP 2011-11-13 06:53 . 2011-11-26 18:43 ——– d—–w- c:\program files (x86)\Common Files\Symantec Shared 2011-11-13 06:48 . 2011-11-28 21:16 ——– d—–w- c:\program files (x86)\NVIDIA Corporation 2011-11-13 03:21 . 2011-11-28 21:20 ——– dc—-w- c:\windows\system32\DRVSTORE 2011-11-13 03:21 . 2011-07-06 20:44 34288 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-11-13 03:13 . 2011-11-28 21:19 ——– d—–w- c:\programdata\Norton 2011-11-13 02:10 . 2011-11-28 21:19 ——– d—–w- c:\programdata\IsolatedStorage 2011-11-13 02:09 . 2011-11-28 21:12 ——– d—–w- c:\program files (x86)\Common Files\scanner 2011-11-13 02:09 . 2011-11-28 21:12 ——– d—–w- c:\program files (x86)\comcasttb 2011-11-13 02:09 . 2011-11-28 21:10 ——– d—–w- c:\program files (x86)\CA 2011-11-13 02:08 . 2011-11-28 21:19 ——– d—–w- c:\program files (x86)\xfin_portal 2011-11-13 02:08 . 2011-11-28 21:12 ——– d—–w- c:\program files (x86)\Constant Guard Protection Suite 2011-11-13 02:08 . 2011-11-28 21:19 ——– d—–w- c:\programdata\White Sky, Inc 2011-11-12 14:56 . 2011-11-28 21:18 ——– d—–w- c:\program files (x86)\The Elder Scrolls V Skyrim 2011-11-10 19:18 . 2011-11-28 21:12 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-11-10 19:16 . 2011-11-10 19:16 544656 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-11-10 19:16 . 2011-11-28 21:14 ——– d—–w- c:\program files (x86)\Java 2011-11-10 19:14 . 2011-11-28 21:19 ——– d—–w- c:\programdata\PMS 2011-11-10 19:14 . 2011-11-29 17:06 ——– d—–w- c:\program files (x86)\PS3 Media Server 2011-11-10 04:08 . 2011-11-10 04:08 ——– d—–w- C:\ATI 2011-11-09 21:37 . 2011-11-28 21:19 ——– d—–w- c:\programdata\Malwarebytes 2011-11-09 21:37 . 2011-11-28 21:16 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-11-09 21:37 . 2011-09-01 01:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-15 15:24 . 2011-10-17 01:51 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-10-22 18:51 . 2011-10-22 18:51 31808 —-a-w- c:\windows\system32\drivers\FNETTBOH_305.SYS 2011-10-22 16:25 . 2011-10-17 01:25 122904 —-a-w- c:\windows\system32\OpenAL32.dll 2011-10-22 16:24 . 2011-10-17 01:25 109080 —-a-w- c:\windows\SysWow64\OpenAL32.dll 2011-10-18 03:59 . 2011-10-17 01:25 466520 —-a-w- c:\windows\system32\wrap_oal.dll 2011-10-18 03:59 . 2011-10-17 01:25 445016 —-a-w- c:\windows\SysWow64\wrap_oal.dll 2011-10-17 18:04 . 2011-10-17 18:04 526392 —-a-w- c:\windows\system32\drivers\sptd.sys 2011-10-17 01:22 . 2011-10-17 01:22 15936 —-a-w- c:\windows\system32\drivers\FNETURPX.SYS 2011-10-07 05:29 . 2011-10-07 05:29 51200 —-a-w- c:\windows\system32\OpenCL.dll 2011-10-07 05:29 . 2011-10-07 05:29 43520 —-a-w- c:\windows\SysWow64\OpenCL.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{66bd2442-241b-44cd-8c7a-b51037053cdb}"= "c:\program files (x86)\TVersitybar\prxtbTVer.dll" [2011-05-09 176936] "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{66bd2442-241b-44cd-8c7a-b51037053cdb}] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{66bd2442-241b-44cd-8c7a-b51037053cdb}] 2011-05-09 09:49 176936 —-a-w- c:\program files (x86)\TVersitybar\prxtbTVer.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] 2011-05-09 09:49 176936 —-a-w- c:\program files (x86)\uTorrentBar\prxtbuTo0.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FA3FEDF6-1A34-4076-9F25-A26A2DE6A401}] 2011-11-18 09:54 88576 —-a-w- c:\program files\RebateRobot\RebateRobot.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{66bd2442-241b-44cd-8c7a-b51037053cdb}"= "c:\program files (x86)\TVersitybar\prxtbTVer.dll" [2011-05-09 176936] "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{66bd2442-241b-44cd-8c7a-b51037053cdb}] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ComcastAntispyClient"="c:\program files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" [2009-08-19 1589208] "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2011-03-17 842048] "Desura"="c:\program files (x86)\Desura\desura.exe" [2011-11-15 2529608] "Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-10-17 3071384] "Steam"="c:\program files (x86)\Steam\steam.exe" [2011-10-17 1242448] "uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-10-20 641400] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-08-22 593920] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-11-25 343168] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136] "XFastUsb"="c:\program files (x86)\XFastUsb\XFastUsb.exe" [2011-10-17 4942336] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ GamersFirst LIVE!.lnk - c:\program files (x86)\GamersFirst\LIVE!\Live.exe [2011-8-15 2589808] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "ConsentPromptBehaviorAdmin"= 0 (0x0) "EnableLUA"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 AMD FusionUtility Service;AMD FusionUtility Service;c:\program files (x86)\AMD\Fusion Utility for Desktop\FusionUtility2Service.exe [2010-04-15 275832] R2 AODService;AODService;c:\program files (x86)\AMD\OverDrive\AODAssist.exe [2011-10-14 136616] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 PhoneMyPC_Helper;PhoneMyPC_Helper;c:\program files\SoftwareForMe Inc\PhoneMyPC\PhoneMyPC_Helper.exe [2011-07-15 31232] R2 PS3 Media Server;PS3 Media Server;c:\program files (x86)\PS3 Media Server\win32\service\wrapper.exe [2011-05-17 366872] R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe [2011-11-15 131912] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [x] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\RpcAgentSrv.exe [2008-11-06 93848] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-11-25 361984] S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files (x86)\AMD\Reservation Manager\AMD Reservation Manager.exe [2010-04-15 140160] S2 AntiSpywareService;Comcast AntiSpyware;c:\program files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [2009-06-17 616408] S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2011-06-24 55424] S2 AODDriver4.1;AODDriver4.1;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [2011-10-14 55936] S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-08-13 87040] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-11-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-172915268-861668825-1451973386-1000Core.job - c:\users\Dru\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-24 21:27] . 2011-11-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-172915268-861668825-1451973386-1000UA.job - c:\users\Dru\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-24 21:27] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA3FEDF6-1A34-4076-9F25-A26A2DE6A401}] 2011-11-18 09:54 105472 —-a-w- c:\program files\RebateRobot\RebateRobot-x64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-26 12681320] "RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 825184] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.42.129 DPF: {E7DA7F8D-27AB-4EE9-8FC0-3FEC9ECFE758} - hxxps://www.benefitscalwin.org/DynamicWebTWAIN.cab FF - ProfilePath - c:\users\Dru\AppData\Roaming\Mozilla\Firefox\Profiles\cjfdp991.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2548838&SearchSource=3&q={searchTerms} FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . WebBrowser-{66BD2442-241B-44CD-8C7A-B51037053CDB} - (no file) WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\programdata\TVersity\Media Server\MediaServer.exe c:\program files (x86)\DAEMON Tools Pro\DTShellHlp.exe . ************************************************************************** . Completion time: 2011-11-29 10:05:40 - machine was rebooted ComboFix-quarantined-files.txt 2011-11-29 18:05 . Pre-Run: 1,182,128,373,760 bytes free Post-Run: 1,182,053,380,096 bytes free . - - End Of File - - 9EFB631BC97AAF02497D39DD9E26EA79
Hello, I Am Alander :)

Welcome to the Malware Removal forums.

I would be glad to take a look at your log and help you with solving any malware problems.

DDS logs can take a while to research so please be patient while I work on your log and I will post back here with any recommendations.

As I am still training, everything that I post to you, must be checked by an Admin or Moderator.

Thus, there may be a tiny bit of a delay between posts. While it shouldn't be too long, you can be assured you will get the best possible advice.

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download DDS by sUBs from one of the links below, save it to your Desktop (Note: It must be in this location).
  • Link 1
  • Link 2
Please disable any anti-malware program that will block scripts from running before running DDS.

  • Right-Click on dds.scr And select " Run as administrator "… and a command window will appear. This is normal.
  • Shortly after two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply

PLEASE DO NOT run any other tools without supervision unless I tell you to do
3 Day Response
Hi…
It has been 2 days since my last post to you.
  • Do you still need help with this problem?
  • Do you need more time?
  • Are you having problems understanding or following my instructions?
Just let me know what's going on otherwise…
After 24 hrs., if you have not replied to this thread… it will be closed!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI