aristos
Topic Starter
I will try to keep this brief.
I brought a copy of Norton with my HP Pavilion g6 laptop in September. The laptop came with a trial version of a more expensive Norton, so I let it run it's course with the intent of installing the version I bought. This was dumb, because I should've known that I'd procrastinate when the trial version ran out. Norton kept warning me that I did not have any protection, and being an arrogant person, I ignored the warnings and made fun of them mentally.
So yesterday, a few times when I tried using google, I clicked on a search result and was led to an ad thing. I disregarded it, even though this is obviously a highly unusual thing. Then today, I tried to use the internet, and I couldn't get on. I said, "Oh, well since I can't do that, good time to install Norton." Installed Norton, started a full system scan (which ended up detecting and removing 4 trojan horse things). Called the computer people who work at the university I'm dorming at and asked why I couldn't get on the internet, and long story short: I have a virus. I went in with the laptop and they ran TDSSkiller and Fix TDSS and both didn't find anything. They then ran live update on my Norton (which was 363 days behind in updates…) and pretty much told me I could go and that they would restore connectivity to my port. So I made sure that the Norton was updated, got home, started running TDSSkiller and Fix TDSS again on my own to try and fix things. When Fix TDSS restarted the computer, it wouldn't start up again. So I told the computer to run Startup repair and it restored the computer to an earlier "checkpoint" (?) or whatever and I thought this fixed everything and went about my merry way, facebooking and emailing.
Then Norton started giving me more popups telling me "Threat requiring manual removal detected: System Inected: Tidserv Activity", and sometimes will include a "2" at the end. So I ran TDSSkiller again, didn't detect anything. Renamed the file as was suggested on Yahoo Answers, didn't detect anything. Fix TDSS didn't detect anything. Norton Power Eraser didn't detect anything (after restarting the computer as the program suggested to include a search for rootkits).
I am fairly stumped, at this point, and any assistance would be fantastic. I am pretty sure that if the virus is still there (as I type this a popup from norton is telling me that it is..) it is only a matter of time before they shut down my port again. And the obvious badness of having a virus too.
OLT Scan Results:
OTL logfile created on: 11/29/2011 6:30:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nikholas\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 2.16 Gb Available Physical Memory | 56.87% Memory free
7.60 Gb Paging File | 5.90 Gb Available in Paging File | 77.59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450.78 Gb Total Space | 352.24 Gb Free Space | 78.14% Space Free | Partition Type: NTFS
Drive D: | 14.69 Gb Total Space | 1.63 Gb Free Space | 11.10% Space Free | Partition Type: NTFS
Drive E: | 590.19 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 99.02 Mb Total Space | 84.90 Mb Free Space | 85.73% Space Free | Partition Type: FAT32
Computer Name: JARVIS | User Name: Nikholas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/29 18:20:52 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nikholas\Downloads\OTL.exe
PRC - [2011/09/05 09:04:54 | 000,064,952 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/09/01 16:42:06 | 024,183,152 | —- | M] (Dropbox, Inc.) – C:\Users\Nikholas\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/08/23 20:20:18 | 000,887,976 | —- | M] (Ask) – C:\Program Files (x86)\Ask.com\Updater\Updater.exe
PRC - [2011/08/14 11:02:58 | 021,975,120 | —- | M] (ooVoo LLC) – C:\Program Files (x86)\ooVoo\ooVoo.exe
PRC - [2011/08/04 15:57:48 | 000,789,088 | —- | M] (Jackpot Rewards) – C:\Program Files (x86)\DealRunner\DealRunner.exe
PRC - [2011/07/27 03:06:44 | 000,267,488 | —- | M] () – C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe
PRC - [2011/07/05 16:02:58 | 000,227,384 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2011/06/14 13:29:22 | 000,587,320 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2011/06/14 13:29:22 | 000,026,680 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2011/06/13 15:47:12 | 000,336,440 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
PRC - [2011/04/29 23:32:54 | 000,013,592 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011/04/29 23:32:50 | 000,284,440 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2011/04/16 16:45:11 | 000,130,008 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton AntiVirus\Norton AntiVirus\Engine\18.6.0.29\ccsvchst.exe
PRC - [2011/03/22 10:42:40 | 000,136,488 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/02/15 14:48:52 | 001,071,160 | —- | M] (Hewlett-Packard Development Company L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
PRC - [2010/11/26 06:09:12 | 000,399,344 | —- | M] (Roxio) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/09/16 10:13:14 | 002,538,520 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/09/16 10:13:06 | 000,325,656 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/09/14 04:45:56 | 000,219,496 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010/09/14 04:45:44 | 000,508,264 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/04/23 11:00:00 | 000,514,232 | —- | M] (EasyBits Software AS) – C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/04/23 11:00:00 | 000,514,232 | —- | M] (EasyBits Software AS) – C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/01/15 04:49:20 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2010/01/14 18:16:16 | 000,345,600 | —- | M] (Pharos Systems International) – C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
PRC - [2009/07/13 17:14:28 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\PING.EXE
PRC - [2009/04/23 05:29:18 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2009/04/23 05:29:14 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/18 19:41:09 | 011,819,520 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\8e7909ef6b5f953d49244c6b9f5f5100\System.Web.ni.dll
MOD - [2011/10/18 19:41:02 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b2622080e047040fa044dd21a04ff10d\System.Runtime.Remoting.ni.dll
MOD - [2011/10/18 19:41:02 | 000,014,336 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\33cecc66284ef59208b639ec72b0f565\IAStorCommon.ni.dll
MOD - [2011/10/18 19:41:01 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll
MOD - [2011/10/18 19:40:58 | 000,492,544 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\e8339b699235ebf2f904ccb8383de342\IAStorUtil.ni.dll
MOD - [2011/10/18 19:40:56 | 012,433,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll
MOD - [2011/10/18 19:40:48 | 001,587,200 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll
MOD - [2011/10/18 19:40:31 | 005,453,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/10/18 19:40:27 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/10/18 19:40:25 | 007,963,648 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/10/18 19:40:19 | 011,490,304 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/05/26 12:42:00 | 000,067,872 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2010/11/20 19:24:09 | 000,232,448 | —- | M] () – \\?\globalroot\systemroot\syswow64\mswsock.DLL
MOD - [2010/11/20 19:24:09 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\syswow64\mswsock.dll
MOD - [2009/04/16 12:02:16 | 000,970,752 | —- | M] () – C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/09/12 08:48:34 | 000,301,568 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [2011/02/16 21:47:28 | 000,682,040 | —- | M] (Hewlett-Packard) [Auto | Stopped] – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe – (HPAuto)
SRV:64bit: - [2010/10/11 01:48:14 | 000,346,168 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe – (HPClientSvc)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/09/05 09:04:54 | 000,064,952 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/07/27 03:06:44 | 000,267,488 | —- | M] () [Auto | Running] – C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe – (Updater Service for StartNow Toolbar)
SRV - [2011/07/05 16:02:58 | 000,227,384 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2011/06/21 14:57:34 | 000,085,560 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe – (HP Support Assistant Service)
SRV - [2011/06/14 13:29:22 | 000,026,680 | —- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe – (HPWMISVC)
SRV - [2011/04/29 23:32:54 | 000,013,592 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2011/04/16 16:45:11 | 000,130,008 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton AntiVirus\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe – (NAV)
SRV - [2011/04/14 14:47:38 | 000,103,336 | —- | M] (stumbleupon.com) [On_Demand | Stopped] – C:\Program Files (x86)\StumbleUpon\StumbleUponUpdateService.exe – (StumbleUponUpdateService)
SRV - [2011/03/07 16:43:30 | 002,375,168 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2011/03/01 20:23:36 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2011/02/15 14:48:52 | 001,071,160 | —- | M] (Hewlett-Packard Development Company L.P.) [On_Demand | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe – (hpCMSrv)
SRV - [2010/11/26 06:09:12 | 000,399,344 | —- | M] (Roxio) [Auto | Running] – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe – (RoxioNow Service)
SRV - [2010/10/12 09:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/09/16 10:13:14 | 002,538,520 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/09/16 10:13:06 | 000,325,656 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2010/09/14 04:45:56 | 000,219,496 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe – (sftvsa)
SRV - [2010/09/14 04:45:44 | 000,508,264 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe – (sftlist)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/01/15 04:49:20 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2010/01/14 18:16:16 | 000,345,600 | —- | M] (Pharos Systems International) [Auto | Running] – C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe – (Pharos Systems ComTaskMaster)
SRV - [2009/06/10 13:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/11/29 18:07:07 | 000,096,376 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\SMR210.SYS – (SMR210)
DRV:64bit: - [2011/11/29 17:36:25 | 000,174,200 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2011/09/12 08:50:51 | 000,533,096 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2011/09/12 08:48:34 | 000,528,384 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\stwrt64.sys – (STHDA)
DRV:64bit: - [2011/09/12 08:16:56 | 001,451,056 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2011/07/19 09:19:16 | 001,492,992 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\netr28x.sys – (netr28x)
DRV:64bit: - [2011/05/10 07:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/04/26 10:07:36 | 000,557,848 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2011/03/30 19:00:09 | 000,744,568 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtsp64.sys – (SRTSP)
DRV:64bit: - [2011/03/30 19:00:09 | 000,040,568 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtspx64.sys – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2011/03/21 16:39:49 | 000,382,584 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symnets.sys – (SymNetS)
DRV:64bit: - [2011/03/14 18:31:23 | 000,912,504 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symefa64.sys – (SymEFA)
DRV:64bit: - [2011/03/10 22:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/10 22:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/02/15 11:37:10 | 000,335,464 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsPStor.sys – (RSPCIESTOR)
DRV:64bit: - [2011/01/26 22:47:10 | 000,450,680 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symds64.sys – (SymDS)
DRV:64bit: - [2011/01/26 21:07:06 | 000,171,128 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\ironx64.sys – (SymIRON)
DRV:64bit: - [2011/01/07 17:42:34 | 012,262,688 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/11/20 19:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 19:23:47 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/11/20 19:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 19:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/15 00:28:16 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2010/09/14 04:45:52 | 000,022,376 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftvollh.sys – (Sftvol)
DRV:64bit: - [2010/09/14 04:45:50 | 000,025,960 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftredirlh.sys – (Sftredir)
DRV:64bit: - [2010/09/14 04:45:48 | 000,268,648 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftplaylh.sys – (Sftplay)
DRV:64bit: - [2010/09/14 04:45:44 | 000,760,168 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftfslh.sys – (Sftfs)
DRV:64bit: - [2010/07/28 08:13:50 | 000,031,088 | —- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\clwvd.sys – (clwvd)
DRV:64bit: - [2010/02/26 15:32:12 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/09/17 12:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 13:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 13:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 13:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 12:35:35 | 000,408,960 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nvm62x64.sys – (NVENETFD)
DRV:64bit: - [2009/06/10 12:34:38 | 001,311,232 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2011/11/29 17:35:59 | 002,048,632 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\VirusDefs\20111129.020\ex64.sys – (NAVEX15)
DRV - [2011/11/29 17:35:58 | 000,482,936 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2011/11/29 17:35:58 | 000,138,360 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2011/11/29 17:35:58 | 000,117,880 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\VirusDefs\20111129.020\eng64.sys – (NAVENG)
DRV - [2011/11/29 16:52:40 | 000,488,568 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\IPSDefs\20111129.030\IDSviA64.sys – (IDSVia64)
DRV - [2011/11/23 23:08:44 | 001,156,216 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\BASHDefs\20111123.001\BHDrvx64.sys – (BHDrvx64)
DRV - [2009/07/13 17:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=14196
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}"
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Nikholas\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\coFFPlgn_2011_7_3_6
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\IPSFFPlgn\ [2011/11/29 17:39:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/22 19:23:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/08/25 22:42:50 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Extensions
[2011/11/14 23:15:43 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions
[2011/11/14 23:15:42 | 000,000,000 | —D | M] (ShopToWin9) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\{46d606b0-a645-11df-981c-0800200c9a66}
[2011/10/11 03:05:52 | 000,000,000 | —D | M] (StartNow Toolbar) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2011/11/14 23:15:43 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/11/08 20:07:00 | 000,000,000 | —D | M] ("ooVoo toolbar, powered by Ask.com") – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\[removed]
[2011/11/14 23:15:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\{46d606b0-a645-11df-981c-0800200c9a66}\chrome\content\dca\core\extensionManager
[2011/07/29 21:02:18 | 000,002,333 | —- | M] () – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\searchplugins\askcom.xml
[2011/08/16 09:06:22 | 000,000,863 | —- | M] () – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\searchplugins\conduit.xml
[2011/08/25 22:42:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/22 19:23:49 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/02 23:12:42 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/22 19:23:49 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Nikholas\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Black Hole Sun = C:\Users\Nikholas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjflaldchiphekckakjglcfjiomhjobc\1_0\
CHR - Extension: StumbleUpon = C:\Users\Nikholas\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg\3.10.11.1_0\
Hosts file not found
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Shop to Win) - {0095C290-A428-4BDD-B98C-E0A116F1C702} - C:\Program Files (x86)\Shop to Win 9\Shop to Win 9.dll (Shop To Win, LLC)
O2 - BHO: (StumbleUpon Launcher) - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files (x86)\StumbleUpon\StumbleUponIEBar.dll (stumbleupon.com)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll File not found
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Norton AntiVirus\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (StartNow Toolbar Helper) - {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll ()
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (StumbleUpon Toolbar) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files (x86)\StumbleUpon\StumbleUponIEBar.dll (stumbleupon.com)
O3 - HKLM\..\Toolbar: (StartNow Toolbar) - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll File not found
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [StartNowToolbarHelper] "C:\Program Files (x86)\StartNow Toolbar\ToolbarHelper.exe" File not found
O4 - HKCU..\Run: [DealRunner] C:\Program Files (x86)\DealRunner\DealRunner.exe (Jackpot Rewards)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Nikholas\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe (ooVoo LLC)
O4 - Startup: C:\Users\Nikholas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Nikholas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Nikholas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage File not found
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage File not found
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{893EC908-EDE1-45D3-8BA5-FB8DFFBC9631}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8D276B82-01A2-4915-A127-12050761D0EB}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/04 13:24:23 | 000,000,175 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{bbb76687-cfaf-11e0-8d78-806e6f6e6963}\Shell\AutoRun\command - "" = E:\START.EXE – [2010/12/03 22:57:51 | 003,109,304 | R— | M] (Symantec Corporation)
O33 - MountPoints2\{bbb76687-cfaf-11e0-8d78-806e6f6e6963}\Shell\Install\Command - "" = E:\START.EXE – [2010/12/03 22:57:51 | 003,109,304 | R— | M] (Symantec Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/29 18:07:07 | 000,096,376 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SMR210.SYS
[2011/11/29 18:04:10 | 000,000,000 | —D | C] – C:\Users\Nikholas\AppData\Local\NPE
[2011/11/29 17:36:23 | 000,912,504 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symefa64.sys
[2011/11/29 17:36:23 | 000,744,568 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtsp64.sys
[2011/11/29 17:36:23 | 000,450,680 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symds64.sys
[2011/11/29 17:36:23 | 000,382,584 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symnets.sys
[2011/11/29 17:36:23 | 000,171,128 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\ironx64.sys
[2011/11/29 17:36:23 | 000,040,568 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtspx64.sys
[2011/11/29 17:36:12 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D
[2011/11/29 17:30:59 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NAVx64
[2011/11/29 12:16:41 | 000,000,000 | —D | C] – C:\Users\Nikholas\Desktop\New folder
[2011/11/29 10:57:21 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/11/29 10:56:05 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton AntiVirus
[2011/11/29 10:56:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton AntiVirus
[2011/11/29 10:52:35 | 000,000,000 | —D | C] – C:\ProgramData\PCSettings
[2011/11/24 12:13:33 | 000,000,000 | —D | C] – C:\Windows\system64
[2011/11/23 02:19:56 | 000,000,000 | —D | C] – C:\Users\Nikholas\AppData\Local\Microsoft Help
[2011/11/23 02:19:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/11/22 14:54:52 | 000,000,000 | —D | C] – C:\Users\Nikholas\Documents\Correspondence
[2011/11/20 15:18:28 | 000,000,000 | —D | C] – C:\Users\Nikholas\Documents\Other People's Work
[2011/11/19 23:16:38 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Samsung_USB_Drivers
[2011/11/19 23:16:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Samsung
[2011/11/02 13:32:35 | 000,000,000 | —D | C] – C:\Users\Nikholas\AppData\Roaming\ooVoo Details
[2011/11/02 13:32:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ask.com
[2011/11/02 13:31:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
[2011/11/02 13:31:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\ooVoo
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Users\Nikholas\Documents\*.tmp files -> C:\Users\Nikholas\Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/29 18:16:11 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/29 18:16:11 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/29 18:13:36 | 000,727,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/29 18:13:36 | 000,624,622 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/29 18:13:36 | 000,106,708 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/29 18:08:34 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/29 18:08:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/29 18:08:04 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2011/11/29 18:07:07 | 000,096,376 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SMR210.SYS
[2011/11/29 18:06:00 | 000,000,350 | —- | M] () – C:\Windows\tasks\At38.job
[2011/11/29 18:06:00 | 000,000,348 | —- | M] () – C:\Windows\tasks\At37.job
[2011/11/29 17:39:24 | 000,002,640 | —- | M] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/11/29 17:38:52 | 001,396,538 | —- | M] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\Cat.DB
[2011/11/29 17:36:25 | 000,174,200 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/11/29 17:36:25 | 000,007,488 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/11/29 17:36:25 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At8.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At6.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At42.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At40.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At36.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At32.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At30.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At28.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At22.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At20.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At18.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At16.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At14.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At12.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At10.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At9.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At7.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At5.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At41.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At39.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At35.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At33.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At31.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At29.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At27.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At21.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At19.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At17.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At15.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At13.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At11.job
[2011/11/29 17:11:29 | 000,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJARVIS$.job
[2011/11/26 23:06:00 | 000,000,350 | —- | M] () – C:\Windows\tasks\At48.job
[2011/11/26 23:06:00 | 000,000,348 | —- | M] () – C:\Windows\tasks\At47.job
[2011/11/26 22:46:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/26 22:41:26 | 000,000,940 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1339067313-137779846-2497530518-1000UA.job
[2011/11/26 16:57:40 | 000,000,350 | —- | M] () – C:\Windows\tasks\At34.job
[2011/11/26 16:57:40 | 000,000,350 | —- | M] () – C:\Windows\tasks\At26.job
[2011/11/26 16:57:40 | 000,000,350 | —- | M] () – C:\Windows\tasks\At24.job
[2011/11/26 16:57:40 | 000,000,348 | —- | M] () – C:\Windows\tasks\At25.job
[2011/11/26 16:57:40 | 000,000,348 | —- | M] () – C:\Windows\tasks\At23.job
[2011/11/26 06:52:41 | 000,000,350 | —- | M] () – C:\Windows\tasks\At4.job
[2011/11/26 06:52:41 | 000,000,348 | —- | M] () – C:\Windows\tasks\At3.job
[2011/11/26 00:06:00 | 000,000,350 | —- | M] () – C:\Windows\tasks\At2.job
[2011/11/26 00:06:00 | 000,000,348 | —- | M] () – C:\Windows\tasks\At1.job
[2011/11/25 22:08:39 | 000,000,350 | —- | M] () – C:\Windows\tasks\At46.job
[2011/11/25 22:08:39 | 000,000,348 | —- | M] () – C:\Windows\tasks\At45.job
[2011/11/25 21:06:00 | 000,000,350 | —- | M] () – C:\Windows\tasks\At44.job
[2011/11/25 21:06:00 | 000,000,348 | —- | M] () – C:\Windows\tasks\At43.job
[2011/11/25 16:25:22 | 000,000,112 | —- | M] () – C:\ProgramData\786trd8.dat
[2011/11/25 16:23:11 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\A6xErEJ.com.b
[2011/11/24 23:00:40 | 000,000,918 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1339067313-137779846-2497530518-1000Core.job
[2011/11/19 23:23:16 | 000,000,344 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForNikholas.job
[2011/11/18 23:46:53 | 000,002,268 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/11/11 06:50:44 | 001,397,596 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\Cat.DB
[2011/11/10 11:59:36 | 000,284,920 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/02 13:31:21 | 000,001,857 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Users\Nikholas\Documents\*.tmp files -> C:\Users\Nikholas\Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/29 17:38:35 | 001,396,538 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\Cat.DB
[2011/11/29 17:36:23 | 000,007,492 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\iron.cat
[2011/11/29 17:36:23 | 000,007,462 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtspx64.cat
[2011/11/29 17:36:23 | 000,007,460 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symefa64.cat
[2011/11/29 17:36:23 | 000,007,458 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symnet64.cat
[2011/11/29 17:36:23 | 000,007,458 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtsp64.cat
[2011/11/29 17:36:23 | 000,003,373 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symefa.inf
[2011/11/29 17:36:23 | 000,002,792 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symds.inf
[2011/11/29 17:36:23 | 000,001,446 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symnet.inf
[2011/11/29 17:36:23 | 000,001,438 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtsp64.inf
[2011/11/29 17:36:23 | 000,001,422 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtspx64.inf
[2011/11/29 17:36:23 | 000,000,772 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\iron.inf
[2011/11/29 17:36:14 | 000,000,000 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symds64.cat
[2011/11/29 17:36:12 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\isolate.ini
[2011/11/29 17:31:58 | 000,002,640 | —- | C] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/11/25 16:23:11 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\A6xErEJ.com.b
[2011/11/25 16:20:25 | 000,000,350 | —- | C] () – C:\Windows\tasks\At48.job
[2011/11/25 16:20:25 | 000,000,348 | —- | C] () – C:\Windows\tasks\At47.job
[2011/11/25 16:20:25 | 000,000,112 | —- | C] () – C:\ProgramData\786trd8.dat
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At46.job
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At44.job
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At42.job
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At40.job
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At38.job
[2011/11/25 16:20:24 | 000,000,348 | —- | C] () – C:\Windows\tasks\At45.job
[2011/11/25 16:20:24 | 000,000,348 | —- | C] () – C:\Windows\tasks\At43.job
[2011/11/25 16:20:24 | 000,000,348 | —- | C] () – C:\Windows\tasks\At41.job
[2011/11/25 16:20:24 | 000,000,348 | —- | C] () – C:\Windows\tasks\At39.job
[2011/11/25 16:20:23 | 000,000,350 | —- | C] () – C:\Windows\tasks\At36.job
[2011/11/25 16:20:23 | 000,000,350 | —- | C] () – C:\Windows\tasks\At34.job
[2011/11/25 16:20:23 | 000,000,350 | —- | C] () – C:\Windows\tasks\At32.job
[2011/11/25 16:20:23 | 000,000,348 | —- | C] () – C:\Windows\tasks\At37.job
[2011/11/25 16:20:23 | 000,000,348 | —- | C] () – C:\Windows\tasks\At35.job
[2011/11/25 16:20:23 | 000,000,348 | —- | C] () – C:\Windows\tasks\At33.job
[2011/11/25 16:20:23 | 000,000,348 | —- | C] () – C:\Windows\tasks\At31.job
[2011/11/25 16:20:22 | 000,000,350 | —- | C] () – C:\Windows\tasks\At30.job
[2011/11/25 16:20:22 | 000,000,350 | —- | C] () – C:\Windows\tasks\At28.job
[2011/11/25 16:20:22 | 000,000,350 | —- | C] () – C:\Windows\tasks\At26.job
[2011/11/25 16:20:22 | 000,000,348 | —- | C] () – C:\Windows\tasks\At29.job
[2011/11/25 16:20:22 | 000,000,348 | —- | C] () – C:\Windows\tasks\At27.job
[2011/11/25 16:20:22 | 000,000,348 | —- | C] () – C:\Windows\tasks\At25.job
[2011/11/25 16:20:21 | 000,000,350 | —- | C] () – C:\Windows\tasks\At24.job
[2011/11/25 16:20:21 | 000,000,350 | —- | C] () – C:\Windows\tasks\At22.job
[2011/11/25 16:20:21 | 000,000,350 | —- | C] () – C:\Windows\tasks\At20.job
[2011/11/25 16:20:21 | 000,000,348 | —- | C] () – C:\Windows\tasks\At23.job
[2011/11/25 16:20:21 | 000,000,348 | —- | C] () – C:\Windows\tasks\At21.job
[2011/11/25 16:20:21 | 000,000,348 | —- | C] () – C:\Windows\tasks\At19.job
[2011/11/25 16:20:20 | 000,000,350 | —- | C] () – C:\Windows\tasks\At18.job
[2011/11/25 16:20LS\x00\x00\x00\x00
I brought a copy of Norton with my HP Pavilion g6 laptop in September. The laptop came with a trial version of a more expensive Norton, so I let it run it's course with the intent of installing the version I bought. This was dumb, because I should've known that I'd procrastinate when the trial version ran out. Norton kept warning me that I did not have any protection, and being an arrogant person, I ignored the warnings and made fun of them mentally.
So yesterday, a few times when I tried using google, I clicked on a search result and was led to an ad thing. I disregarded it, even though this is obviously a highly unusual thing. Then today, I tried to use the internet, and I couldn't get on. I said, "Oh, well since I can't do that, good time to install Norton." Installed Norton, started a full system scan (which ended up detecting and removing 4 trojan horse things). Called the computer people who work at the university I'm dorming at and asked why I couldn't get on the internet, and long story short: I have a virus. I went in with the laptop and they ran TDSSkiller and Fix TDSS and both didn't find anything. They then ran live update on my Norton (which was 363 days behind in updates…) and pretty much told me I could go and that they would restore connectivity to my port. So I made sure that the Norton was updated, got home, started running TDSSkiller and Fix TDSS again on my own to try and fix things. When Fix TDSS restarted the computer, it wouldn't start up again. So I told the computer to run Startup repair and it restored the computer to an earlier "checkpoint" (?) or whatever and I thought this fixed everything and went about my merry way, facebooking and emailing.
Then Norton started giving me more popups telling me "Threat requiring manual removal detected: System Inected: Tidserv Activity", and sometimes will include a "2" at the end. So I ran TDSSkiller again, didn't detect anything. Renamed the file as was suggested on Yahoo Answers, didn't detect anything. Fix TDSS didn't detect anything. Norton Power Eraser didn't detect anything (after restarting the computer as the program suggested to include a search for rootkits).
I am fairly stumped, at this point, and any assistance would be fantastic. I am pretty sure that if the virus is still there (as I type this a popup from norton is telling me that it is..) it is only a matter of time before they shut down my port again. And the obvious badness of having a virus too.
OLT Scan Results:
OTL logfile created on: 11/29/2011 6:30:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nikholas\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 2.16 Gb Available Physical Memory | 56.87% Memory free
7.60 Gb Paging File | 5.90 Gb Available in Paging File | 77.59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450.78 Gb Total Space | 352.24 Gb Free Space | 78.14% Space Free | Partition Type: NTFS
Drive D: | 14.69 Gb Total Space | 1.63 Gb Free Space | 11.10% Space Free | Partition Type: NTFS
Drive E: | 590.19 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 99.02 Mb Total Space | 84.90 Mb Free Space | 85.73% Space Free | Partition Type: FAT32
Computer Name: JARVIS | User Name: Nikholas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/29 18:20:52 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nikholas\Downloads\OTL.exe
PRC - [2011/09/05 09:04:54 | 000,064,952 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/09/01 16:42:06 | 024,183,152 | —- | M] (Dropbox, Inc.) – C:\Users\Nikholas\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/08/23 20:20:18 | 000,887,976 | —- | M] (Ask) – C:\Program Files (x86)\Ask.com\Updater\Updater.exe
PRC - [2011/08/14 11:02:58 | 021,975,120 | —- | M] (ooVoo LLC) – C:\Program Files (x86)\ooVoo\ooVoo.exe
PRC - [2011/08/04 15:57:48 | 000,789,088 | —- | M] (Jackpot Rewards) – C:\Program Files (x86)\DealRunner\DealRunner.exe
PRC - [2011/07/27 03:06:44 | 000,267,488 | —- | M] () – C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe
PRC - [2011/07/05 16:02:58 | 000,227,384 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2011/06/14 13:29:22 | 000,587,320 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2011/06/14 13:29:22 | 000,026,680 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2011/06/13 15:47:12 | 000,336,440 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
PRC - [2011/04/29 23:32:54 | 000,013,592 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011/04/29 23:32:50 | 000,284,440 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2011/04/16 16:45:11 | 000,130,008 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton AntiVirus\Norton AntiVirus\Engine\18.6.0.29\ccsvchst.exe
PRC - [2011/03/22 10:42:40 | 000,136,488 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/02/15 14:48:52 | 001,071,160 | —- | M] (Hewlett-Packard Development Company L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
PRC - [2010/11/26 06:09:12 | 000,399,344 | —- | M] (Roxio) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/09/16 10:13:14 | 002,538,520 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/09/16 10:13:06 | 000,325,656 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/09/14 04:45:56 | 000,219,496 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010/09/14 04:45:44 | 000,508,264 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/04/23 11:00:00 | 000,514,232 | —- | M] (EasyBits Software AS) – C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/04/23 11:00:00 | 000,514,232 | —- | M] (EasyBits Software AS) – C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/01/15 04:49:20 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2010/01/14 18:16:16 | 000,345,600 | —- | M] (Pharos Systems International) – C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
PRC - [2009/07/13 17:14:28 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\PING.EXE
PRC - [2009/04/23 05:29:18 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2009/04/23 05:29:14 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/18 19:41:09 | 011,819,520 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\8e7909ef6b5f953d49244c6b9f5f5100\System.Web.ni.dll
MOD - [2011/10/18 19:41:02 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b2622080e047040fa044dd21a04ff10d\System.Runtime.Remoting.ni.dll
MOD - [2011/10/18 19:41:02 | 000,014,336 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\33cecc66284ef59208b639ec72b0f565\IAStorCommon.ni.dll
MOD - [2011/10/18 19:41:01 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll
MOD - [2011/10/18 19:40:58 | 000,492,544 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\e8339b699235ebf2f904ccb8383de342\IAStorUtil.ni.dll
MOD - [2011/10/18 19:40:56 | 012,433,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll
MOD - [2011/10/18 19:40:48 | 001,587,200 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll
MOD - [2011/10/18 19:40:31 | 005,453,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/10/18 19:40:27 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/10/18 19:40:25 | 007,963,648 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/10/18 19:40:19 | 011,490,304 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/05/26 12:42:00 | 000,067,872 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2010/11/20 19:24:09 | 000,232,448 | —- | M] () – \\?\globalroot\systemroot\syswow64\mswsock.DLL
MOD - [2010/11/20 19:24:09 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\syswow64\mswsock.dll
MOD - [2009/04/16 12:02:16 | 000,970,752 | —- | M] () – C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/09/12 08:48:34 | 000,301,568 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [2011/02/16 21:47:28 | 000,682,040 | —- | M] (Hewlett-Packard) [Auto | Stopped] – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe – (HPAuto)
SRV:64bit: - [2010/10/11 01:48:14 | 000,346,168 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe – (HPClientSvc)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/09/05 09:04:54 | 000,064,952 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/07/27 03:06:44 | 000,267,488 | —- | M] () [Auto | Running] – C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe – (Updater Service for StartNow Toolbar)
SRV - [2011/07/05 16:02:58 | 000,227,384 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2011/06/21 14:57:34 | 000,085,560 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe – (HP Support Assistant Service)
SRV - [2011/06/14 13:29:22 | 000,026,680 | —- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe – (HPWMISVC)
SRV - [2011/04/29 23:32:54 | 000,013,592 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2011/04/16 16:45:11 | 000,130,008 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton AntiVirus\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe – (NAV)
SRV - [2011/04/14 14:47:38 | 000,103,336 | —- | M] (stumbleupon.com) [On_Demand | Stopped] – C:\Program Files (x86)\StumbleUpon\StumbleUponUpdateService.exe – (StumbleUponUpdateService)
SRV - [2011/03/07 16:43:30 | 002,375,168 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2011/03/01 20:23:36 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 09:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2011/02/15 14:48:52 | 001,071,160 | —- | M] (Hewlett-Packard Development Company L.P.) [On_Demand | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe – (hpCMSrv)
SRV - [2010/11/26 06:09:12 | 000,399,344 | —- | M] (Roxio) [Auto | Running] – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe – (RoxioNow Service)
SRV - [2010/10/12 09:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/09/16 10:13:14 | 002,538,520 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/09/16 10:13:06 | 000,325,656 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2010/09/14 04:45:56 | 000,219,496 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe – (sftvsa)
SRV - [2010/09/14 04:45:44 | 000,508,264 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe – (sftlist)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/01/15 04:49:20 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2010/01/14 18:16:16 | 000,345,600 | —- | M] (Pharos Systems International) [Auto | Running] – C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe – (Pharos Systems ComTaskMaster)
SRV - [2009/06/10 13:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/11/29 18:07:07 | 000,096,376 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\SMR210.SYS – (SMR210)
DRV:64bit: - [2011/11/29 17:36:25 | 000,174,200 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2011/09/12 08:50:51 | 000,533,096 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2011/09/12 08:48:34 | 000,528,384 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\stwrt64.sys – (STHDA)
DRV:64bit: - [2011/09/12 08:16:56 | 001,451,056 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2011/07/19 09:19:16 | 001,492,992 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\netr28x.sys – (netr28x)
DRV:64bit: - [2011/05/10 07:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/04/26 10:07:36 | 000,557,848 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2011/03/30 19:00:09 | 000,744,568 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtsp64.sys – (SRTSP)
DRV:64bit: - [2011/03/30 19:00:09 | 000,040,568 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtspx64.sys – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2011/03/21 16:39:49 | 000,382,584 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symnets.sys – (SymNetS)
DRV:64bit: - [2011/03/14 18:31:23 | 000,912,504 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symefa64.sys – (SymEFA)
DRV:64bit: - [2011/03/10 22:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/10 22:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/02/15 11:37:10 | 000,335,464 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsPStor.sys – (RSPCIESTOR)
DRV:64bit: - [2011/01/26 22:47:10 | 000,450,680 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symds64.sys – (SymDS)
DRV:64bit: - [2011/01/26 21:07:06 | 000,171,128 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\ironx64.sys – (SymIRON)
DRV:64bit: - [2011/01/07 17:42:34 | 012,262,688 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/11/20 19:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 19:23:47 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/11/20 19:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 19:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/15 00:28:16 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2010/09/14 04:45:52 | 000,022,376 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftvollh.sys – (Sftvol)
DRV:64bit: - [2010/09/14 04:45:50 | 000,025,960 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftredirlh.sys – (Sftredir)
DRV:64bit: - [2010/09/14 04:45:48 | 000,268,648 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftplaylh.sys – (Sftplay)
DRV:64bit: - [2010/09/14 04:45:44 | 000,760,168 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftfslh.sys – (Sftfs)
DRV:64bit: - [2010/07/28 08:13:50 | 000,031,088 | —- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\clwvd.sys – (clwvd)
DRV:64bit: - [2010/02/26 15:32:12 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/09/17 12:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 13:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 13:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 13:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 12:35:35 | 000,408,960 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nvm62x64.sys – (NVENETFD)
DRV:64bit: - [2009/06/10 12:34:38 | 001,311,232 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2011/11/29 17:35:59 | 002,048,632 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\VirusDefs\20111129.020\ex64.sys – (NAVEX15)
DRV - [2011/11/29 17:35:58 | 000,482,936 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2011/11/29 17:35:58 | 000,138,360 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2011/11/29 17:35:58 | 000,117,880 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\VirusDefs\20111129.020\eng64.sys – (NAVENG)
DRV - [2011/11/29 16:52:40 | 000,488,568 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\IPSDefs\20111129.030\IDSviA64.sys – (IDSVia64)
DRV - [2011/11/23 23:08:44 | 001,156,216 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\BASHDefs\20111123.001\BHDrvx64.sys – (BHDrvx64)
DRV - [2009/07/13 17:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=14196
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}"
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Nikholas\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\coFFPlgn_2011_7_3_6
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\IPSFFPlgn\ [2011/11/29 17:39:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/22 19:23:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/08/25 22:42:50 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Extensions
[2011/11/14 23:15:43 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions
[2011/11/14 23:15:42 | 000,000,000 | —D | M] (ShopToWin9) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\{46d606b0-a645-11df-981c-0800200c9a66}
[2011/10/11 03:05:52 | 000,000,000 | —D | M] (StartNow Toolbar) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2011/11/14 23:15:43 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/11/08 20:07:00 | 000,000,000 | —D | M] ("ooVoo toolbar, powered by Ask.com") – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\[removed]
[2011/11/14 23:15:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\extensions\{46d606b0-a645-11df-981c-0800200c9a66}\chrome\content\dca\core\extensionManager
[2011/07/29 21:02:18 | 000,002,333 | —- | M] () – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\searchplugins\askcom.xml
[2011/08/16 09:06:22 | 000,000,863 | —- | M] () – C:\Users\Nikholas\AppData\Roaming\Mozilla\Firefox\Profiles\n57kajlw.default\searchplugins\conduit.xml
[2011/08/25 22:42:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/22 19:23:49 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/02 23:12:42 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/22 19:23:49 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Nikholas\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Black Hole Sun = C:\Users\Nikholas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjflaldchiphekckakjglcfjiomhjobc\1_0\
CHR - Extension: StumbleUpon = C:\Users\Nikholas\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg\3.10.11.1_0\
Hosts file not found
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Shop to Win) - {0095C290-A428-4BDD-B98C-E0A116F1C702} - C:\Program Files (x86)\Shop to Win 9\Shop to Win 9.dll (Shop To Win, LLC)
O2 - BHO: (StumbleUpon Launcher) - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files (x86)\StumbleUpon\StumbleUponIEBar.dll (stumbleupon.com)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll File not found
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Norton AntiVirus\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (StartNow Toolbar Helper) - {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll ()
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (StumbleUpon Toolbar) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files (x86)\StumbleUpon\StumbleUponIEBar.dll (stumbleupon.com)
O3 - HKLM\..\Toolbar: (StartNow Toolbar) - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll File not found
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (ooVoo toolbar, powered by Ask.com) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [StartNowToolbarHelper] "C:\Program Files (x86)\StartNow Toolbar\ToolbarHelper.exe" File not found
O4 - HKCU..\Run: [DealRunner] C:\Program Files (x86)\DealRunner\DealRunner.exe (Jackpot Rewards)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Nikholas\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe (ooVoo LLC)
O4 - Startup: C:\Users\Nikholas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Nikholas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Nikholas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage File not found
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage File not found
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{893EC908-EDE1-45D3-8BA5-FB8DFFBC9631}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8D276B82-01A2-4915-A127-12050761D0EB}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/04 13:24:23 | 000,000,175 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{bbb76687-cfaf-11e0-8d78-806e6f6e6963}\Shell\AutoRun\command - "" = E:\START.EXE – [2010/12/03 22:57:51 | 003,109,304 | R— | M] (Symantec Corporation)
O33 - MountPoints2\{bbb76687-cfaf-11e0-8d78-806e6f6e6963}\Shell\Install\Command - "" = E:\START.EXE – [2010/12/03 22:57:51 | 003,109,304 | R— | M] (Symantec Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/29 18:07:07 | 000,096,376 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SMR210.SYS
[2011/11/29 18:04:10 | 000,000,000 | —D | C] – C:\Users\Nikholas\AppData\Local\NPE
[2011/11/29 17:36:23 | 000,912,504 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symefa64.sys
[2011/11/29 17:36:23 | 000,744,568 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtsp64.sys
[2011/11/29 17:36:23 | 000,450,680 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symds64.sys
[2011/11/29 17:36:23 | 000,382,584 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symnets.sys
[2011/11/29 17:36:23 | 000,171,128 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\ironx64.sys
[2011/11/29 17:36:23 | 000,040,568 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtspx64.sys
[2011/11/29 17:36:12 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NAVx64\1206000.01D
[2011/11/29 17:30:59 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NAVx64
[2011/11/29 12:16:41 | 000,000,000 | —D | C] – C:\Users\Nikholas\Desktop\New folder
[2011/11/29 10:57:21 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/11/29 10:56:05 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton AntiVirus
[2011/11/29 10:56:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton AntiVirus
[2011/11/29 10:52:35 | 000,000,000 | —D | C] – C:\ProgramData\PCSettings
[2011/11/24 12:13:33 | 000,000,000 | —D | C] – C:\Windows\system64
[2011/11/23 02:19:56 | 000,000,000 | —D | C] – C:\Users\Nikholas\AppData\Local\Microsoft Help
[2011/11/23 02:19:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/11/22 14:54:52 | 000,000,000 | —D | C] – C:\Users\Nikholas\Documents\Correspondence
[2011/11/20 15:18:28 | 000,000,000 | —D | C] – C:\Users\Nikholas\Documents\Other People's Work
[2011/11/19 23:16:38 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Samsung_USB_Drivers
[2011/11/19 23:16:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Samsung
[2011/11/02 13:32:35 | 000,000,000 | —D | C] – C:\Users\Nikholas\AppData\Roaming\ooVoo Details
[2011/11/02 13:32:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ask.com
[2011/11/02 13:31:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
[2011/11/02 13:31:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\ooVoo
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Users\Nikholas\Documents\*.tmp files -> C:\Users\Nikholas\Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/29 18:16:11 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/29 18:16:11 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/29 18:13:36 | 000,727,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/29 18:13:36 | 000,624,622 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/29 18:13:36 | 000,106,708 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/29 18:08:34 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/29 18:08:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/29 18:08:04 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2011/11/29 18:07:07 | 000,096,376 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SMR210.SYS
[2011/11/29 18:06:00 | 000,000,350 | —- | M] () – C:\Windows\tasks\At38.job
[2011/11/29 18:06:00 | 000,000,348 | —- | M] () – C:\Windows\tasks\At37.job
[2011/11/29 17:39:24 | 000,002,640 | —- | M] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/11/29 17:38:52 | 001,396,538 | —- | M] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\Cat.DB
[2011/11/29 17:36:25 | 000,174,200 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/11/29 17:36:25 | 000,007,488 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/11/29 17:36:25 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At8.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At6.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At42.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At40.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At36.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At32.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At30.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At28.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At22.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At20.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At18.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At16.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At14.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At12.job
[2011/11/29 17:11:29 | 000,000,350 | —- | M] () – C:\Windows\tasks\At10.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At9.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At7.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At5.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At41.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At39.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At35.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At33.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At31.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At29.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At27.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At21.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At19.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At17.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At15.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At13.job
[2011/11/29 17:11:29 | 000,000,348 | —- | M] () – C:\Windows\tasks\At11.job
[2011/11/29 17:11:29 | 000,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJARVIS$.job
[2011/11/26 23:06:00 | 000,000,350 | —- | M] () – C:\Windows\tasks\At48.job
[2011/11/26 23:06:00 | 000,000,348 | —- | M] () – C:\Windows\tasks\At47.job
[2011/11/26 22:46:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/26 22:41:26 | 000,000,940 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1339067313-137779846-2497530518-1000UA.job
[2011/11/26 16:57:40 | 000,000,350 | —- | M] () – C:\Windows\tasks\At34.job
[2011/11/26 16:57:40 | 000,000,350 | —- | M] () – C:\Windows\tasks\At26.job
[2011/11/26 16:57:40 | 000,000,350 | —- | M] () – C:\Windows\tasks\At24.job
[2011/11/26 16:57:40 | 000,000,348 | —- | M] () – C:\Windows\tasks\At25.job
[2011/11/26 16:57:40 | 000,000,348 | —- | M] () – C:\Windows\tasks\At23.job
[2011/11/26 06:52:41 | 000,000,350 | —- | M] () – C:\Windows\tasks\At4.job
[2011/11/26 06:52:41 | 000,000,348 | —- | M] () – C:\Windows\tasks\At3.job
[2011/11/26 00:06:00 | 000,000,350 | —- | M] () – C:\Windows\tasks\At2.job
[2011/11/26 00:06:00 | 000,000,348 | —- | M] () – C:\Windows\tasks\At1.job
[2011/11/25 22:08:39 | 000,000,350 | —- | M] () – C:\Windows\tasks\At46.job
[2011/11/25 22:08:39 | 000,000,348 | —- | M] () – C:\Windows\tasks\At45.job
[2011/11/25 21:06:00 | 000,000,350 | —- | M] () – C:\Windows\tasks\At44.job
[2011/11/25 21:06:00 | 000,000,348 | —- | M] () – C:\Windows\tasks\At43.job
[2011/11/25 16:25:22 | 000,000,112 | —- | M] () – C:\ProgramData\786trd8.dat
[2011/11/25 16:23:11 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\A6xErEJ.com.b
[2011/11/24 23:00:40 | 000,000,918 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1339067313-137779846-2497530518-1000Core.job
[2011/11/19 23:23:16 | 000,000,344 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForNikholas.job
[2011/11/18 23:46:53 | 000,002,268 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/11/11 06:50:44 | 001,397,596 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\Cat.DB
[2011/11/10 11:59:36 | 000,284,920 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/02 13:31:21 | 000,001,857 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Users\Nikholas\Documents\*.tmp files -> C:\Users\Nikholas\Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/29 17:38:35 | 001,396,538 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\Cat.DB
[2011/11/29 17:36:23 | 000,007,492 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\iron.cat
[2011/11/29 17:36:23 | 000,007,462 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtspx64.cat
[2011/11/29 17:36:23 | 000,007,460 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symefa64.cat
[2011/11/29 17:36:23 | 000,007,458 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symnet64.cat
[2011/11/29 17:36:23 | 000,007,458 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtsp64.cat
[2011/11/29 17:36:23 | 000,003,373 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symefa.inf
[2011/11/29 17:36:23 | 000,002,792 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symds.inf
[2011/11/29 17:36:23 | 000,001,446 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symnet.inf
[2011/11/29 17:36:23 | 000,001,438 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtsp64.inf
[2011/11/29 17:36:23 | 000,001,422 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\srtspx64.inf
[2011/11/29 17:36:23 | 000,000,772 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\iron.inf
[2011/11/29 17:36:14 | 000,000,000 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\symds64.cat
[2011/11/29 17:36:12 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1206000.01D\isolate.ini
[2011/11/29 17:31:58 | 000,002,640 | —- | C] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/11/25 16:23:11 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\A6xErEJ.com.b
[2011/11/25 16:20:25 | 000,000,350 | —- | C] () – C:\Windows\tasks\At48.job
[2011/11/25 16:20:25 | 000,000,348 | —- | C] () – C:\Windows\tasks\At47.job
[2011/11/25 16:20:25 | 000,000,112 | —- | C] () – C:\ProgramData\786trd8.dat
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At46.job
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At44.job
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At42.job
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At40.job
[2011/11/25 16:20:24 | 000,000,350 | —- | C] () – C:\Windows\tasks\At38.job
[2011/11/25 16:20:24 | 000,000,348 | —- | C] () – C:\Windows\tasks\At45.job
[2011/11/25 16:20:24 | 000,000,348 | —- | C] () – C:\Windows\tasks\At43.job
[2011/11/25 16:20:24 | 000,000,348 | —- | C] () – C:\Windows\tasks\At41.job
[2011/11/25 16:20:24 | 000,000,348 | —- | C] () – C:\Windows\tasks\At39.job
[2011/11/25 16:20:23 | 000,000,350 | —- | C] () – C:\Windows\tasks\At36.job
[2011/11/25 16:20:23 | 000,000,350 | —- | C] () – C:\Windows\tasks\At34.job
[2011/11/25 16:20:23 | 000,000,350 | —- | C] () – C:\Windows\tasks\At32.job
[2011/11/25 16:20:23 | 000,000,348 | —- | C] () – C:\Windows\tasks\At37.job
[2011/11/25 16:20:23 | 000,000,348 | —- | C] () – C:\Windows\tasks\At35.job
[2011/11/25 16:20:23 | 000,000,348 | —- | C] () – C:\Windows\tasks\At33.job
[2011/11/25 16:20:23 | 000,000,348 | —- | C] () – C:\Windows\tasks\At31.job
[2011/11/25 16:20:22 | 000,000,350 | —- | C] () – C:\Windows\tasks\At30.job
[2011/11/25 16:20:22 | 000,000,350 | —- | C] () – C:\Windows\tasks\At28.job
[2011/11/25 16:20:22 | 000,000,350 | —- | C] () – C:\Windows\tasks\At26.job
[2011/11/25 16:20:22 | 000,000,348 | —- | C] () – C:\Windows\tasks\At29.job
[2011/11/25 16:20:22 | 000,000,348 | —- | C] () – C:\Windows\tasks\At27.job
[2011/11/25 16:20:22 | 000,000,348 | —- | C] () – C:\Windows\tasks\At25.job
[2011/11/25 16:20:21 | 000,000,350 | —- | C] () – C:\Windows\tasks\At24.job
[2011/11/25 16:20:21 | 000,000,350 | —- | C] () – C:\Windows\tasks\At22.job
[2011/11/25 16:20:21 | 000,000,350 | —- | C] () – C:\Windows\tasks\At20.job
[2011/11/25 16:20:21 | 000,000,348 | —- | C] () – C:\Windows\tasks\At23.job
[2011/11/25 16:20:21 | 000,000,348 | —- | C] () – C:\Windows\tasks\At21.job
[2011/11/25 16:20:21 | 000,000,348 | —- | C] () – C:\Windows\tasks\At19.job
[2011/11/25 16:20:20 | 000,000,350 | —- | C] () – C:\Windows\tasks\At18.job
[2011/11/25 16:20LS\x00\x00\x00\x00