krome8800
Topic Starter
This computer was crazy infected with Trojans and still have a hi jacked web browser. The home page will pull up but the search doesnt pull up what u need or ask for. I also on a different laptop using an external hard drive to get the files as i can even get on to what the tech on the laptop in question.
I including the OTL,Hijack, and Malwarbytes logs.
OTL Log
OTL logfile created on: 12/11/2011 4:25:18 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = D:\
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.84 Gb Total Physical Memory | 2.46 Gb Available Physical Memory | 63.90% Memory free
7.68 Gb Paging File | 6.08 Gb Available in Paging File | 79.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 290.37 Gb Total Space | 200.11 Gb Free Space | 68.92% Space Free | Partition Type: NTFS
Drive D: | 74.53 Gb Total Space | 6.01 Gb Free Space | 8.06% Space Free | Partition Type: NTFS
Computer Name: KILLAH-VAIO | User Name: meagon86 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/11 16:21:52 | 000,388,608 | —- | M] (Trend Micro Inc.) – D:\HiJackThis.exe
PRC - [2011/12/11 16:21:35 | 000,584,192 | —- | M] (OldTimer Tools) – D:\OTL.exe
PRC - [2011/04/18 17:21:43 | 001,643,272 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe
PRC - [2011/04/18 17:21:40 | 000,789,392 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/04/18 17:21:39 | 001,181,328 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/12/02 07:19:02 | 000,707,704 | —- | M] () – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWWSC.exe
PRC - [2009/09/01 16:32:12 | 000,087,344 | —- | M] (Prolific Technology Inc.) – C:\Windows\SysWOW64\IoctlSvc.exe
PRC - [2009/08/26 18:11:50 | 000,173,368 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
PRC - [2009/08/26 18:11:50 | 000,033,792 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
PRC - [2009/08/26 18:11:50 | 000,017,408 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
PRC - [2009/08/26 18:11:48 | 000,017,920 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
PRC - [2009/07/23 11:39:38 | 000,313,264 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
PRC - [2009/07/23 11:39:36 | 000,206,336 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
PRC - [2009/07/22 16:03:04 | 000,642,920 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
PRC - [2009/07/13 19:14:28 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\PING.EXE
PRC - [2009/07/01 12:49:34 | 000,204,648 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
PRC - [2009/07/01 12:49:34 | 000,112,488 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
PRC - [2009/06/18 15:19:30 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/06/04 20:03:32 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/04 20:03:06 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/05/26 10:23:14 | 000,317,288 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2008/09/18 11:59:10 | 000,104,960 | —- | M] (ArcSoft, Inc.) – C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/27 13:39:42 | 011,807,744 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5a95ba97100404e2ab26b5a9ab9ef965\System.Web.ni.dll
MOD - [2011/11/27 13:39:34 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\018d2569cf208acbe8ad73908705f607\System.Runtime.Remoting.ni.dll
MOD - [2011/11/27 13:38:36 | 012,431,360 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll
MOD - [2011/11/27 13:38:24 | 001,586,688 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll
MOD - [2011/11/27 13:38:04 | 003,325,952 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll
MOD - [2011/11/27 13:37:58 | 005,452,800 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll
MOD - [2011/11/27 13:37:52 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll
MOD - [2011/11/27 13:37:50 | 007,949,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll
MOD - [2011/11/27 13:37:37 | 011,490,304 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll
MOD - [2011/05/04 16:34:29 | 003,178,496 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2011/04/18 17:21:49 | 000,087,496 | —- | M] () – C:\Program Files (x86)\Lavasoft\Ad-Aware\PrivacyClean.dll
MOD - [2011/03/29 16:31:57 | 005,025,792 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
MOD - [2009/08/26 18:11:50 | 000,120,320 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\SonyCommonLib.dll
MOD - [2009/08/26 18:11:50 | 000,081,408 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\DevicePanel.dll
MOD - [2009/08/26 18:11:50 | 000,033,792 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
MOD - [2009/08/26 18:11:50 | 000,027,648 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.BtPower.dll
MOD - [2009/08/26 18:11:50 | 000,023,040 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.Generic.dll
MOD - [2009/08/26 18:11:50 | 000,018,944 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\DictionaryLookup.dll
MOD - [2009/08/26 18:11:50 | 000,017,408 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
MOD - [2009/08/26 18:11:50 | 000,015,360 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.NativeWifiThirdPartyApp.dll
MOD - [2009/08/26 18:11:50 | 000,011,264 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.TosBtThirdPartyApp.dll
MOD - [2009/08/26 18:11:50 | 000,007,680 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\DebugMsg.dll
MOD - [2009/08/26 18:11:50 | 000,007,168 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.WlanPower.dll
MOD - [2009/08/26 18:11:50 | 000,005,120 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.ThirdPartyApp.dll
MOD - [2009/08/26 18:11:50 | 000,005,120 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.Generic.dll
MOD - [2009/08/26 18:11:50 | 000,004,608 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.Power.dll
MOD - [2009/08/26 18:11:48 | 000,017,920 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
MOD - [2009/08/26 18:11:48 | 000,015,360 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\SharedInterfaces.dll
MOD - [2009/08/26 18:11:48 | 000,011,264 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\MessageXML.dll
MOD - [2009/08/26 18:11:48 | 000,009,728 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Resources.dll
MOD - [2009/07/13 19:15:51 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\syswow64\mswsock.dll
MOD - [2009/06/10 15:23:20 | 002,048,000 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2009/06/10 15:23:19 | 000,303,104 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2009/06/10 15:23:18 | 000,626,688 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
MOD - [2009/06/10 15:23:18 | 000,372,736 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2009/08/22 15:19:06 | 000,411,496 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files\Sony\VAIO Power Management\SPMService.exe – (VAIO Power Management)
SRV:64bit: - [2009/07/23 22:34:31 | 000,189,984 | —- | M] (Realtek Semiconductor) [Auto | Running] – C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe – (RtkAudioService)
SRV:64bit: - [2009/06/26 15:56:10 | 000,357,672 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe – (VcmINSMgr)
SRV:64bit: - [2009/06/26 15:35:04 | 000,468,264 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe – (VcmIAlzMgr)
SRV:64bit: - [2009/06/17 19:50:30 | 000,110,888 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe – (VcmXmlIfHelper)
SRV:64bit: - [2008/09/29 17:06:32 | 000,167,424 | —- | M] (Intel Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\VAIO Care\collsvc.exe – (SampleCollector)
SRV - [2011/04/18 17:21:39 | 001,181,328 | —- | M] (Lavasoft) [Auto | Running] – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/09/01 16:32:12 | 000,087,344 | —- | M] (Prolific Technology Inc.) [Auto | Running] – C:\Windows\SysWOW64\IoctlSvc.exe – (PLFlash DeviceIoControl Service)
SRV - [2009/07/31 14:09:12 | 000,436,736 | —- | M] (Conexant Systems, Inc.) [Auto | Stopped] – C:\Windows\SysWOW64\XAudio64.dll – (HsfXAudioService)
SRV - [2009/07/27 17:58:40 | 000,091,432 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe – (SOHPlMgr)
SRV - [2009/07/27 17:58:38 | 000,427,304 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe – (SOHDms)
SRV - [2009/07/27 17:58:38 | 000,075,048 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe – (SOHDs)
SRV - [2009/07/27 17:58:38 | 000,070,952 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe – (SOHDBSvr)
SRV - [2009/07/27 17:58:36 | 000,120,104 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe – (SOHCImp)
SRV - [2009/07/23 11:39:38 | 000,313,264 | —- | M] (Sony Corporation) [On_Demand | Running] – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe – (Vcsw)
SRV - [2009/07/23 11:39:38 | 000,069,632 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe – (VAIO Entertainment TV Device Arbitration Service)
SRV - [2009/07/23 11:39:36 | 000,206,336 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe – (VzCdbSvc)
SRV - [2009/07/22 16:03:04 | 000,642,920 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe – (VCFw)
SRV - [2009/07/01 12:49:34 | 000,204,648 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe – (VAIO Event Service)
SRV - [2009/06/18 15:19:30 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2009/06/10 15:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 20:03:06 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/02/06 18:02:14 | 000,109,056 | —- | M] (ArcSoft Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2008/09/18 11:59:10 | 000,104,960 | —- | M] (ArcSoft, Inc.) [Auto | Running] – C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe – (uCamMonitor)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/03/11 00:22:41 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 00:22:40 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/02/18 15:36:58 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2010/04/16 20:24:34 | 000,027,536 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d) MS Hardware Device Detection Driver (HID)
DRV:64bit: - [2010/01/30 12:20:49 | 000,069,152 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\Lbd.sys – (Lbd)
DRV:64bit: - [2009/08/04 19:22:40 | 000,139,264 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV:64bit: - [2009/08/04 19:20:51 | 007,345,632 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/08/03 14:06:34 | 000,250,928 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Apfiltr.sys – (ApfiltrService)
DRV:64bit: - [2009/07/31 14:29:11 | 001,484,800 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/07/31 14:14:14 | 000,076,288 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\risdsn64.sys – (risdptsk)
DRV:64bit: - [2009/07/31 14:13:51 | 000,086,528 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\rimssn64.sys – (rimsptsk)
DRV:64bit: - [2009/07/31 14:09:12 | 000,010,240 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\XAudio64.sys – (XAudio)
DRV:64bit: - [2009/07/31 14:09:08 | 000,017,024 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\mdmxsdk.sys – (mdmxsdk)
DRV:64bit: - [2009/07/31 14:02:03 | 000,393,216 | —- | M] (Marvell) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:64bit: - [2009/07/27 14:27:10 | 006,037,504 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/07/23 23:24:03 | 000,201,472 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtHDMIVX.sys – (RTHDMIAzAudService)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:31:10 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2009/06/11 14:19:09 | 000,011,392 | —- | M] (Sony Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SFEP.sys – (SFEP)
DRV:64bit: - [2009/06/10 15:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 15:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 15:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 14:35:28 | 005,434,368 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netw5v64.sys – (netw5v64) Intel®
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 19:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/05/26 15:32:04 | 000,019,968 | —- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys – (ArcSoftKsUFilter)
DRV:64bit: - [2009/05/20 04:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2009/07/13 19:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…T&bmod;=SNNT
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…T&bmod;=SNNT
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…T&bmod;=SNNT
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "BearShare Web Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=634471"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=634471&p;="
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/27 11:24:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/11/21 17:10:51 | 000,000,000 | —D | M]
[2010/04/18 20:59:21 | 000,000,000 | -H-D | M] (No name found) – C:\Users\meagon86\AppData\Roaming\Mozilla\Extensions
[2010/01/30 13:49:53 | 000,000,000 | -H-D | M] (No name found) – C:\Users\meagon86\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/11/27 11:24:38 | 000,000,000 | —D | M] (No name found) – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\extensions
[2011/11/27 11:24:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/27 12:15:14 | 000,000,000 | —D | M] (MediaBar) – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593}
[2010/11/21 14:43:44 | 000,002,568 | -H– | M] () – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\searchplugins\askcom.xml
[2010/09/14 06:41:12 | 000,002,506 | -H– | M] () – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\searchplugins\BearShareWebSearch.xml
[2011/11/27 11:24:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/27 11:24:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2011/11/27 11:24:03 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/05 00:53:18 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/09/14 06:41:12 | 000,002,506 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\BearShareWebSearch.xml
[2011/11/04 21:21:03 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/04 21:21:03 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
Hosts file not found
O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll File not found
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SmartWiHelper] C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe (Sony Electronics Corporation)
O4 - HKCU..\RunOnce: [AutoLaunch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AutoLaunch.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4663E24F-3089-4E27-A1DB-886BC3E53AC6}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\Windows\SysWow64\VESWinlogon.dll (Sony Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/04 07:57:48 | 000,000,084 | RH– | M] () - D:\AutoRun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2011/12/11 16:26:00 | 009,851,496 | —- | C] (Malwarebytes Corporation ) – C:\Users\meagon86\Desktop\mbam-setup.exe
[2011/12/11 16:26:00 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\meagon86\Desktop\OTL.exe
[2011/12/11 16:26:00 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\meagon86\Desktop\HiJackThis.exe
[2011/12/11 14:18:36 | 000,000,000 | —D | C] – C:\Users\meagon86\AppData\Local\ElevatedDiagnostics
[2011/12/09 14:25:18 | 000,000,000 | —D | C] – C:\Windows\system64
[2011/11/27 12:47:07 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/11/27 12:39:38 | 000,000,000 | —D | C] – C:\Users\meagon86\AppData\Roaming\Opera
[2011/11/27 12:39:38 | 000,000,000 | —D | C] – C:\Users\meagon86\AppData\Local\Opera
[2011/11/27 12:39:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Opera
[2011/11/27 11:30:27 | 000,000,000 | —D | C] – C:\Users\meagon86\AppData\Roaming\Malwarebytes
[2011/11/27 11:30:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/27 11:30:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/27 11:30:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/27 11:28:22 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/11/27 11:28:21 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/11/27 11:28:21 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/11/27 11:28:19 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/11/27 11:28:18 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/11/27 11:28:18 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/11/27 11:28:18 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/11/27 11:28:17 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/11/27 11:28:17 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/11/27 11:28:16 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/11/27 11:28:16 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/11/27 11:28:16 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/11/27 11:28:16 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/11/27 11:28:16 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/11/27 11:28:16 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/11/27 11:27:15 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/11/27 11:27:15 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/11/27 11:27:15 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/11/27 11:27:15 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/11/27 11:27:15 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/11/27 11:27:15 | 000,104,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/11/27 11:27:15 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/11/27 11:27:15 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/11/27 11:27:15 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/11/27 11:27:14 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/11/27 11:27:11 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/11/27 11:27:11 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
========== Files - Modified Within 30 Days ==========
[2011/12/11 16:27:16 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/12/11 16:22:41 | 000,625,664 | —- | M] () – C:\Users\meagon86\Desktop\dds.scr
[2011/12/11 16:21:52 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\meagon86\Desktop\HiJackThis.exe
[2011/12/11 16:21:35 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\meagon86\Desktop\OTL.exe
[2011/12/11 16:20:28 | 000,014,144 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/11 16:20:28 | 000,014,144 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/11 16:20:16 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/11 16:20:16 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/11 16:20:16 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/11 16:13:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/11 16:13:06 | 3094,622,208 | -HS- | M] () – C:\hiberfil.sys
[2011/12/11 15:32:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At32.job
[2011/12/11 15:32:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At31.job
[2011/12/11 14:38:08 | 000,011,542 | -HS- | M] () – C:\Users\meagon86\AppData\Local\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/11 14:38:08 | 000,011,542 | -HS- | M] () – C:\ProgramData\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/11 14:32:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At30.job
[2011/12/11 14:32:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At29.job
[2011/12/09 23:32:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At48.job
[2011/12/09 23:32:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At47.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At8.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At6.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At46.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At44.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At42.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At40.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At4.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At38.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At36.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At34.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At28.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At26.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At24.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At22.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At20.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At2.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At18.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At16.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At14.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At12.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At10.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At9.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At7.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At5.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At45.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At43.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At41.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At39.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At37.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At35.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At33.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At3.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At27.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At25.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At23.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At21.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At19.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At17.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At15.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At13.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At11.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At1.job
[2011/12/09 14:51:53 | 000,000,112 | —- | M] () – C:\ProgramData\268J82.dat
[2011/12/09 14:44:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\5A66SN04M.com.b
[2011/11/27 13:35:37 | 000,363,928 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/27 12:47:08 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/27 12:39:34 | 000,001,833 | —- | M] () – C:\Users\Public\Desktop\Opera.lnk
[2011/11/27 11:30:12 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/27 11:24:13 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/26 17:43:44 | 000,000,320 | -H– | M] () – C:\ProgramData\~zhyLWWVfWs51of
[2011/11/26 17:43:44 | 000,000,224 | -H– | M] () – C:\ProgramData\~zhyLWWVfWs51ofr
[2011/11/26 17:43:33 | 000,000,440 | -H– | M] () – C:\ProgramData\zhyLWWVfWs51of
[2011/11/14 17:44:47 | 009,851,496 | —- | M] (Malwarebytes Corporation ) – C:\Users\meagon86\Desktop\mbam-setup.exe
========== Files Created - No Company Name ==========
[2011/12/11 16:26:00 | 000,625,664 | —- | C] () – C:\Users\meagon86\Desktop\dds.scr
[2011/12/09 14:44:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\5A66SN04M.com.b
[2011/12/09 14:36:48 | 000,000,112 | —- | C] () – C:\ProgramData\268J82.dat
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At48.job
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At46.job
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At44.job
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At42.job
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At40.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At47.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At45.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At43.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At41.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At39.job
[2011/12/09 14:36:46 | 000,000,354 | —- | C] () – C:\Windows\tasks\At38.job
[2011/12/09 14:36:46 | 000,000,354 | —- | C] () – C:\Windows\tasks\At36.job
[2011/12/09 14:36:46 | 000,000,354 | —- | C] () – C:\Windows\tasks\At34.job
[2011/12/09 14:36:46 | 000,000,352 | —- | C] () – C:\Windows\tasks\At37.job
[2011/12/09 14:36:46 | 000,000,352 | —- | C] () – C:\Windows\tasks\At35.job
[2011/12/09 14:36:45 | 000,000,354 | —- | C] () – C:\Windows\tasks\At32.job
[2011/12/09 14:36:45 | 000,000,354 | —- | C] () – C:\Windows\tasks\At30.job
[2011/12/09 14:36:45 | 000,000,352 | —- | C] () – C:\Windows\tasks\At33.job
[2011/12/09 14:36:45 | 000,000,352 | —- | C] () – C:\Windows\tasks\At31.job
[2011/12/09 14:36:44 | 000,000,354 | —- | C] () – C:\Windows\tasks\At28.job
[2011/12/09 14:36:44 | 000,000,354 | —- | C] () – C:\Windows\tasks\At26.job
[2011/12/09 14:36:44 | 000,000,354 | —- | C] () – C:\Windows\tasks\At24.job
[2011/12/09 14:36:44 | 000,000,352 | —- | C] () – C:\Windows\tasks\At29.job
[2011/12/09 14:36:44 | 000,000,352 | —- | C] () – C:\Windows\tasks\At27.job
[2011/12/09 14:36:44 | 000,000,352 | —- | C] () – C:\Windows\tasks\At25.job
[2011/12/09 14:36:44 | 000,000,352 | —- | C] () – C:\Windows\tasks\At23.job
[2011/12/09 14:36:43 | 000,000,354 | —- | C] () – C:\Windows\tasks\At22.job
[2011/12/09 14:36:43 | 000,000,354 | —- | C] () – C:\Windows\tasks\At20.job
[2011/12/09 14:36:43 | 000,000,354 | —- | C] () – C:\Windows\tasks\At18.job
[2011/12/09 14:36:43 | 000,000,352 | —- | C] () – C:\Windows\tasks\At21.job
[2011/12/09 14:36:43 | 000,000,352 | —- | C] () – C:\Windows\tasks\At19.job
[2011/12/09 14:36:42 | 000,000,354 | —- | C] () – C:\Windows\tasks\At16.job
[2011/12/09 14:36:42 | 000,000,354 | —- | C] () – C:\Windows\tasks\At14.job
[2011/12/09 14:36:42 | 000,000,352 | —- | C] () – C:\Windows\tasks\At17.job
[2011/12/09 14:36:42 | 000,000,352 | —- | C] () – C:\Windows\tasks\At15.job
[2011/12/09 14:36:41 | 000,000,354 | —- | C] () – C:\Windows\tasks\At12.job
[2011/12/09 14:36:41 | 000,000,354 | —- | C] () – C:\Windows\tasks\At10.job
[2011/12/09 14:36:41 | 000,000,352 | —- | C] () – C:\Windows\tasks\At9.job
[2011/12/09 14:36:41 | 000,000,352 | —- | C] () – C:\Windows\tasks\At13.job
[2011/12/09 14:36:41 | 000,000,352 | —- | C] () – C:\Windows\tasks\At11.job
[2011/12/09 14:36:40 | 000,000,354 | —- | C] () – C:\Windows\tasks\At8.job
[2011/12/09 14:36:40 | 000,000,354 | —- | C] () – C:\Windows\tasks\At6.job
[2011/12/09 14:36:40 | 000,000,354 | —- | C] () – C:\Windows\tasks\At4.job
[2011/12/09 14:36:40 | 000,000,352 | —- | C] () – C:\Windows\tasks\At7.job
[2011/12/09 14:36:40 | 000,000,352 | —- | C] () – C:\Windows\tasks\At5.job
[2011/12/09 14:36:40 | 000,000,352 | —- | C] () – C:\Windows\tasks\At3.job
[2011/12/09 14:36:39 | 000,000,354 | —- | C] () – C:\Windows\tasks\At2.job
[2011/12/09 14:36:39 | 000,000,352 | —- | C] () – C:\Windows\tasks\At1.job
[2011/12/09 14:25:01 | 000,011,542 | -HS- | C] () – C:\Users\meagon86\AppData\Local\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/09 14:25:01 | 000,011,542 | -HS- | C] () – C:\ProgramData\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/11/27 12:47:08 | 000,000,822 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/27 12:39:34 | 000,001,845 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2011/11/27 12:39:34 | 000,001,833 | —- | C] () – C:\Users\Public\Desktop\Opera.lnk
[2011/11/27 11:30:12 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/27 11:24:13 | 000,001,150 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/27 11:24:13 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/26 17:30:03 | 000,000,224 | -H– | C] () – C:\ProgramData\~zhyLWWVfWs51ofr
[2011/11/26 17:30:02 | 000,000,320 | -H– | C] () – C:\ProgramData\~zhyLWWVfWs51of
[2011/11/26 17:29:58 | 000,000,440 | -H– | C] () – C:\ProgramData\zhyLWWVfWs51of
[2011/04/18 11:43:03 | 000,000,268 | -H– | C] () – C:\Users\meagon86\AppData\Roaming\wklnhst.dat
[2010/11/23 14:49:43 | 000,000,000 | -H– | C] () – C:\Users\meagon86\AppData\Roaming\downloads.m3u
[2010/11/22 10:50:15 | 000,000,181 | —- | C] () – C:\Windows\WININIT.INI
[2010/01/30 14:00:39 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2010/01/30 13:28:33 | 000,000,029 | -H– | C] () – C:\Users\meagon86\AppData\Roaming\default.rss
[2010/01/30 12:39:56 | 000,004,767 | —- | C] () – C:\Windows\Irremote.ini
[2009/09/03 00:53:07 | 000,000,000 | —- | C] () – C:\Windows\VAIOUpdt.INI
[2009/08/18 18:16:10 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/08/18 17:46:36 | 000,982,220 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2009/08/18 17:46:34 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/08/18 17:46:34 | 000,092,216 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2009/08/18 17:46:33 | 000,439,300 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 23:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
< End of report >
Hijack This log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:24:44 PM, on 12/11/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16869)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe
D:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll (file missing)
O3 - Toolbar: FrostWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SmartWiHelper] "C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\RunOnce: [AutoLaunch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AutoLaunch.exe monthly
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: Intel® Sample Collector (SampleCollector) - Intel Corporation - C:\Program Files\Sony\VAIO Care\collsvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 10910 bytes
Mal Log
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8253
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
12/11/2011 2:25:46 PM
mbam-log-2011-12-11 (14-25-46).txt
Scan type: Quick scan
Objects scanned: 170188
Time elapsed: 5 minute(s), 8 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 11
Memory Processes Infected:
c:\Users\meagon86\AppData\Local\bjw.exe (Trojan.ExeShell.Gen) -> 824 -> Failed to unload process.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Privacy Protection (Rogue.PrvacyProtect) -> Value: Privacy Protection -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\meagon86\AppData\Local\bjw.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\meagon86\AppData\Local\bjw.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\meagon86\AppData\Local\bjw.exe" -a "C:\Program Files (x86)\Int") Good: (iexplore.exe) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\meagon86\AppData\Local\bjw.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
c:\Windows\System32\5a66sn04m.com (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\System32\5a66sn04m.com_ (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\SysWOW64\5a66sn04m.com (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\SysWOW64\5a66sn04m.com_ (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\Temp\hki10514.exe (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\Temp\hki10929.exe (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\Temp\kvcenk\setup.exe (Trojan.Email) -> Quarantined and deleted successfully.
c:\Users\meagon86\local settings\application data\bjw.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
c:\Users\meagon86\AppData\Local\Temp\0.5184897839241733.exe (Exploit.Drop.2) -> Quarantined and deleted successfully.
c:\Users\meagon86\AppData\Roaming\privacy.exe (Rogue.PrvacyProtect) -> Quarantined and deleted successfully.
Last run
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8352
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
12/11/2011 4:12:00 PM
mbam-log-2011-12-11 (16-12-00).txt
Scan type: Full scan (C:\|E:\|F:\|G:\|)
Objects scanned: 351472
Time elapsed: 44 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\assembly\temp\kwrd.dll (PUP.BitMiner) -> Quarantined and deleted successfully.
I including the OTL,Hijack, and Malwarbytes logs.
OTL Log
OTL logfile created on: 12/11/2011 4:25:18 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = D:\
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.84 Gb Total Physical Memory | 2.46 Gb Available Physical Memory | 63.90% Memory free
7.68 Gb Paging File | 6.08 Gb Available in Paging File | 79.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 290.37 Gb Total Space | 200.11 Gb Free Space | 68.92% Space Free | Partition Type: NTFS
Drive D: | 74.53 Gb Total Space | 6.01 Gb Free Space | 8.06% Space Free | Partition Type: NTFS
Computer Name: KILLAH-VAIO | User Name: meagon86 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/11 16:21:52 | 000,388,608 | —- | M] (Trend Micro Inc.) – D:\HiJackThis.exe
PRC - [2011/12/11 16:21:35 | 000,584,192 | —- | M] (OldTimer Tools) – D:\OTL.exe
PRC - [2011/04/18 17:21:43 | 001,643,272 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe
PRC - [2011/04/18 17:21:40 | 000,789,392 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/04/18 17:21:39 | 001,181,328 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/12/02 07:19:02 | 000,707,704 | —- | M] () – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWWSC.exe
PRC - [2009/09/01 16:32:12 | 000,087,344 | —- | M] (Prolific Technology Inc.) – C:\Windows\SysWOW64\IoctlSvc.exe
PRC - [2009/08/26 18:11:50 | 000,173,368 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
PRC - [2009/08/26 18:11:50 | 000,033,792 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
PRC - [2009/08/26 18:11:50 | 000,017,408 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
PRC - [2009/08/26 18:11:48 | 000,017,920 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
PRC - [2009/07/23 11:39:38 | 000,313,264 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
PRC - [2009/07/23 11:39:36 | 000,206,336 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
PRC - [2009/07/22 16:03:04 | 000,642,920 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
PRC - [2009/07/13 19:14:28 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\PING.EXE
PRC - [2009/07/01 12:49:34 | 000,204,648 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
PRC - [2009/07/01 12:49:34 | 000,112,488 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
PRC - [2009/06/18 15:19:30 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/06/04 20:03:32 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/04 20:03:06 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/05/26 10:23:14 | 000,317,288 | —- | M] (Sony Corporation) – C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2008/09/18 11:59:10 | 000,104,960 | —- | M] (ArcSoft, Inc.) – C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/27 13:39:42 | 011,807,744 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5a95ba97100404e2ab26b5a9ab9ef965\System.Web.ni.dll
MOD - [2011/11/27 13:39:34 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\018d2569cf208acbe8ad73908705f607\System.Runtime.Remoting.ni.dll
MOD - [2011/11/27 13:38:36 | 012,431,360 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll
MOD - [2011/11/27 13:38:24 | 001,586,688 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll
MOD - [2011/11/27 13:38:04 | 003,325,952 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll
MOD - [2011/11/27 13:37:58 | 005,452,800 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll
MOD - [2011/11/27 13:37:52 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll
MOD - [2011/11/27 13:37:50 | 007,949,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll
MOD - [2011/11/27 13:37:37 | 011,490,304 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll
MOD - [2011/05/04 16:34:29 | 003,178,496 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2011/04/18 17:21:49 | 000,087,496 | —- | M] () – C:\Program Files (x86)\Lavasoft\Ad-Aware\PrivacyClean.dll
MOD - [2011/03/29 16:31:57 | 005,025,792 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
MOD - [2009/08/26 18:11:50 | 000,120,320 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\SonyCommonLib.dll
MOD - [2009/08/26 18:11:50 | 000,081,408 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\DevicePanel.dll
MOD - [2009/08/26 18:11:50 | 000,033,792 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
MOD - [2009/08/26 18:11:50 | 000,027,648 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.BtPower.dll
MOD - [2009/08/26 18:11:50 | 000,023,040 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.Generic.dll
MOD - [2009/08/26 18:11:50 | 000,018,944 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\DictionaryLookup.dll
MOD - [2009/08/26 18:11:50 | 000,017,408 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
MOD - [2009/08/26 18:11:50 | 000,015,360 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.NativeWifiThirdPartyApp.dll
MOD - [2009/08/26 18:11:50 | 000,011,264 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.TosBtThirdPartyApp.dll
MOD - [2009/08/26 18:11:50 | 000,007,680 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\DebugMsg.dll
MOD - [2009/08/26 18:11:50 | 000,007,168 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.WlanPower.dll
MOD - [2009/08/26 18:11:50 | 000,005,120 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.ThirdPartyApp.dll
MOD - [2009/08/26 18:11:50 | 000,005,120 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.Generic.dll
MOD - [2009/08/26 18:11:50 | 000,004,608 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.Power.dll
MOD - [2009/08/26 18:11:48 | 000,017,920 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
MOD - [2009/08/26 18:11:48 | 000,015,360 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\SharedInterfaces.dll
MOD - [2009/08/26 18:11:48 | 000,011,264 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\MessageXML.dll
MOD - [2009/08/26 18:11:48 | 000,009,728 | —- | M] () – C:\Program Files (x86)\Sony\SmartWi Connection Utility\Resources.dll
MOD - [2009/07/13 19:15:51 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\syswow64\mswsock.dll
MOD - [2009/06/10 15:23:20 | 002,048,000 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2009/06/10 15:23:19 | 000,303,104 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2009/06/10 15:23:18 | 000,626,688 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
MOD - [2009/06/10 15:23:18 | 000,372,736 | —- | M] () – C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2009/08/22 15:19:06 | 000,411,496 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files\Sony\VAIO Power Management\SPMService.exe – (VAIO Power Management)
SRV:64bit: - [2009/07/23 22:34:31 | 000,189,984 | —- | M] (Realtek Semiconductor) [Auto | Running] – C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe – (RtkAudioService)
SRV:64bit: - [2009/06/26 15:56:10 | 000,357,672 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe – (VcmINSMgr)
SRV:64bit: - [2009/06/26 15:35:04 | 000,468,264 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe – (VcmIAlzMgr)
SRV:64bit: - [2009/06/17 19:50:30 | 000,110,888 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe – (VcmXmlIfHelper)
SRV:64bit: - [2008/09/29 17:06:32 | 000,167,424 | —- | M] (Intel Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\VAIO Care\collsvc.exe – (SampleCollector)
SRV - [2011/04/18 17:21:39 | 001,181,328 | —- | M] (Lavasoft) [Auto | Running] – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/09/01 16:32:12 | 000,087,344 | —- | M] (Prolific Technology Inc.) [Auto | Running] – C:\Windows\SysWOW64\IoctlSvc.exe – (PLFlash DeviceIoControl Service)
SRV - [2009/07/31 14:09:12 | 000,436,736 | —- | M] (Conexant Systems, Inc.) [Auto | Stopped] – C:\Windows\SysWOW64\XAudio64.dll – (HsfXAudioService)
SRV - [2009/07/27 17:58:40 | 000,091,432 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe – (SOHPlMgr)
SRV - [2009/07/27 17:58:38 | 000,427,304 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe – (SOHDms)
SRV - [2009/07/27 17:58:38 | 000,075,048 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe – (SOHDs)
SRV - [2009/07/27 17:58:38 | 000,070,952 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe – (SOHDBSvr)
SRV - [2009/07/27 17:58:36 | 000,120,104 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe – (SOHCImp)
SRV - [2009/07/23 11:39:38 | 000,313,264 | —- | M] (Sony Corporation) [On_Demand | Running] – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe – (Vcsw)
SRV - [2009/07/23 11:39:38 | 000,069,632 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe – (VAIO Entertainment TV Device Arbitration Service)
SRV - [2009/07/23 11:39:36 | 000,206,336 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe – (VzCdbSvc)
SRV - [2009/07/22 16:03:04 | 000,642,920 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe – (VCFw)
SRV - [2009/07/01 12:49:34 | 000,204,648 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe – (VAIO Event Service)
SRV - [2009/06/18 15:19:30 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2009/06/10 15:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 20:03:06 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/02/06 18:02:14 | 000,109,056 | —- | M] (ArcSoft Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2008/09/18 11:59:10 | 000,104,960 | —- | M] (ArcSoft, Inc.) [Auto | Running] – C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe – (uCamMonitor)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/03/11 00:22:41 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 00:22:40 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/02/18 15:36:58 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2010/04/16 20:24:34 | 000,027,536 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d) MS Hardware Device Detection Driver (HID)
DRV:64bit: - [2010/01/30 12:20:49 | 000,069,152 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\Lbd.sys – (Lbd)
DRV:64bit: - [2009/08/04 19:22:40 | 000,139,264 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV:64bit: - [2009/08/04 19:20:51 | 007,345,632 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/08/03 14:06:34 | 000,250,928 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Apfiltr.sys – (ApfiltrService)
DRV:64bit: - [2009/07/31 14:29:11 | 001,484,800 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/07/31 14:14:14 | 000,076,288 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\risdsn64.sys – (risdptsk)
DRV:64bit: - [2009/07/31 14:13:51 | 000,086,528 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\rimssn64.sys – (rimsptsk)
DRV:64bit: - [2009/07/31 14:09:12 | 000,010,240 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\XAudio64.sys – (XAudio)
DRV:64bit: - [2009/07/31 14:09:08 | 000,017,024 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\mdmxsdk.sys – (mdmxsdk)
DRV:64bit: - [2009/07/31 14:02:03 | 000,393,216 | —- | M] (Marvell) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:64bit: - [2009/07/27 14:27:10 | 006,037,504 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/07/23 23:24:03 | 000,201,472 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtHDMIVX.sys – (RTHDMIAzAudService)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:31:10 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2009/06/11 14:19:09 | 000,011,392 | —- | M] (Sony Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SFEP.sys – (SFEP)
DRV:64bit: - [2009/06/10 15:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 15:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 15:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 14:35:28 | 005,434,368 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netw5v64.sys – (netw5v64) Intel®
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 19:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/05/26 15:32:04 | 000,019,968 | —- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys – (ArcSoftKsUFilter)
DRV:64bit: - [2009/05/20 04:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2009/07/13 19:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…T&bmod;=SNNT
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…T&bmod;=SNNT
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…T&bmod;=SNNT
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "BearShare Web Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=634471"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=634471&p;="
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/27 11:24:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/11/21 17:10:51 | 000,000,000 | —D | M]
[2010/04/18 20:59:21 | 000,000,000 | -H-D | M] (No name found) – C:\Users\meagon86\AppData\Roaming\Mozilla\Extensions
[2010/01/30 13:49:53 | 000,000,000 | -H-D | M] (No name found) – C:\Users\meagon86\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/11/27 11:24:38 | 000,000,000 | —D | M] (No name found) – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\extensions
[2011/11/27 11:24:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/27 12:15:14 | 000,000,000 | —D | M] (MediaBar) – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593}
[2010/11/21 14:43:44 | 000,002,568 | -H– | M] () – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\searchplugins\askcom.xml
[2010/09/14 06:41:12 | 000,002,506 | -H– | M] () – C:\Users\meagon86\AppData\Roaming\Mozilla\Firefox\Profiles\l853t9j7.default\searchplugins\BearShareWebSearch.xml
[2011/11/27 11:24:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/27 11:24:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2011/11/27 11:24:03 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/05 00:53:18 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/09/14 06:41:12 | 000,002,506 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\BearShareWebSearch.xml
[2011/11/04 21:21:03 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/04 21:21:03 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
Hosts file not found
O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll File not found
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SmartWiHelper] C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe (Sony Electronics Corporation)
O4 - HKCU..\RunOnce: [AutoLaunch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AutoLaunch.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4663E24F-3089-4E27-A1DB-886BC3E53AC6}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\Windows\SysWow64\VESWinlogon.dll (Sony Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/04 07:57:48 | 000,000,084 | RH– | M] () - D:\AutoRun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2011/12/11 16:26:00 | 009,851,496 | —- | C] (Malwarebytes Corporation ) – C:\Users\meagon86\Desktop\mbam-setup.exe
[2011/12/11 16:26:00 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\meagon86\Desktop\OTL.exe
[2011/12/11 16:26:00 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\meagon86\Desktop\HiJackThis.exe
[2011/12/11 14:18:36 | 000,000,000 | —D | C] – C:\Users\meagon86\AppData\Local\ElevatedDiagnostics
[2011/12/09 14:25:18 | 000,000,000 | —D | C] – C:\Windows\system64
[2011/11/27 12:47:07 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/11/27 12:39:38 | 000,000,000 | —D | C] – C:\Users\meagon86\AppData\Roaming\Opera
[2011/11/27 12:39:38 | 000,000,000 | —D | C] – C:\Users\meagon86\AppData\Local\Opera
[2011/11/27 12:39:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Opera
[2011/11/27 11:30:27 | 000,000,000 | —D | C] – C:\Users\meagon86\AppData\Roaming\Malwarebytes
[2011/11/27 11:30:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/27 11:30:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/27 11:30:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/27 11:28:22 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/11/27 11:28:21 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/11/27 11:28:21 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/11/27 11:28:19 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/11/27 11:28:18 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/11/27 11:28:18 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/11/27 11:28:18 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/11/27 11:28:17 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/11/27 11:28:17 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/11/27 11:28:16 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/11/27 11:28:16 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/11/27 11:28:16 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/11/27 11:28:16 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/11/27 11:28:16 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/11/27 11:28:16 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/11/27 11:27:15 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/11/27 11:27:15 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/11/27 11:27:15 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/11/27 11:27:15 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/11/27 11:27:15 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/11/27 11:27:15 | 000,104,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/11/27 11:27:15 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/11/27 11:27:15 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/11/27 11:27:15 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/11/27 11:27:14 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/11/27 11:27:11 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/11/27 11:27:11 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
========== Files - Modified Within 30 Days ==========
[2011/12/11 16:27:16 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/12/11 16:22:41 | 000,625,664 | —- | M] () – C:\Users\meagon86\Desktop\dds.scr
[2011/12/11 16:21:52 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\meagon86\Desktop\HiJackThis.exe
[2011/12/11 16:21:35 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\meagon86\Desktop\OTL.exe
[2011/12/11 16:20:28 | 000,014,144 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/11 16:20:28 | 000,014,144 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/11 16:20:16 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/11 16:20:16 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/11 16:20:16 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/11 16:13:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/11 16:13:06 | 3094,622,208 | -HS- | M] () – C:\hiberfil.sys
[2011/12/11 15:32:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At32.job
[2011/12/11 15:32:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At31.job
[2011/12/11 14:38:08 | 000,011,542 | -HS- | M] () – C:\Users\meagon86\AppData\Local\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/11 14:38:08 | 000,011,542 | -HS- | M] () – C:\ProgramData\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/11 14:32:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At30.job
[2011/12/11 14:32:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At29.job
[2011/12/09 23:32:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At48.job
[2011/12/09 23:32:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At47.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At8.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At6.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At46.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At44.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At42.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At40.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At4.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At38.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At36.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At34.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At28.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At26.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At24.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At22.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At20.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At2.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At18.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At16.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At14.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At12.job
[2011/12/09 23:02:48 | 000,000,354 | —- | M] () – C:\Windows\tasks\At10.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At9.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At7.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At5.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At45.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At43.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At41.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At39.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At37.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At35.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At33.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At3.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At27.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At25.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At23.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At21.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At19.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At17.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At15.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At13.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At11.job
[2011/12/09 23:02:48 | 000,000,352 | —- | M] () – C:\Windows\tasks\At1.job
[2011/12/09 14:51:53 | 000,000,112 | —- | M] () – C:\ProgramData\268J82.dat
[2011/12/09 14:44:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\5A66SN04M.com.b
[2011/11/27 13:35:37 | 000,363,928 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/27 12:47:08 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/27 12:39:34 | 000,001,833 | —- | M] () – C:\Users\Public\Desktop\Opera.lnk
[2011/11/27 11:30:12 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/27 11:24:13 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/26 17:43:44 | 000,000,320 | -H– | M] () – C:\ProgramData\~zhyLWWVfWs51of
[2011/11/26 17:43:44 | 000,000,224 | -H– | M] () – C:\ProgramData\~zhyLWWVfWs51ofr
[2011/11/26 17:43:33 | 000,000,440 | -H– | M] () – C:\ProgramData\zhyLWWVfWs51of
[2011/11/14 17:44:47 | 009,851,496 | —- | M] (Malwarebytes Corporation ) – C:\Users\meagon86\Desktop\mbam-setup.exe
========== Files Created - No Company Name ==========
[2011/12/11 16:26:00 | 000,625,664 | —- | C] () – C:\Users\meagon86\Desktop\dds.scr
[2011/12/09 14:44:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\5A66SN04M.com.b
[2011/12/09 14:36:48 | 000,000,112 | —- | C] () – C:\ProgramData\268J82.dat
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At48.job
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At46.job
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At44.job
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At42.job
[2011/12/09 14:36:47 | 000,000,354 | —- | C] () – C:\Windows\tasks\At40.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At47.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At45.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At43.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At41.job
[2011/12/09 14:36:47 | 000,000,352 | —- | C] () – C:\Windows\tasks\At39.job
[2011/12/09 14:36:46 | 000,000,354 | —- | C] () – C:\Windows\tasks\At38.job
[2011/12/09 14:36:46 | 000,000,354 | —- | C] () – C:\Windows\tasks\At36.job
[2011/12/09 14:36:46 | 000,000,354 | —- | C] () – C:\Windows\tasks\At34.job
[2011/12/09 14:36:46 | 000,000,352 | —- | C] () – C:\Windows\tasks\At37.job
[2011/12/09 14:36:46 | 000,000,352 | —- | C] () – C:\Windows\tasks\At35.job
[2011/12/09 14:36:45 | 000,000,354 | —- | C] () – C:\Windows\tasks\At32.job
[2011/12/09 14:36:45 | 000,000,354 | —- | C] () – C:\Windows\tasks\At30.job
[2011/12/09 14:36:45 | 000,000,352 | —- | C] () – C:\Windows\tasks\At33.job
[2011/12/09 14:36:45 | 000,000,352 | —- | C] () – C:\Windows\tasks\At31.job
[2011/12/09 14:36:44 | 000,000,354 | —- | C] () – C:\Windows\tasks\At28.job
[2011/12/09 14:36:44 | 000,000,354 | —- | C] () – C:\Windows\tasks\At26.job
[2011/12/09 14:36:44 | 000,000,354 | —- | C] () – C:\Windows\tasks\At24.job
[2011/12/09 14:36:44 | 000,000,352 | —- | C] () – C:\Windows\tasks\At29.job
[2011/12/09 14:36:44 | 000,000,352 | —- | C] () – C:\Windows\tasks\At27.job
[2011/12/09 14:36:44 | 000,000,352 | —- | C] () – C:\Windows\tasks\At25.job
[2011/12/09 14:36:44 | 000,000,352 | —- | C] () – C:\Windows\tasks\At23.job
[2011/12/09 14:36:43 | 000,000,354 | —- | C] () – C:\Windows\tasks\At22.job
[2011/12/09 14:36:43 | 000,000,354 | —- | C] () – C:\Windows\tasks\At20.job
[2011/12/09 14:36:43 | 000,000,354 | —- | C] () – C:\Windows\tasks\At18.job
[2011/12/09 14:36:43 | 000,000,352 | —- | C] () – C:\Windows\tasks\At21.job
[2011/12/09 14:36:43 | 000,000,352 | —- | C] () – C:\Windows\tasks\At19.job
[2011/12/09 14:36:42 | 000,000,354 | —- | C] () – C:\Windows\tasks\At16.job
[2011/12/09 14:36:42 | 000,000,354 | —- | C] () – C:\Windows\tasks\At14.job
[2011/12/09 14:36:42 | 000,000,352 | —- | C] () – C:\Windows\tasks\At17.job
[2011/12/09 14:36:42 | 000,000,352 | —- | C] () – C:\Windows\tasks\At15.job
[2011/12/09 14:36:41 | 000,000,354 | —- | C] () – C:\Windows\tasks\At12.job
[2011/12/09 14:36:41 | 000,000,354 | —- | C] () – C:\Windows\tasks\At10.job
[2011/12/09 14:36:41 | 000,000,352 | —- | C] () – C:\Windows\tasks\At9.job
[2011/12/09 14:36:41 | 000,000,352 | —- | C] () – C:\Windows\tasks\At13.job
[2011/12/09 14:36:41 | 000,000,352 | —- | C] () – C:\Windows\tasks\At11.job
[2011/12/09 14:36:40 | 000,000,354 | —- | C] () – C:\Windows\tasks\At8.job
[2011/12/09 14:36:40 | 000,000,354 | —- | C] () – C:\Windows\tasks\At6.job
[2011/12/09 14:36:40 | 000,000,354 | —- | C] () – C:\Windows\tasks\At4.job
[2011/12/09 14:36:40 | 000,000,352 | —- | C] () – C:\Windows\tasks\At7.job
[2011/12/09 14:36:40 | 000,000,352 | —- | C] () – C:\Windows\tasks\At5.job
[2011/12/09 14:36:40 | 000,000,352 | —- | C] () – C:\Windows\tasks\At3.job
[2011/12/09 14:36:39 | 000,000,354 | —- | C] () – C:\Windows\tasks\At2.job
[2011/12/09 14:36:39 | 000,000,352 | —- | C] () – C:\Windows\tasks\At1.job
[2011/12/09 14:25:01 | 000,011,542 | -HS- | C] () – C:\Users\meagon86\AppData\Local\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/09 14:25:01 | 000,011,542 | -HS- | C] () – C:\ProgramData\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/11/27 12:47:08 | 000,000,822 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/27 12:39:34 | 000,001,845 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2011/11/27 12:39:34 | 000,001,833 | —- | C] () – C:\Users\Public\Desktop\Opera.lnk
[2011/11/27 11:30:12 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/27 11:24:13 | 000,001,150 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/27 11:24:13 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/26 17:30:03 | 000,000,224 | -H– | C] () – C:\ProgramData\~zhyLWWVfWs51ofr
[2011/11/26 17:30:02 | 000,000,320 | -H– | C] () – C:\ProgramData\~zhyLWWVfWs51of
[2011/11/26 17:29:58 | 000,000,440 | -H– | C] () – C:\ProgramData\zhyLWWVfWs51of
[2011/04/18 11:43:03 | 000,000,268 | -H– | C] () – C:\Users\meagon86\AppData\Roaming\wklnhst.dat
[2010/11/23 14:49:43 | 000,000,000 | -H– | C] () – C:\Users\meagon86\AppData\Roaming\downloads.m3u
[2010/11/22 10:50:15 | 000,000,181 | —- | C] () – C:\Windows\WININIT.INI
[2010/01/30 14:00:39 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2010/01/30 13:28:33 | 000,000,029 | -H– | C] () – C:\Users\meagon86\AppData\Roaming\default.rss
[2010/01/30 12:39:56 | 000,004,767 | —- | C] () – C:\Windows\Irremote.ini
[2009/09/03 00:53:07 | 000,000,000 | —- | C] () – C:\Windows\VAIOUpdt.INI
[2009/08/18 18:16:10 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/08/18 17:46:36 | 000,982,220 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2009/08/18 17:46:34 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/08/18 17:46:34 | 000,092,216 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2009/08/18 17:46:33 | 000,439,300 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 23:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
< End of report >
Hijack This log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:24:44 PM, on 12/11/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16869)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe
D:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll (file missing)
O3 - Toolbar: FrostWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SmartWiHelper] "C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\RunOnce: [AutoLaunch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AutoLaunch.exe monthly
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: Intel® Sample Collector (SampleCollector) - Intel Corporation - C:\Program Files\Sony\VAIO Care\collsvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 10910 bytes
Mal Log
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8253
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
12/11/2011 2:25:46 PM
mbam-log-2011-12-11 (14-25-46).txt
Scan type: Quick scan
Objects scanned: 170188
Time elapsed: 5 minute(s), 8 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 11
Memory Processes Infected:
c:\Users\meagon86\AppData\Local\bjw.exe (Trojan.ExeShell.Gen) -> 824 -> Failed to unload process.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Privacy Protection (Rogue.PrvacyProtect) -> Value: Privacy Protection -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\meagon86\AppData\Local\bjw.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\meagon86\AppData\Local\bjw.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\meagon86\AppData\Local\bjw.exe" -a "C:\Program Files (x86)\Int") Good: (iexplore.exe) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\meagon86\AppData\Local\bjw.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
c:\Windows\System32\5a66sn04m.com (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\System32\5a66sn04m.com_ (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\SysWOW64\5a66sn04m.com (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\SysWOW64\5a66sn04m.com_ (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\Temp\hki10514.exe (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\Temp\hki10929.exe (Trojan.Email) -> Quarantined and deleted successfully.
c:\Windows\Temp\kvcenk\setup.exe (Trojan.Email) -> Quarantined and deleted successfully.
c:\Users\meagon86\local settings\application data\bjw.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
c:\Users\meagon86\AppData\Local\Temp\0.5184897839241733.exe (Exploit.Drop.2) -> Quarantined and deleted successfully.
c:\Users\meagon86\AppData\Roaming\privacy.exe (Rogue.PrvacyProtect) -> Quarantined and deleted successfully.
Last run
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8352
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
12/11/2011 4:12:00 PM
mbam-log-2011-12-11 (16-12-00).txt
Scan type: Full scan (C:\|E:\|F:\|G:\|)
Objects scanned: 351472
Time elapsed: 44 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\assembly\temp\kwrd.dll (PUP.BitMiner) -> Quarantined and deleted successfully.