This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible PING.exe infection [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello and thanks in advance for any help you all can give. My issue is with the PING.exe program
running in the background. I use task manager regularly and know it is a very recent thing to pop
up in my tasks. Whatever is using it is slowing down my computer and redirecting any google links
to different websites than the ones I clicked on. TDSSkiller found nothing wrong with my computer
on two runs with it, although I have yet to run a comodo scan to determine if that can remedy the
situation. Comodo did manage to quarantine a plethora of malware, but it just keeps reappearing
in the temp folder leading me to believe it is something else taking a hold. Before anything, I
would appreciate knowing if I should try and limit my internet connection for this computer
because my household has other connections running that I don't want to infect. Below are my log
files. Thanks again, I hope to hear back soon!


OTL logfile created on: 12/16/2011 3:21:50 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Joseph\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.28 Gb Available Physical Memory | 57.00% Memory free
7.99 Gb Paging File | 6.20 Gb Available in Paging File | 77.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 298.09 Gb Total Space | 14.38 Gb Free Space | 4.82% Space Free | Partition Type: NTFS
Drive E: | 232.88 Gb Total Space | 8.34 Gb Free Space | 3.58% Space Free | Partition Type: NTFS

Computer Name: JOSEPH-PC | User Name: Joseph | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Joseph\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe ()
PRC - C:\Program Files (x86)\Lexmark 2600 Series\lxdnmsdmon.exe ()
PRC - C:\Windows\SysWOW64\PING.EXE (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll ()
MOD - C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\avutil-51.dll ()
MOD - C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\avformat-53.dll ()
MOD - C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\avcodec-53.dll ()
MOD - C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdnmsdmon.exe ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\app4r.monitor.core.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\app4r.monitor.common.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdndrs.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdnscw.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdncaps.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdncnv4.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdndatr.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdncats.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (CLPSLS) – C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe (COMODO)
SRV:64bit: - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (lxdnCATSCustConnectService) – C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxdnserv.exe ()
SRV:64bit: - (lxdn_device) – C:\Windows\SysNative\lxdncoms.exe ( )
SRV:64bit: - (O2FLASH) – C:\Windows\SysNative\drivers\o2flash.exe (O2Micro International)
SRV - (Desura Install Service) – C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HsfXAudioService) – C:\Windows\SysWOW64\XAudio64.dll (Conexant Systems, Inc.)
SRV - (lxdn_device) – C:\Windows\SysWow64\lxdncoms.exe ( )


========== Driver Services (SafeList) ==========

DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (cmderd) – C:\Windows\SysNative\drivers\cmderd.sys (COMODO)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (atksgt) – C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:64bit: - (lirsgt) – C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (cpuz135) – C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (appliandMP) – C:\Windows\SysNative\drivers\appliand.sys (Applian Technologies Inc.)
DRV:64bit: - (appliand) – C:\Windows\SysNative\drivers\appliand.sys (Applian Technologies Inc.)
DRV:64bit: - (NETw5s64) Intel® – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (O2SDRDR) – C:\Windows\SysNative\drivers\o2sdx64.sys (O2Micro )
DRV:64bit: - (O2MDRDR) – C:\Windows\SysNative\drivers\o2mdx64.sys (O2Micro )
DRV:64bit: - (XAudio) – C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 22 84 43 70 AC A5 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@onlive.com/OlGameDetect,version=1.1.0.70351: C:\Program Files (x86)\OnLive\FirefoxPlugin\npolgdet.dll (OnLive)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Joseph\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Joseph\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Joseph\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)



========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Battlefield Play4Free Updater (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.53.2_0\npBP4FUpdater.dll
CHR - plugin: Battlefield Play4Free Updater (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.53.2_0\BP4FUpdater.exe
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: OnLive Games Service Detector for Firefox (Enabled) = C:\Program Files (x86)\OnLive\FirefoxPlugin\npolgdet.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Joseph\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Joseph\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.7_0\
CHR - Extension: 3DTin = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\algoakekcdmbbikdjgjdahbfihboglmi\0.97_0\
CHR - Extension: Isle of Tune = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\bljldflafhmbedhjnlncilbhfcnfabgb\1_0\
CHR - Extension: Battlefield Play4Free = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.53.2_0\
CHR - Extension: Gamux = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhjfcocbebjediffgmnknicggaemomh\2.0.2_0\
CHR - Extension: Poppit = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: RSS Subscription Extension (by Google) = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd\2.1.3_0\
CHR - Extension: NESbox = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\oanegjalpoiojbhpoajhjeohnaigdgdi\2.0.0.0_0\
CHR - Extension: Atari - Missile Command = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\oobnopfjjndfekinfcddimnjbhjdgmbg\1.0_0\

O1 HOSTS File: ([2011/12/16 00:08:20 | 000,000,000 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4:64bit: - HKLM..\Run: [lxdnamon] C:\Program Files (x86)\Lexmark 2600 Series\lxdnamon.exe ()
O4:64bit: - HKLM..\Run: [lxdnmon.exe] C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe ()
O4:64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()
O8 - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75E67AC0-70CA-4BAD-AC15-7A31CF144F87}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AC9BC976-F35A-438A-8CB8-5726178E8961}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) -C:\Windows\SysWOW64\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1f4172b3-d713-11e0-aeec-001d72f34bd1}\Shell - "" = AutoRun
O33 - MountPoints2\{1f4172b3-d713-11e0-aeec-001d72f34bd1}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{54ea877b-01b2-11e1-ac5a-001d72f34bd1}\Shell - "" = AutoRun
O33 - MountPoints2\{54ea877b-01b2-11e1-ac5a-001d72f34bd1}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{d79c86ab-4675-11e0-b3d1-001d72f34bd1}\Shell - "" = AutoRun
O33 - MountPoints2\{d79c86ab-4675-11e0-b3d1-001d72f34bd1}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/16 02:53:35 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\Virus Things
[2011/12/16 02:38:57 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Joseph\Desktop\HiJackThis.exe
[2011/12/16 02:38:50 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Joseph\Desktop\OTL.exe
[2011/12/16 00:31:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/16 00:31:05 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/12/16 00:31:05 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/16 00:27:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/12/16 00:26:04 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/12/15 15:29:51 | 000,000,000 | —D | C] – C:\Users\Joseph\Documents\WB Games
[2011/12/15 15:23:10 | 000,000,000 | —D | C] – C:\Windows\system64
[2011/12/15 14:45:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Batman - Arkham City
[2011/12/15 14:18:39 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\FreeArc
[2011/12/15 14:18:26 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeArc
[2011/12/15 14:18:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeArc
[2011/12/15 14:18:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\FreeArc
[2011/12/15 01:44:59 | 006,004,544 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2011/12/15 01:44:59 | 003,028,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2011/12/15 01:44:59 | 002,562,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2011/12/15 01:44:59 | 000,118,080 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2011/12/15 01:44:59 | 000,063,296 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2011/12/15 01:44:02 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2011/12/15 01:40:53 | 025,432,384 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/12/15 01:40:53 | 019,348,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/12/15 01:40:53 | 009,622,848 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2011/12/15 01:40:53 | 007,677,248 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/12/15 01:40:53 | 001,466,176 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/12/15 01:40:52 | 025,137,472 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/12/15 01:40:52 | 017,498,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/12/15 01:40:52 | 017,474,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/12/15 01:40:52 | 014,854,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2011/12/15 01:40:52 | 007,974,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/12/15 01:40:52 | 005,868,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/12/15 01:40:52 | 002,660,160 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/12/15 01:40:52 | 002,506,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/12/15 01:40:52 | 002,403,136 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2011/12/15 01:40:52 | 002,374,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/12/15 01:40:52 | 002,206,016 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/12/15 01:40:52 | 002,095,424 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2011/12/15 01:40:52 | 001,726,272 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/12/15 01:40:52 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/12/15 01:40:52 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/12/15 01:38:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2011/12/15 01:27:49 | 001,451,840 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420103.dll
[2011/12/15 01:27:49 | 000,187,200 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2011/12/15 01:27:49 | 000,072,512 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapo64v.dll
[2011/12/15 01:27:49 | 000,031,040 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2011/12/14 03:02:05 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/14 03:02:05 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/14 03:02:04 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/14 03:02:04 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/14 03:02:03 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/14 03:02:03 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/14 03:02:02 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/12/14 03:02:02 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/14 03:02:02 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/14 03:02:02 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/12/14 03:02:02 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/12/13 17:55:34 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/13 17:54:51 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/13 17:54:51 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/09 23:01:19 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\A
[2011/12/08 01:26:58 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\To the Moon - Freebird Games
[2011/12/08 01:24:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\To the Moon
[2011/12/08 01:23:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\To the Moon
[2011/12/05 14:34:06 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\redsn0w
[2011/12/05 14:33:49 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\Untethered Jailbreak iOS 5.0.1
[2011/12/05 12:43:39 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011/12/05 12:43:39 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011/12/05 12:43:39 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/12/05 12:41:46 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/12/05 12:41:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/12/05 11:34:56 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\Backups
[2011/11/29 13:25:20 | 000,000,000 | —D | C] – C:\ProgramData\CPA_VA
[2011/11/25 23:13:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\id Software
[2011/11/25 23:13:25 | 000,000,000 | —D | C] – C:\ProgramData\id Software
[2011/11/25 16:48:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\BOSS
[2011/11/24 22:29:22 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Local\Oblivion
[2011/11/23 21:53:18 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\digipen
[2011/11/23 21:53:18 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Local\digipen
[2011/11/23 21:06:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Digipen
[2011/11/23 21:03:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Digipen
[2011/11/18 00:15:11 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\project4
[2011/11/16 13:13:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty Modern Warfare 3
[2011/11/16 12:13:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Black_Box
[2011/11/16 12:07:12 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\Algorithms
[2011/01/17 19:59:02 | 000,647,168 | —- | C] ( ) – C:\Windows\SysWow64\lxdnpmui.dll
[2011/01/17 19:59:02 | 000,364,544 | —- | C] ( ) – C:\Windows\SysWow64\lxdninpa.dll
[2011/01/17 19:59:02 | 000,339,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdniesc.dll
[2011/01/17 19:59:01 | 001,101,824 | —- | C] ( ) – C:\Windows\SysWow64\lxdnserv.dll
[2011/01/17 19:59:01 | 000,843,776 | —- | C] ( ) – C:\Windows\SysWow64\lxdnusb1.dll
[2011/01/17 19:59:01 | 000,569,344 | —- | C] ( ) – C:\Windows\SysWow64\lxdnlmpm.dll
[2011/01/17 19:59:01 | 000,315,392 | —- | C] ( ) – C:\Windows\SysWow64\lxdnih.exe
[2011/01/17 19:59:01 | 000,053,248 | —- | C] ( ) – C:\Windows\SysWow64\lxdnprox.dll
[2011/01/17 19:59:00 | 000,851,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdncomc.dll
[2011/01/17 19:59:00 | 000,663,552 | —- | C] ( ) – C:\Windows\SysWow64\lxdnhbn3.dll
[2011/01/17 19:59:00 | 000,589,824 | —- | C] ( ) – C:\Windows\SysWow64\lxdncoms.exe
[2011/01/17 19:59:00 | 000,376,832 | —- | C] ( ) – C:\Windows\SysWow64\lxdncomm.dll
[2011/01/17 19:59:00 | 000,360,448 | —- | C] ( ) – C:\Windows\SysWow64\lxdncfg.exe
[2011/01/05 22:41:39 | 000,121,344 | —- | C] ( ) – C:\Windows\SysWow64\lagarith.dll
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/16 03:16:57 | 001,474,832 | —- | M] () – C:\Windows\SysNative\drivers\sfi.dat
[2011/12/16 03:04:35 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/16 03:04:35 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/16 02:57:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/16 02:57:00 | 3217,199,104 | -HS- | M] () – C:\hiberfil.sys
[2011/12/16 02:39:14 | 000,625,664 | —- | M] () – C:\Users\Joseph\Desktop\dds.scr
[2011/12/16 02:38:57 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Joseph\Desktop\HiJackThis.exe
[2011/12/16 02:38:51 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Joseph\Desktop\OTL.exe
[2011/12/16 02:17:59 | 001,557,791 | —- | M] () – C:\Users\Joseph\Desktop\tdsskiller.zip
[2011/12/16 01:50:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3141220578-551946994-1010253117-1000UA.job
[2011/12/16 00:31:43 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/12/16 00:08:20 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/12/15 14:18:26 | 000,001,097 | —- | M] () – C:\Users\Joseph\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeArc.lnk
[2011/12/15 14:18:26 | 000,001,073 | —- | M] () – C:\Users\Joseph\Desktop\FreeArc.lnk
[2011/12/15 10:50:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3141220578-551946994-1010253117-1000Core.job
[2011/12/14 18:51:15 | 000,002,364 | —- | M] () – C:\Users\Joseph\Desktop\Google Chrome.lnk
[2011/12/14 18:34:15 | 002,641,064 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/14 18:34:15 | 000,688,546 | —- | M] () – C:\Windows\SysNative\perfh00C.dat
[2011/12/14 18:34:15 | 000,660,530 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/14 18:34:15 | 000,477,400 | —- | M] () – C:\Windows\SysNative\perfh001.dat
[2011/12/14 18:34:15 | 000,383,288 | —- | M] () – C:\Windows\SysNative\prfh0804.dat
[2011/12/14 18:34:15 | 000,129,176 | —- | M] () – C:\Windows\SysNative\perfc00C.dat
[2011/12/14 18:34:15 | 000,121,426 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/14 18:34:15 | 000,119,286 | —- | M] () – C:\Windows\SysNative\prfc0804.dat
[2011/12/14 18:34:15 | 000,094,022 | —- | M] () – C:\Windows\SysNative\perfc001.dat
[2011/12/14 18:28:04 | 000,310,408 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/11 16:10:36 | 000,000,600 | —- | M] () – C:\Users\Joseph\AppData\Local\PUTTY.RND
[2011/12/09 23:50:30 | 000,010,382 | —- | M] () – C:\Users\Joseph\Desktop\Joseph_Zelada_4c_Code.c
[2011/12/09 23:50:27 | 000,012,864 | —- | M] () – C:\Users\Joseph\Desktop\Joseph_Zelada_2c_Code.c
[2011/12/09 23:50:22 | 000,013,203 | —- | M] () – C:\Users\Joseph\Desktop\Joseph_Zelada_1b_Code.c
[2011/12/09 23:47:27 | 000,021,293 | —- | M] () – C:\Users\Joseph\Desktop\Untitled 1.odt
[2011/12/09 23:47:20 | 000,039,026 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.pdf
[2011/12/09 05:26:28 | 000,010,373 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.c
[2011/12/09 05:26:15 | 000,030,391 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.exe
[2011/12/09 05:26:15 | 000,006,784 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.o
[2011/12/08 16:29:34 | 000,121,449 | —- | M] () – C:\Users\Joseph\Desktop\Final_ProjectF11.pdf
[2011/12/08 15:36:44 | 000,001,083 | —- | M] () – C:\Users\Joseph\Documents - Shortcut.lnk
[2011/12/08 01:24:25 | 000,291,827 | —- | M] () – C:\Windows\To the Moon Uninstaller.exe
[2011/12/03 00:37:44 | 000,028,961 | —- | M] () – C:\Users\Joseph\Desktop\Ethics Module.odt
[2011/11/27 00:04:02 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/11/25 22:29:44 | 000,000,023 | —- | M] () – C:\Windows\BlendSettings.ini
[2011/11/23 22:59:00 | 025,432,384 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/11/23 22:59:00 | 025,137,472 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/11/23 22:59:00 | 019,348,800 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/11/23 22:59:00 | 017,498,432 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/11/23 22:59:00 | 017,474,368 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/11/23 22:59:00 | 014,854,464 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2011/11/23 22:59:00 | 009,622,848 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2011/11/23 22:59:00 | 007,974,208 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/11/23 22:59:00 | 007,677,248 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/11/23 22:59:00 | 005,868,352 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/11/23 22:59:00 | 002,660,160 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/11/23 22:59:00 | 002,506,048 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/11/23 22:59:00 | 002,403,136 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2011/11/23 22:59:00 | 002,374,464 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/11/23 22:59:00 | 002,206,016 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/11/23 22:59:00 | 002,095,424 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2011/11/23 22:59:00 | 001,726,272 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/11/23 22:59:00 | 001,466,176 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/11/23 22:59:00 | 000,068,928 | —- | M] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/11/23 22:59:00 | 000,061,248 | —- | M] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/11/23 22:59:00 | 000,007,653 | —- | M] () – C:\Windows\SysNative\nvinfo.pb
[2011/11/23 20:47:47 | 006,004,544 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2011/11/23 20:41:24 | 003,028,800 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2011/11/23 20:38:53 | 002,562,368 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2011/11/23 20:38:44 | 000,118,080 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2011/11/23 20:38:44 | 000,063,296 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/16 02:39:13 | 000,625,664 | —- | C] () – C:\Users\Joseph\Desktop\dds.scr
[2011/12/16 02:17:46 | 001,557,791 | —- | C] () – C:\Users\Joseph\Desktop\tdsskiller.zip
[2011/12/16 00:31:43 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/12/15 14:18:26 | 000,001,097 | —- | C] () – C:\Users\Joseph\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeArc.lnk
[2011/12/15 14:18:26 | 000,001,073 | —- | C] () – C:\Users\Joseph\Desktop\FreeArc.lnk
[2011/12/15 01:40:53 | 000,007,653 | —- | C] () – C:\Windows\SysNative\nvinfo.pb
[2011/12/09 23:50:30 | 000,010,382 | —- | C] () – C:\Users\Joseph\Desktop\Joseph_Zelada_4c_Code.c
[2011/12/09 23:50:27 | 000,012,864 | —- | C] () – C:\Users\Joseph\Desktop\Joseph_Zelada_2c_Code.c
[2011/12/09 23:50:22 | 000,013,203 | —- | C] () – C:\Users\Joseph\Desktop\Joseph_Zelada_1b_Code.c
[2011/12/09 23:47:26 | 000,021,293 | —- | C] () – C:\Users\Joseph\Desktop\Untitled 1.odt
[2011/12/09 23:45:00 | 000,039,026 | —- | C] () – C:\Users\Joseph\Desktop\Algorithms.pdf
[2011/12/09 04:04:24 | 000,030,391 | —- | C] () – C:\Users\Joseph\Desktop\Algorithms.exe
[2011/12/09 04:04:23 | 000,006,784 | —- | C] () – C:\Users\Joseph\Desktop\Algorithms.o
[2011/12/08 16:29:35 | 000,121,449 | —- | C] () – C:\Users\Joseph\Desktop\Final_ProjectF11.pdf
[2011/12/08 15:36:44 | 000,001,083 | —- | C] () – C:\Users\Joseph\Documents - Shortcut.lnk
[2011/12/08 01:24:24 | 000,291,827 | —- | C] () – C:\Windows\To the Moon Uninstaller.exe
[2011/12/07 02:57:00 | 000,010,373 | —- | C] () – C:\Users\Joseph\Desktop\Algorithms.c
[2011/12/02 21:30:54 | 000,028,961 | —- | C] () – C:\Users\Joseph\Desktop\Ethics Module.odt
[2011/11/24 22:31:25 | 000,000,023 | —- | C] () – C:\Windows\BlendSettings.ini
[2011/08/25 16:45:23 | 000,000,600 | —- | C] () – C:\Users\Joseph\AppData\Local\PUTTY.RND
[2011/08/09 03:25:06 | 000,103,736 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/08/09 03:21:43 | 000,066,872 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/07/05 20:44:19 | 000,011,005 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2011/07/05 20:43:41 | 000,002,836 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [ID Tag Update] Codec.dat
[2011/07/05 20:43:32 | 000,003,002 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Multi Encoder] Codec.dat
[2011/07/05 20:43:25 | 000,002,879 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Arrange Audio] Codec.dat
[2011/07/05 20:43:20 | 000,002,871 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Audio Info] Codec.dat
[2011/07/05 20:43:15 | 000,002,869 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Tag From Filename] Codec.dat
[2011/07/05 20:43:09 | 000,002,862 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Length Split] Codec.dat
[2011/07/05 20:43:04 | 000,002,999 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Channel Split] Codec.dat
[2011/07/05 20:42:57 | 000,002,900 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [ReplayGain] Codec.dat
[2011/07/05 20:39:25 | 003,480,752 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2011/07/05 20:39:25 | 000,014,645 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2011/07/02 02:48:16 | 000,130,268 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/04/22 22:20:25 | 000,007,595 | —- | C] () – C:\Users\Joseph\AppData\Local\Resmon.ResmonCfg
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/03/28 13:35:16 | 000,202,213 | —- | C] () – C:\Windows\libmpg123-0.dll
[2011/03/28 13:35:16 | 000,190,464 | —- | C] () – C:\Windows\libvorbis.dll
[2011/03/28 13:35:16 | 000,045,568 | —- | C] () – C:\Windows\libg7221_decode.dll
[2011/01/17 19:59:02 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\LXDNinst.dll
[2011/01/17 19:59:02 | 000,335,872 | —- | C] () – C:\Windows\SysWow64\lxdncomx.dll
[2011/01/05 22:41:40 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011/01/05 22:41:39 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/01/05 22:41:38 | 002,942,464 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2011/01/05 22:41:38 | 000,810,496 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/01/05 22:41:38 | 000,183,808 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/01/05 22:41:38 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/01/05 22:15:27 | 002,625,640 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/05 22:08:35 | 000,921,665 | —- | C] () – C:\Windows\SysWow64\msvcrt-ruby18.dll
[2011/01/05 22:08:35 | 000,271,264 | —- | C] () – C:\Windows\SysWow64\vbrun100.dll
[2011/01/05 22:08:35 | 000,210,944 | —- | C] () – C:\Windows\SysWow64\msvcrt10.dll
[2011/01/05 22:08:34 | 000,027,136 | —- | C] () – C:\Windows\SysWow64\pythonw.exe
[2011/01/05 22:08:34 | 000,026,624 | —- | C] () – C:\Windows\SysWow64\python.exe
[2011/01/05 22:08:34 | 000,020,537 | —- | C] () – C:\Windows\SysWow64\rubyw.exe
[2011/01/05 22:08:34 | 000,020,536 | —- | C] () – C:\Windows\SysWow64\ruby.exe
[2009/07/23 14:49:06 | 000,782,336 | —- | C] () – C:\Windows\SysWow64\lxdndrs.dll
[2009/07/13 23:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/05/14 08:46:42 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\lxdncaps.dll
[2007/10/02 09:51:10 | 000,069,632 | —- | C] () – C:\Windows\SysWow64\lxdncnv4.dll

========== LOP Check ==========

[2011/11/14 13:18:22 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\ApexDC++
[2011/06/19 18:29:20 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Bioshock2
[2011/02/25 15:39:18 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Broken Rules
[2011/06/22 13:37:06 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Cakewalk
[2011/01/06 00:31:47 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\DAEMON Tools Lite
[2011/07/05 21:26:02 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\dBpoweramp
[2011/12/09 01:33:11 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\DC++
[2011/11/23 21:53:18 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\digipen
[2011/07/05 02:54:54 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\DiskAid
[2011/03/20 15:09:47 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Emulators
[2011/04/06 15:58:33 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\EurekaLog
[2011/04/09 22:08:27 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\FLV Extract
[2011/01/08 14:10:08 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Foxit Software
[2011/12/15 14:18:39 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\FreeArc
[2011/06/21 19:43:04 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\ImgBurn
[2011/02/06 18:20:09 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Lexmark Productivity Studio
[2011/12/16 02:10:58 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Mipony
[2011/01/14 17:57:41 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\OnLive App
[2011/01/07 15:26:39 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\OpenOffice.org
[2011/09/25 14:22:50 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Quest3D
[2011/01/07 16:33:01 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Red Kawa
[2011/12/05 14:48:16 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\redsn0w
[2011/04/06 16:16:04 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Replay Media Catcher 4
[2011/05/24 18:23:04 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\runic games
[2011/03/13 20:00:37 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\ScummVM
[2011/07/21 16:24:19 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\SystemRequirementsLab
[2011/12/15 03:53:25 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\To the Moon - Freebird Games
[2011/07/17 23:01:16 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\TuneUpMedia
[2011/01/22 11:15:57 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Unity
[2011/12/16 02:19:14 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\uTorrent
[2011/03/05 15:21:00 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Western Digital
[2011/03/01 20:30:41 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Windows Live Writer
[2011/03/15 15:42:17 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Xilisoft
[2011/09/06 23:37:13 | 000,032,530 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/11/20 06:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/01/05 23:53:38 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2008/04/11 09:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/12/16 02:57:00 | 3217,199,104 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 09:32:30 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 09:32:30 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 09:32:30 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 09:32:30 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 09:32:30 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 09:32:30 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 09:32:30 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 09:32:30 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 09:32:30 | 000,092,176 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 09:32:30 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 09:32:30 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/12/01 23:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/12/16 02:57:04 | 4289,601,536 | -HS- | M] () – C:\pagefile.sys
[2011/12/16 02:22:22 | 000,082,634 | —- | M] () – C:\TDSSKiller.2.6.23.0_16.12.2011_02.21.47_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/13 23:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 14:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/22 18:19:30 | 000,000,221 | -HS- | M] () – C:\Users\Joseph\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/12/09 05:26:15 | 000,030,391 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.exe
[2011/04/22 20:55:02 | 000,939,360 | —- | M] (techPowerUp (www.techpowerup.com)) – C:\Users\Joseph\Desktop\GPU-Z.0.5.3.exe
[2011/12/16 02:38:57 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Joseph\Desktop\HiJackThis.exe
[2011/12/16 02:38:51 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Joseph\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\system64] -> \systemroot\system32 -> Mount Point

< End of report >



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:01:26 AM, on 12/16/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe
C:\Program Files (x86)\Lexmark 2600 Series\lxdnMsdMon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\Desktop\OTL.exe
C:\Users\Joseph\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Joseph\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3141220578-551946994-1010253117-1011\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3141220578-551946994-1010253117-1011\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: Download with Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Desura Install Service - Desura Pty Ltd - C:\Program Files (x86)\Common Files\Desura\desura_service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\x64\3\\lxdnserv.exe
O23 - Service: lxdn_device - - C:\Windows\system32\lxdncoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\DRIVERS\o2flash.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 9746 bytes




.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 3:02:02.92 on Fri 12/16/2011
Internet Explorer: 9.0.8112.16421
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4091.2452 [GMT -6:00]
.
AV: COMODO Antivirus *Disabled/Updated* {7554F4C5-5EC0-2FC6-8192-8DF831DBED51}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
FW: COMODO Firewall *Disabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\Lexmark 2600 Series\lxdnMsdMon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Windows\system32\lxdncoms.exe
C:\Windows\system32\DRIVERS\o2flash.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Joseph\Desktop\OTL.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Joseph\Desktop\HiJackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Joseph\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Joseph\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Download with Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
mRun-x64: [lxdnmon.exe] "C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe"
mRun-x64: [lxdnamon] "C:\Program Files (x86)\Lexmark 2600 Series\lxdnamon.exe"
mRun-x64: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
AppInit_DLLs-X64: C:\Windows\system32\guard64.dll
.
============= SERVICES / DRIVERS ===============
.
R1 cmderd;COMODO Internet Security Eradication Driver;C:\Windows\System32\drivers\cmderd.sys [2011-10-7 16528]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\System32\drivers\cmdGuard.sys [2011-10-7 574216]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\System32\drivers\cmdhlp.sys [2011-10-7 43248]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 CLPSLS;COMODO livePCsupport Service;C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 1267000]
R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2011-1-29 21992]
R2 HsfXAudioService;HsfXAudioService;C:\Windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 27136]
R2 lxdn_device;lxdn_device;C:\Windows\system32\lxdncoms.exe -service –> C:\Windows\system32\lxdncoms.exe -service [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2011-12-15 2348864]
R3 appliandMP;appliandMP;C:\Windows\System32\drivers\appliand.sys [2010-6-24 33888]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\System32\drivers\CAXHWAZL.sys [2011-1-5 292864]
R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2010-1-13 7675392]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2011-12-15 187200]
R3 O2MDRDR;O2MDRDR;C:\Windows\System32\drivers\o2mdx64.sys [2009-5-7 63264]
R3 O2SDRDR;O2SDRDR;C:\Windows\System32\drivers\o2sdx64.sys [2009-5-7 49696]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;C:\Windows\System32\spool\drivers\x64\3\lxdnserv.exe [2009-4-28 29184]
S3 appliand;Applian Network Service;C:\Windows\System32\drivers\appliand.sys [2010-6-24 33888]
S3 Desura Install Service;Desura Install Service;C:\Program Files (x86)\Common Files\Desura\desura_service.exe [2011-6-5 131912]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-1-29 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2010-12-25 5435904]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-3-12 20992]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-12 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-12-14 1255736]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2009-2-13 14464]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-12-16 06:31:05 ——– d—–w- C:\Program Files\iTunes
2011-12-16 06:31:05 ——– d—–w- C:\Program Files\iPod
2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2011-12-15 21:23:10 ——– d—–we C:\Windows\system64
2011-12-15 20:45:31 ——– d—–w- C:\Program Files (x86)\Batman - Arkham City
2011-12-15 20:18:39 ——– d—–w- C:\Users\Joseph\AppData\Roaming\FreeArc
2011-12-15 20:18:21 ——– d—–w- C:\Program Files (x86)\FreeArc
2011-12-15 07:44:59 889664 —-a-w- C:\Windows\System32\nvvsvc.exe
2011-12-15 07:44:59 63296 —-a-w- C:\Windows\System32\nvshext.dll
2011-12-15 07:44:59 6004544 —-a-w- C:\Windows\System32\nvcpl.dll
2011-12-15 07:44:59 3028800 —-a-w- C:\Windows\System32\nvsvc64.dll
2011-12-15 07:44:59 2562368 —-a-w- C:\Windows\System32\nvsvcr.dll
2011-12-15 07:44:59 118080 —-a-w- C:\Windows\System32\nvmctray.dll
2011-12-15 07:44:02 ——– d—–w- C:\PROGRA~3\NVIDIA Corporation
2011-12-15 07:38:40 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation
2011-12-15 07:27:49 72512 —-a-w- C:\Windows\System32\nvapo64v.dll
2011-12-15 07:27:49 31040 —-a-w- C:\Windows\System32\nvhdap64.dll
2011-12-15 07:27:49 187200 —-a-w- C:\Windows\System32\drivers\nvhda64v.sys
2011-12-15 07:27:49 1451840 —-a-w- C:\Windows\System32\nvhdagenco6420103.dll
2011-12-13 23:55:34 43520 —-a-w- C:\Windows\System32\csrsrv.dll
2011-12-13 23:55:13 3145216 —-a-w- C:\Windows\System32\win32k.sys
2011-12-13 23:54:51 723456 —-a-w- C:\Windows\System32\EncDec.dll
2011-12-13 23:54:51 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-13 23:54:35 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2011-12-13 23:54:35 2048 —-a-w- C:\Windows\System32\tzres.dll
2011-12-08 07:26:58 ——– d—–w- C:\Users\Joseph\AppData\Roaming\To the Moon - Freebird Games
2011-12-08 07:24:24 291827 —-a-w- C:\Windows\To the Moon Uninstaller.exe
2011-12-08 07:23:47 ——– d—–w- C:\Program Files (x86)\To the Moon
2011-12-05 20:34:06 ——– d—–w- C:\Users\Joseph\AppData\Roaming\redsn0w
2011-12-05 18:43:39 34152 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2011-12-05 18:43:39 126312 —-a-w- C:\Windows\System32\GEARAspi64.dll
2011-12-05 18:43:39 107368 —-a-w- C:\Windows\SysWow64\GEARAspi.dll
2011-12-05 18:41:46 ——– d—–w- C:\Program Files\Bonjour
2011-12-05 18:41:46 ——– d—–w- C:\Program Files (x86)\Bonjour
2011-11-29 19:25:20 ——– d—–w- C:\PROGRA~3\CPA_VA
2011-11-26 05:13:25 ——– d—–w- C:\PROGRA~3\id Software
2011-11-25 22:48:57 ——– d—–w- C:\Program Files (x86)\Common Files\BOSS
2011-11-25 04:29:22 ——– d—–w- C:\Users\Joseph\AppData\Local\Oblivion
2011-11-24 03:53:18 ——– d—–w- C:\Users\Joseph\AppData\Roaming\digipen
2011-11-24 03:53:18 ——– d—–w- C:\Users\Joseph\AppData\Local\digipen
2011-11-24 03:03:48 ——– d—–w- C:\Program Files (x86)\Digipen
2011-11-16 18:13:59 ——– d—–w- C:\Program Files (x86)\Black_Box
.
==================== Find3M ====================
.
2011-11-27 06:04:02 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-12 08:52:32 1700352 —-a-w- C:\Windows\SysWow64\gdiplus.dll
2011-11-04 01:53:39 2309120 —-a-w- C:\Windows\System32\jscript9.dll
2011-11-04 01:44:47 1390080 —-a-w- C:\Windows\System32\wininet.dll
2011-11-04 01:44:21 1493504 —-a-w- C:\Windows\System32\inetcpl.cpl
2011-11-04 01:34:43 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2011-11-03 22:47:42 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll
2011-11-03 22:40:21 1427456 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-11-03 22:39:47 1127424 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-11-03 22:31:57 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-24 20:29:02 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2011-10-24 20:29:02 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts
2011-10-08 00:47:58 574216 —-a-w- C:\Windows\System32\drivers\cmdGuard.sys
2011-10-08 00:47:58 43248 —-a-w- C:\Windows\System32\drivers\cmdhlp.sys
2011-10-08 00:47:56 16528 —-a-w- C:\Windows\System32\drivers\cmderd.sys
2011-10-08 00:47:14 41200 —-a-w- C:\Windows\System32\cmdcsr.dll
2011-10-08 00:47:12 300200 —-a-w- C:\Windows\SysWow64\guard32.dll
2011-10-08 00:47:10 388280 —-a-w- C:\Windows\System32\guard64.dll
2011-10-03 11:06:03 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2011-09-29 16:29:28 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 3:07:57.47 ===============
Hi,

Yes, limit your internet connection with this machine, there are indications that you are infected with the ZeroAccess rootkit, which has backdoor capabilities. As a precaution, I would change all your online passwords from a machine that has never been infected and keep a close watch on all your financial accounts for the next while.

Please do the following

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Here is the Log from aswMBR. Please let me know when you need me to do something else aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-16 21:22:13 —————————– 21:22:13.268 OS Version: Windows x64 6.1.7601 Service Pack 1 21:22:13.268 Number of processors: 2 586 0x1706 21:22:13.268 ComputerName: JOSEPH-PC UserName: Joseph 21:22:14.092 Initialize success 21:22:17.506 AVAST engine defs: 11121603 21:22:20.993 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 21:22:20.993 Disk 0 Vendor: ST9320325AS 0001SDM1 Size: 305245MB BusType: 11 21:22:20.993 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-1 21:22:20.993 Disk 1 Vendor: WDC_WD2500BEKT-00A25T0 01.01A01 Size: 238475MB BusType: 11 21:22:23.090 Disk 0 MBR read successfully 21:22:23.093 Disk 0 MBR scan 21:22:23.097 Disk 0 Windows 7 default MBR code 21:22:23.104 Service scanning 21:22:24.069 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 21:22:24.648 Modules scanning 21:22:24.652 Disk 0 trace - called modules: 21:22:24.660 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa80049b62c0]<< 21:22:24.664 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004ce1060] 21:22:24.670 3 CLASSPNP.SYS[fffff88001bd043f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004b451f0] 21:22:24.675 \Driver\atapi[0xfffffa8004b09b10] -> IRP_MJ_CREATE -> 0xfffffa80049b62c0 21:22:25.496 AVAST engine scan C:\Windows 21:22:29.058 AVAST engine scan C:\Windows\system32 21:22:43.025 File: C:\Windows\system32\consrv.dll **INFECTED** Win32:Sirefef-FQ [Drp] 21:24:37.729 AVAST engine scan C:\Windows\system32\drivers 21:24:50.656 AVAST engine scan C:\Users\Joseph 21:32:40.662 AVAST engine scan C:\ProgramData 21:34:48.236 Scan finished successfully 21:35:48.443 Disk 0 MBR has been saved successfully to "C:\Users\Joseph\Desktop\MBR.dat" 21:35:48.448 The log file has been saved successfully to "C:\Users\Joseph\Desktop\aswMBR.txt"

Attachments:

Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Here is my log from ComboFix. Do you think it's gone or are there more steps? ComboFix 11-12-16.03 - Joseph 12/17/2011 2:29.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4091.3005 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: COMODO Antivirus *Disabled/Updated* {7554F4C5-5EC0-2FC6-8192-8DF831DBED51} FW: COMODO Firewall *Disabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A} SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe c:\users\Joseph\AppData\Local\TempDIR c:\users\Joseph\AppData\Local\TempDIR\GFInstaller\AppName.txt c:\users\Joseph\AppData\Local\TempDIR\GFInstaller\Channel.txt c:\users\Joseph\AppData\Local\TempDIR\GFInstaller\DownloadURL.txt c:\users\Joseph\AppData\Local\TempDIR\GFInstaller\GFInstaller.exe c:\users\Joseph\AppData\Roaming\EurekaLog c:\windows\system32\consrv.dll c:\windows\System64 . . ((((((((((((((((((((((((( Files Created from 2011-11-17 to 2011-12-17 ))))))))))))))))))))))))))))))) . . 2011-12-17 08:40 . 2011-12-17 08:40 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-12-16 06:31 . 2011-12-16 06:31 ——– d—–w- c:\program files\iTunes 2011-12-16 06:31 . 2011-12-16 06:31 ——– d—–w- c:\program files\iPod 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-12-15 20:45 . 2011-11-22 08:53 ——– d—–w- c:\program files (x86)\Batman - Arkham City 2011-12-15 20:18 . 2011-12-15 20:18 ——– d—–w- c:\users\Joseph\AppData\Roaming\FreeArc 2011-12-15 20:18 . 2011-12-15 20:18 ——– d—–w- c:\program files (x86)\FreeArc 2011-12-15 07:46 . 2011-12-16 19:25 ——– d—–w- c:\users\UpdatusUser 2011-12-15 07:44 . 2011-11-24 02:47 6004544 —-a-w- c:\windows\system32\nvcpl.dll 2011-12-15 07:44 . 2011-11-24 02:41 3028800 —-a-w- c:\windows\system32\nvsvc64.dll 2011-12-15 07:44 . 2011-11-24 02:38 2562368 —-a-w- c:\windows\system32\nvsvcr.dll 2011-12-15 07:44 . 2011-11-24 02:38 889664 —-a-w- c:\windows\system32\nvvsvc.exe 2011-12-15 07:44 . 2011-11-24 02:38 63296 —-a-w- c:\windows\system32\nvshext.dll 2011-12-15 07:44 . 2011-11-24 02:38 118080 —-a-w- c:\windows\system32\nvmctray.dll 2011-12-15 07:44 . 2011-12-15 07:44 ——– d—–w- c:\programdata\NVIDIA Corporation 2011-12-15 07:38 . 2011-12-15 07:46 ——– d—–w- c:\program files (x86)\NVIDIA Corporation 2011-12-15 07:27 . 2011-11-09 14:21 31040 —-a-w- c:\windows\system32\nvhdap64.dll 2011-12-15 07:27 . 2011-11-09 14:21 72512 —-a-w- c:\windows\system32\nvapo64v.dll 2011-12-15 07:27 . 2011-11-09 14:21 187200 —-a-w- c:\windows\system32\drivers\nvhda64v.sys 2011-12-15 07:27 . 2011-11-09 14:21 1451840 —-a-w- c:\windows\system32\nvhdagenco6420103.dll 2011-12-13 23:55 . 2011-10-26 05:21 43520 —-a-w- c:\windows\system32\csrsrv.dll 2011-12-13 23:55 . 2011-11-24 04:52 3145216 —-a-w- c:\windows\system32\win32k.sys 2011-12-13 23:54 . 2011-10-15 06:31 723456 —-a-w- c:\windows\system32\EncDec.dll 2011-12-13 23:54 . 2011-10-15 05:38 534528 —-a-w- c:\windows\SysWow64\EncDec.dll 2011-12-13 23:54 . 2011-11-05 05:32 2048 —-a-w- c:\windows\system32\tzres.dll 2011-12-13 23:54 . 2011-11-05 04:26 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2011-12-08 07:26 . 2011-12-15 09:53 ——– d—–w- c:\users\Joseph\AppData\Roaming\To the Moon - Freebird Games 2011-12-08 07:24 . 2011-12-08 07:24 291827 —-a-w- c:\windows\To the Moon Uninstaller.exe 2011-12-08 07:23 . 2011-12-08 07:25 ——– d—–w- c:\program files (x86)\To the Moon 2011-12-05 20:34 . 2011-12-05 20:48 ——– d—–w- c:\users\Joseph\AppData\Roaming\redsn0w 2011-12-05 18:43 . 2009-05-18 19:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-12-05 18:43 . 2008-04-17 18:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-12-05 18:43 . 2008-04-17 18:12 107368 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-12-05 18:41 . 2011-12-05 18:41 ——– d—–w- c:\program files\Bonjour 2011-12-05 18:41 . 2011-12-05 18:41 ——– d—–w- c:\program files (x86)\Bonjour 2011-11-29 19:25 . 2011-12-01 20:59 ——– d—–w- c:\programdata\CPA_VA 2011-11-26 05:13 . 2011-11-26 05:13 ——– d—–w- c:\programdata\id Software 2011-11-25 22:48 . 2011-11-26 04:35 ——– d—–w- c:\program files (x86)\Common Files\BOSS 2011-11-25 04:29 . 2011-11-25 06:38 ——– d—–w- c:\users\Joseph\AppData\Local\Oblivion 2011-11-24 03:53 . 2011-11-24 03:53 ——– d—–w- c:\users\Joseph\AppData\Roaming\digipen 2011-11-24 03:53 . 2011-11-24 03:53 ——– d—–w- c:\users\Joseph\AppData\Local\digipen 2011-11-24 03:03 . 2011-11-24 03:03 ——– d—–w- c:\program files (x86)\Digipen . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-27 06:04 . 2011-06-01 15:21 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-12 08:52 . 2011-11-12 08:52 1700352 —-a-w- c:\windows\SysWow64\gdiplus.dll 2011-10-24 20:29 . 2011-10-24 20:29 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2011-10-24 20:29 . 2011-10-24 20:29 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts 2011-10-08 00:48 . 2011-10-08 00:48 93200 —-a-w- c:\windows\system32\drivers\inspect.sys 2011-10-08 00:47 . 2011-10-08 00:47 574216 —-a-w- c:\windows\system32\drivers\cmdGuard.sys 2011-10-08 00:47 . 2011-10-08 00:47 43248 —-a-w- c:\windows\system32\drivers\cmdhlp.sys 2011-10-08 00:47 . 2011-10-08 00:47 16528 —-a-w- c:\windows\system32\drivers\cmderd.sys 2011-10-08 00:47 . 2011-10-08 00:47 41200 —-a-w- c:\windows\system32\cmdcsr.dll 2011-10-08 00:47 . 2011-10-08 00:47 300200 —-a-w- c:\windows\SysWow64\guard32.dll 2011-10-08 00:47 . 2011-10-08 00:47 388280 —-a-w- c:\windows\system32\guard64.dll 2011-10-07 04:16 . 2011-11-11 22:50 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{69556484-62FB-40E4-990B-612BC2438C5C}\mpengine.dll 2011-10-03 11:06 . 2011-01-06 04:09 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-09-29 16:29 . 2011-11-08 22:32 1923952 —-a-w- c:\windows\system32\drivers\tcpip.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\lxdnserv.exe [2009-04-28 29184] R3 appliand;Applian Network Service;c:\windows\system32\DRIVERS\appliand.sys [x] R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe [2011-12-15 131912] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 1267000] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe [2007-11-28 1039872] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2011-11-24 2348864] S3 appliandMP;appliandMP;c:\windows\system32\DRIVERS\appliand.sys [x] S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [x] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2mdx64.sys [x] S3 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sdx64.sys [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-12-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3141220578-551946994-1010253117-1000Core.job - c:\users\Joseph\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-06 05:10] . 2011-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3141220578-551946994-1010253117-1000UA.job - c:\users\Joseph\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-06 05:10] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184] "lxdnmon.exe"="c:\program files (x86)\Lexmark 2600 Series\lxdnmon.exe" [2010-02-04 660136] "lxdnamon"="c:\program files (x86)\Lexmark 2600 Series\lxdnamon.exe" [2010-02-04 16040] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 9264456] "combofix"="c:\combofix\CF20647.3XE" [2010-11-20 345088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\windows\System32\guard64.dll . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download with Mipony - file://c:\program files (x86)\MiPony\Browser\IEContext.htm TCP: DhcpNameServer = 192.168.1.1 . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [Arrange Audio] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [Audio Info] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [Channel Split] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [ID Tag Update] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [Length Split] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [Multi Encoder] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [ReplayGain] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp [Tag From Filename] Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-The Klub 17 - c:\users\Joseph\Documents\Mipony\The Klub 17\Binaries\TK17_Uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3141220578-551946994-1010253117-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3141220578-551946994-1010253117-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\system32\DRIVERS\o2flash.exe c:\windows\SysWOW64\PnkBstrA.exe c:\windows\SysWOW64\PnkBstrB.exe c:\program files (x86)\Lexmark 2600 Series\lxdnMsdMon.exe . ************************************************************************** . Completion time: 2011-12-17 02:49:52 - machine was rebooted ComboFix-quarantined-files.txt 2011-12-17 08:49 . Pre-Run: 15,970,914,304 bytes free Post-Run: 15,371,145,216 bytes free . - - End Of File - - 0BCE50F5DC0CDDB18CCA3F6E3A7F5335
Hi,

Just a couple more scans to look for any leftovers

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Here are the contents of the files you requested Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8387 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 12/17/2011 12:25:42 PM mbam-log-2011-12-17 (12-25-42).txt Scan type: Quick scan Objects scanned: 188207 Time elapsed: 6 minute(s), 14 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) C:\Program Files (x86)\EA\Bulletstorm\Binaries\Win32\xlive.dll a variant of Win32/Packed.VMProtect.AAD trojan C:\Qoobox\Quarantine\C\Windows\System32\consrv.dll.vir Win64/Sirefef.G trojan E:\Restore Files\videora-ipod-600-setup.exe Win32/OpenCandy application E:\Restore Files\videora-xbox360-600-setup.exe Win32/OpenCandy application E:\Restore Files\winamp5601_full_emusic-7plus_en-us.exe Win32/OpenCandy application E:\Restore Files\MakeMusic Finale 2010 v15.0\patch_finale_2010_v15.0.exe Win32/HackTool.Patcher.A application
If you don't require the following files then I would delete them

E:\Restore Files\videora-ipod-600-setup.exe
E:\Restore Files\videora-xbox360-600-setup.exe
E:\Restore Files\winamp5601_full_emusic-7plus_en-us.exe


as they are bundled with adware

the following file needs to be deleted as it is pirated

E:\Restore Files\MakeMusic Finale 2010 v15.0\patch_finale_2010_v15.0.exe


the rest of the detections are in quarantine of not a concern


Please post a fresh OTL log and advise how the computer is running now and if there are any outstanding issues
Here's the log file. As for the computer, everything seems to be running normal again. svchost and ping are no longer hogging the processor. I would like to know though if svchost should be running 130 MB of memory in task manager normally?

OTL logfile created on: 12/18/2011 12:56:18 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Joseph\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.77 Gb Available Physical Memory | 69.25% Memory free
7.99 Gb Paging File | 6.58 Gb Available in Paging File | 82.43% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 298.09 Gb Total Space | 12.52 Gb Free Space | 4.20% Space Free | Partition Type: NTFS
Drive E: | 232.88 Gb Total Space | 8.57 Gb Free Space | 3.68% Space Free | Partition Type: NTFS

Computer Name: JOSEPH-PC | User Name: Joseph | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Joseph\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe ()
PRC - C:\Program Files (x86)\Lexmark 2600 Series\lxdnmsdmon.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdnmsdmon.exe ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\app4r.monitor.core.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\app4r.monitor.common.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdndrs.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdnscw.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdncaps.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdncnv4.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdndatr.dll ()
MOD - C:\Program Files (x86)\Lexmark 2600 Series\lxdncats.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (CLPSLS) – C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe (COMODO)
SRV:64bit: - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (lxdnCATSCustConnectService) – C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxdnserv.exe ()
SRV:64bit: - (lxdn_device) – C:\Windows\SysNative\lxdncoms.exe ( )
SRV:64bit: - (O2FLASH) – C:\Windows\SysNative\drivers\o2flash.exe (O2Micro International)
SRV - (Desura Install Service) – C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HsfXAudioService) – C:\Windows\SysWOW64\XAudio64.dll (Conexant Systems, Inc.)
SRV - (lxdn_device) – C:\Windows\SysWow64\lxdncoms.exe ( )


========== Driver Services (SafeList) ==========

DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (cmderd) – C:\Windows\SysNative\drivers\cmderd.sys (COMODO)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (atksgt) – C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:64bit: - (lirsgt) – C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (cpuz135) – C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (appliandMP) – C:\Windows\SysNative\drivers\appliand.sys (Applian Technologies Inc.)
DRV:64bit: - (appliand) – C:\Windows\SysNative\drivers\appliand.sys (Applian Technologies Inc.)
DRV:64bit: - (NETw5s64) Intel® – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (O2SDRDR) – C:\Windows\SysNative\drivers\o2sdx64.sys (O2Micro )
DRV:64bit: - (O2MDRDR) – C:\Windows\SysNative\drivers\o2mdx64.sys (O2Micro )
DRV:64bit: - (XAudio) – C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 67 F8 23 D7 42 BD CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@onlive.com/OlGameDetect,version=1.1.0.70351: C:\Program Files (x86)\OnLive\FirefoxPlugin\npolgdet.dll (OnLive)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Joseph\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Joseph\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Joseph\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)



========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Battlefield Play4Free Updater (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.53.2_0\npBP4FUpdater.dll
CHR - plugin: Battlefield Play4Free Updater (Enabled) = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.53.2_0\BP4FUpdater.exe
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: OnLive Games Service Detector for Firefox (Enabled) = C:\Program Files (x86)\OnLive\FirefoxPlugin\npolgdet.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Joseph\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Joseph\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.7_0\
CHR - Extension: 3DTin = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\algoakekcdmbbikdjgjdahbfihboglmi\0.97_0\
CHR - Extension: Isle of Tune = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\bljldflafhmbedhjnlncilbhfcnfabgb\1_0\
CHR - Extension: Battlefield Play4Free = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.53.2_0\
CHR - Extension: Gamux = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhjfcocbebjediffgmnknicggaemomh\2.0.2_0\
CHR - Extension: Poppit = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: RSS Subscription Extension (by Google) = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd\2.1.3_0\
CHR - Extension: NESbox = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\oanegjalpoiojbhpoajhjeohnaigdgdi\2.0.0.0_0\
CHR - Extension: Atari - Missile Command = C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Extensions\oobnopfjjndfekinfcddimnjbhjdgmbg\1.0_0\

O1 HOSTS File: ([2011/12/17 02:43:41 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4:64bit: - HKLM..\Run: [lxdnamon] C:\Program Files (x86)\Lexmark 2600 Series\lxdnamon.exe ()
O4:64bit: - HKLM..\Run: [lxdnmon.exe] C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe ()
O4:64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\system32\StikyNot.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()
O8 - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75E67AC0-70CA-4BAD-AC15-7A31CF144F87}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) -C:\Windows\SysWOW64\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.atrac3 - C:\Windows\SysWow64\atrac3.acm (Sony Corporation)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\SysWow64\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\SysWow64\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv41 - C:\Windows\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.LAGS - C:\Windows\SysWow64\lagarith.dll ( )
Drivers32: VIDC.VP60 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\SysWow64\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/17 23:08:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/12/17 12:18:53 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\Malwarebytes
[2011/12/17 12:18:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/17 12:18:18 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/12/17 12:18:15 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/12/17 12:18:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/12/17 12:17:15 | 009,852,544 | —- | C] (Malwarebytes Corporation ) – C:\Users\Joseph\Desktop\mbam-setup-1.51.2.1300.exe
[2011/12/17 11:33:27 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/12/17 02:49:55 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/12/17 02:27:52 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/12/17 02:27:52 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/12/17 02:27:52 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/12/17 02:27:47 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/12/17 02:27:43 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/17 02:18:30 | 004,341,424 | R— | C] (Swearware) – C:\Users\Joseph\Desktop\ComboFix.exe
[2011/12/16 21:14:10 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\Joseph\Desktop\aswMBR.exe
[2011/12/16 02:53:35 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\Virus Things
[2011/12/16 02:38:57 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Joseph\Desktop\HiJackThis.exe
[2011/12/16 02:38:50 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Joseph\Desktop\OTL.exe
[2011/12/16 00:31:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/16 00:31:05 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/12/16 00:31:05 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/16 00:27:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/12/16 00:26:04 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/12/15 15:29:51 | 000,000,000 | —D | C] – C:\Users\Joseph\Documents\WB Games
[2011/12/15 14:45:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Batman - Arkham City
[2011/12/15 14:18:39 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\FreeArc
[2011/12/15 14:18:26 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeArc
[2011/12/15 14:18:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeArc
[2011/12/15 14:18:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\FreeArc
[2011/12/15 01:44:59 | 006,004,544 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2011/12/15 01:44:59 | 003,028,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2011/12/15 01:44:59 | 002,562,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2011/12/15 01:44:59 | 000,118,080 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2011/12/15 01:44:59 | 000,063,296 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2011/12/15 01:44:02 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2011/12/15 01:40:53 | 025,432,384 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/12/15 01:40:53 | 019,348,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/12/15 01:40:53 | 009,622,848 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2011/12/15 01:40:53 | 007,677,248 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/12/15 01:40:53 | 001,466,176 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/12/15 01:40:52 | 025,137,472 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/12/15 01:40:52 | 017,498,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/12/15 01:40:52 | 017,474,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/12/15 01:40:52 | 014,854,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2011/12/15 01:40:52 | 007,974,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/12/15 01:40:52 | 005,868,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/12/15 01:40:52 | 002,660,160 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/12/15 01:40:52 | 002,506,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/12/15 01:40:52 | 002,403,136 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2011/12/15 01:40:52 | 002,374,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/12/15 01:40:52 | 002,206,016 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/12/15 01:40:52 | 002,095,424 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2011/12/15 01:40:52 | 001,726,272 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/12/15 01:40:52 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/12/15 01:40:52 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/12/15 01:38:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2011/12/15 01:27:49 | 001,451,840 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420103.dll
[2011/12/15 01:27:49 | 000,187,200 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2011/12/15 01:27:49 | 000,072,512 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapo64v.dll
[2011/12/15 01:27:49 | 000,031,040 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2011/12/14 03:02:05 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/14 03:02:05 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/14 03:02:04 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/14 03:02:04 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/14 03:02:03 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/14 03:02:03 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/14 03:02:02 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/12/14 03:02:02 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/14 03:02:02 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/14 03:02:02 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/12/14 03:02:02 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/12/13 17:55:34 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/13 17:54:51 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/13 17:54:51 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/09 23:01:19 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\A
[2011/12/08 01:26:58 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\To the Moon - Freebird Games
[2011/12/08 01:24:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\To the Moon
[2011/12/08 01:23:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\To the Moon
[2011/12/05 14:34:06 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\redsn0w
[2011/12/05 14:33:49 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\Untethered Jailbreak iOS 5.0.1
[2011/12/05 12:43:39 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011/12/05 12:43:39 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011/12/05 12:43:39 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/12/05 12:41:46 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/12/05 12:41:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/12/05 11:34:56 | 000,000,000 | —D | C] – C:\Users\Joseph\Desktop\Backups
[2011/11/29 13:25:20 | 000,000,000 | —D | C] – C:\ProgramData\CPA_VA
[2011/11/25 23:13:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\id Software
[2011/11/25 23:13:25 | 000,000,000 | —D | C] – C:\ProgramData\id Software
[2011/11/25 16:48:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\BOSS
[2011/11/24 22:29:22 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Local\Oblivion
[2011/11/23 21:53:18 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Roaming\digipen
[2011/11/23 21:53:18 | 000,000,000 | —D | C] – C:\Users\Joseph\AppData\Local\digipen
[2011/11/23 21:06:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Digipen
[2011/11/23 21:03:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Digipen
[2011/01/17 19:59:02 | 000,647,168 | —- | C] ( ) – C:\Windows\SysWow64\lxdnpmui.dll
[2011/01/17 19:59:02 | 000,364,544 | —- | C] ( ) – C:\Windows\SysWow64\lxdninpa.dll
[2011/01/17 19:59:02 | 000,339,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdniesc.dll
[2011/01/17 19:59:01 | 001,101,824 | —- | C] ( ) – C:\Windows\SysWow64\lxdnserv.dll
[2011/01/17 19:59:01 | 000,843,776 | —- | C] ( ) – C:\Windows\SysWow64\lxdnusb1.dll
[2011/01/17 19:59:01 | 000,569,344 | —- | C] ( ) – C:\Windows\SysWow64\lxdnlmpm.dll
[2011/01/17 19:59:01 | 000,315,392 | —- | C] ( ) – C:\Windows\SysWow64\lxdnih.exe
[2011/01/17 19:59:01 | 000,053,248 | —- | C] ( ) – C:\Windows\SysWow64\lxdnprox.dll
[2011/01/17 19:59:00 | 000,851,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdncomc.dll
[2011/01/17 19:59:00 | 000,663,552 | —- | C] ( ) – C:\Windows\SysWow64\lxdnhbn3.dll
[2011/01/17 19:59:00 | 000,589,824 | —- | C] ( ) – C:\Windows\SysWow64\lxdncoms.exe
[2011/01/17 19:59:00 | 000,376,832 | —- | C] ( ) – C:\Windows\SysWow64\lxdncomm.dll
[2011/01/17 19:59:00 | 000,360,448 | —- | C] ( ) – C:\Windows\SysWow64\lxdncfg.exe
[2011/01/05 22:41:39 | 000,121,344 | —- | C] ( ) – C:\Windows\SysWow64\lagarith.dll
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/18 12:52:53 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/18 12:52:53 | 000,014,224 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/18 12:50:04 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3141220578-551946994-1010253117-1000UA.job
[2011/12/18 12:45:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/18 12:45:26 | 3217,199,104 | -HS- | M] () – C:\hiberfil.sys
[2011/12/18 02:47:58 | 263,229,758 | -H– | M] () – C:\Users\Joseph\Desktop\bt_lizzy_tayler.wmv
[2011/12/18 01:49:01 | 433,702,606 | -H– | M] () – C:\Users\Joseph\Desktop\paint_and_pussy_big.mp4
[2011/12/18 01:28:27 | 181,085,211 | -H– | M] () – C:\Users\Joseph\Desktop\rapidrar_com_caprice.gabriella.come.to.me.540.wmv
[2011/12/17 23:01:36 | 001,474,832 | —- | M] () – C:\Windows\SysNative\drivers\sfi.dat
[2011/12/17 12:18:19 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/17 12:17:22 | 009,852,544 | —- | M] (Malwarebytes Corporation ) – C:\Users\Joseph\Desktop\mbam-setup-1.51.2.1300.exe
[2011/12/17 02:43:41 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/12/17 02:18:34 | 004,341,424 | R— | M] (Swearware) – C:\Users\Joseph\Desktop\ComboFix.exe
[2011/12/16 21:36:23 | 000,000,545 | —- | M] () – C:\Users\Joseph\Desktop\MBR.zip
[2011/12/16 21:35:48 | 000,000,512 | —- | M] () – C:\Users\Joseph\Desktop\MBR.dat
[2011/12/16 21:14:13 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\Joseph\Desktop\aswMBR.exe
[2011/12/16 10:50:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3141220578-551946994-1010253117-1000Core.job
[2011/12/16 02:39:14 | 000,625,664 | —- | M] () – C:\Users\Joseph\Desktop\dds.scr
[2011/12/16 02:38:57 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Joseph\Desktop\HiJackThis.exe
[2011/12/16 02:38:51 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Joseph\Desktop\OTL.exe
[2011/12/16 00:31:43 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/12/15 14:18:26 | 000,001,097 | —- | M] () – C:\Users\Joseph\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeArc.lnk
[2011/12/15 14:18:26 | 000,001,073 | —- | M] () – C:\Users\Joseph\Desktop\FreeArc.lnk
[2011/12/14 18:51:15 | 000,002,364 | —- | M] () – C:\Users\Joseph\Desktop\Google Chrome.lnk
[2011/12/14 18:34:15 | 002,641,064 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/14 18:34:15 | 000,688,546 | —- | M] () – C:\Windows\SysNative\perfh00C.dat
[2011/12/14 18:34:15 | 000,660,530 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/14 18:34:15 | 000,477,400 | —- | M] () – C:\Windows\SysNative\perfh001.dat
[2011/12/14 18:34:15 | 000,383,288 | —- | M] () – C:\Windows\SysNative\prfh0804.dat
[2011/12/14 18:34:15 | 000,129,176 | —- | M] () – C:\Windows\SysNative\perfc00C.dat
[2011/12/14 18:34:15 | 000,121,426 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/14 18:34:15 | 000,119,286 | —- | M] () – C:\Windows\SysNative\prfc0804.dat
[2011/12/14 18:34:15 | 000,094,022 | —- | M] () – C:\Windows\SysNative\perfc001.dat
[2011/12/14 18:28:04 | 000,310,408 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/11 16:10:36 | 000,000,600 | —- | M] () – C:\Users\Joseph\AppData\Local\PUTTY.RND
[2011/12/09 23:50:30 | 000,010,382 | —- | M] () – C:\Users\Joseph\Desktop\Joseph_Zelada_4c_Code.c
[2011/12/09 23:50:27 | 000,012,864 | —- | M] () – C:\Users\Joseph\Desktop\Joseph_Zelada_2c_Code.c
[2011/12/09 23:50:22 | 000,013,203 | —- | M] () – C:\Users\Joseph\Desktop\Joseph_Zelada_1b_Code.c
[2011/12/09 23:47:27 | 000,021,293 | —- | M] () – C:\Users\Joseph\Desktop\Untitled 1.odt
[2011/12/09 23:47:20 | 000,039,026 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.pdf
[2011/12/09 05:26:28 | 000,010,373 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.c
[2011/12/09 05:26:15 | 000,030,391 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.exe
[2011/12/09 05:26:15 | 000,006,784 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.o
[2011/12/08 16:29:34 | 000,121,449 | —- | M] () – C:\Users\Joseph\Desktop\Final_ProjectF11.pdf
[2011/12/08 15:36:44 | 000,001,083 | —- | M] () – C:\Users\Joseph\Documents - Shortcut.lnk
[2011/12/08 01:24:25 | 000,291,827 | —- | M] () – C:\Windows\To the Moon Uninstaller.exe
[2011/12/03 00:37:44 | 000,028,961 | —- | M] () – C:\Users\Joseph\Desktop\Ethics Module.odt
[2011/11/27 00:04:02 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/11/25 22:29:44 | 000,000,023 | —- | M] () – C:\Windows\BlendSettings.ini
[2011/11/23 22:59:00 | 025,432,384 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/11/23 22:59:00 | 025,137,472 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/11/23 22:59:00 | 019,348,800 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/11/23 22:59:00 | 017,498,432 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/11/23 22:59:00 | 017,474,368 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/11/23 22:59:00 | 014,854,464 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2011/11/23 22:59:00 | 009,622,848 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2011/11/23 22:59:00 | 007,974,208 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/11/23 22:59:00 | 007,677,248 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/11/23 22:59:00 | 005,868,352 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/11/23 22:59:00 | 002,660,160 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/11/23 22:59:00 | 002,506,048 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/11/23 22:59:00 | 002,403,136 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2011/11/23 22:59:00 | 002,374,464 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/11/23 22:59:00 | 002,206,016 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/11/23 22:59:00 | 002,095,424 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2011/11/23 22:59:00 | 001,726,272 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/11/23 22:59:00 | 001,466,176 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/11/23 22:59:00 | 000,068,928 | —- | M] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/11/23 22:59:00 | 000,061,248 | —- | M] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/11/23 22:59:00 | 000,007,653 | —- | M] () – C:\Windows\SysNative\nvinfo.pb
[2011/11/23 20:47:47 | 006,004,544 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2011/11/23 20:41:24 | 003,028,800 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2011/11/23 20:38:53 | 002,562,368 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2011/11/23 20:38:44 | 000,118,080 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2011/11/23 20:38:44 | 000,063,296 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/18 02:35:24 | 263,229,758 | -H– | C] () – C:\Users\Joseph\Desktop\bt_lizzy_tayler.wmv
[2011/12/18 02:08:36 | 386,932,942 | -H– | C] () – C:\Users\Joseph\Desktop\NaughtyBlog.org_bronze_goddess_big.mp4
[2011/12/18 01:21:56 | 181,085,211 | -H– | C] () – C:\Users\Joseph\Desktop\rapidrar_com_caprice.gabriella.come.to.me.540.wmv
[2011/12/18 01:19:21 | 433,702,606 | -H– | C] () – C:\Users\Joseph\Desktop\paint_and_pussy_big.mp4
[2011/12/17 12:18:19 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/17 02:27:52 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/12/17 02:27:52 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/12/17 02:27:52 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/12/17 02:27:52 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/12/17 02:27:52 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/12/16 21:36:23 | 000,000,545 | —- | C] () – C:\Users\Joseph\Desktop\MBR.zip
[2011/12/16 21:35:48 | 000,000,512 | —- | C] () – C:\Users\Joseph\Desktop\MBR.dat
[2011/12/16 02:39:13 | 000,625,664 | —- | C] () – C:\Users\Joseph\Desktop\dds.scr
[2011/12/16 00:31:43 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/12/15 14:18:26 | 000,001,097 | —- | C] () – C:\Users\Joseph\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeArc.lnk
[2011/12/15 14:18:26 | 000,001,073 | —- | C] () – C:\Users\Joseph\Desktop\FreeArc.lnk
[2011/12/15 01:40:53 | 000,007,653 | —- | C] () – C:\Windows\SysNative\nvinfo.pb
[2011/12/09 23:50:30 | 000,010,382 | —- | C] () – C:\Users\Joseph\Desktop\Joseph_Zelada_4c_Code.c
[2011/12/09 23:50:27 | 000,012,864 | —- | C] () – C:\Users\Joseph\Desktop\Joseph_Zelada_2c_Code.c
[2011/12/09 23:50:22 | 000,013,203 | —- | C] () – C:\Users\Joseph\Desktop\Joseph_Zelada_1b_Code.c
[2011/12/09 23:47:26 | 000,021,293 | —- | C] () – C:\Users\Joseph\Desktop\Untitled 1.odt
[2011/12/09 23:45:00 | 000,039,026 | —- | C] () – C:\Users\Joseph\Desktop\Algorithms.pdf
[2011/12/09 04:04:24 | 000,030,391 | —- | C] () – C:\Users\Joseph\Desktop\Algorithms.exe
[2011/12/09 04:04:23 | 000,006,784 | —- | C] () – C:\Users\Joseph\Desktop\Algorithms.o
[2011/12/08 16:29:35 | 000,121,449 | —- | C] () – C:\Users\Joseph\Desktop\Final_ProjectF11.pdf
[2011/12/08 15:36:44 | 000,001,083 | —- | C] () – C:\Users\Joseph\Documents - Shortcut.lnk
[2011/12/08 01:24:24 | 000,291,827 | —- | C] () – C:\Windows\To the Moon Uninstaller.exe
[2011/12/07 02:57:00 | 000,010,373 | —- | C] () – C:\Users\Joseph\Desktop\Algorithms.c
[2011/12/02 21:30:54 | 000,028,961 | —- | C] () – C:\Users\Joseph\Desktop\Ethics Module.odt
[2011/11/24 22:31:25 | 000,000,023 | —- | C] () – C:\Windows\BlendSettings.ini
[2011/08/25 16:45:23 | 000,000,600 | —- | C] () – C:\Users\Joseph\AppData\Local\PUTTY.RND
[2011/08/09 03:25:06 | 000,103,736 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/08/09 03:21:43 | 000,066,872 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/07/05 20:44:19 | 000,011,005 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2011/07/05 20:43:41 | 000,002,836 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [ID Tag Update] Codec.dat
[2011/07/05 20:43:32 | 000,003,002 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Multi Encoder] Codec.dat
[2011/07/05 20:43:25 | 000,002,879 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Arrange Audio] Codec.dat
[2011/07/05 20:43:20 | 000,002,871 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Audio Info] Codec.dat
[2011/07/05 20:43:15 | 000,002,869 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Tag From Filename] Codec.dat
[2011/07/05 20:43:09 | 000,002,862 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Length Split] Codec.dat
[2011/07/05 20:43:04 | 000,002,999 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [Channel Split] Codec.dat
[2011/07/05 20:42:57 | 000,002,900 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp [ReplayGain] Codec.dat
[2011/07/05 20:39:25 | 003,480,752 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2011/07/05 20:39:25 | 000,014,645 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2011/07/02 02:48:16 | 000,130,268 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/04/22 22:20:25 | 000,007,595 | —- | C] () – C:\Users\Joseph\AppData\Local\Resmon.ResmonCfg
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/03/28 13:35:16 | 000,202,213 | —- | C] () – C:\Windows\libmpg123-0.dll
[2011/03/28 13:35:16 | 000,190,464 | —- | C] () – C:\Windows\libvorbis.dll
[2011/03/28 13:35:16 | 000,045,568 | —- | C] () – C:\Windows\libg7221_decode.dll
[2011/01/17 19:59:02 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\LXDNinst.dll
[2011/01/17 19:59:02 | 000,335,872 | —- | C] () – C:\Windows\SysWow64\lxdncomx.dll
[2011/01/05 22:41:40 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011/01/05 22:41:39 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/01/05 22:41:38 | 002,942,464 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2011/01/05 22:41:38 | 000,810,496 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/01/05 22:41:38 | 000,183,808 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/01/05 22:41:38 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/01/05 22:15:27 | 002,625,640 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/05 22:08:35 | 000,921,665 | —- | C] () – C:\Windows\SysWow64\msvcrt-ruby18.dll
[2011/01/05 22:08:35 | 000,271,264 | —- | C] () – C:\Windows\SysWow64\vbrun100.dll
[2011/01/05 22:08:35 | 000,210,944 | —- | C] () – C:\Windows\SysWow64\msvcrt10.dll
[2011/01/05 22:08:34 | 000,027,136 | —- | C] () – C:\Windows\SysWow64\pythonw.exe
[2011/01/05 22:08:34 | 000,026,624 | —- | C] () – C:\Windows\SysWow64\python.exe
[2011/01/05 22:08:34 | 000,020,537 | —- | C] () – C:\Windows\SysWow64\rubyw.exe
[2011/01/05 22:08:34 | 000,020,536 | —- | C] () – C:\Windows\SysWow64\ruby.exe
[2009/07/23 14:49:06 | 000,782,336 | —- | C] () – C:\Windows\SysWow64\lxdndrs.dll
[2009/07/13 23:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/05/14 08:46:42 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\lxdncaps.dll
[2007/10/02 09:51:10 | 000,069,632 | —- | C] () – C:\Windows\SysWow64\lxdncnv4.dll

========== LOP Check ==========

[2011/11/14 13:18:22 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\ApexDC++
[2011/06/19 18:29:20 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Bioshock2
[2011/02/25 15:39:18 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Broken Rules
[2011/06/22 13:37:06 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Cakewalk
[2011/01/06 00:31:47 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\DAEMON Tools Lite
[2011/07/05 21:26:02 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\dBpoweramp
[2011/12/09 01:33:11 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\DC++
[2011/11/23 21:53:18 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\digipen
[2011/07/05 02:54:54 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\DiskAid
[2011/03/20 15:09:47 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Emulators
[2011/04/09 22:08:27 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\FLV Extract
[2011/01/08 14:10:08 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Foxit Software
[2011/12/15 14:18:39 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\FreeArc
[2011/06/21 19:43:04 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\ImgBurn
[2011/02/06 18:20:09 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Lexmark Productivity Studio
[2011/12/16 02:10:58 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Mipony
[2011/01/14 17:57:41 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\OnLive App
[2011/01/07 15:26:39 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\OpenOffice.org
[2011/09/25 14:22:50 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Quest3D
[2011/12/05 14:48:16 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\redsn0w
[2011/04/06 16:16:04 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Replay Media Catcher 4
[2011/05/24 18:23:04 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\runic games
[2011/03/13 20:00:37 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\ScummVM
[2011/07/21 16:24:19 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\SystemRequirementsLab
[2011/12/15 03:53:25 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\To the Moon - Freebird Games
[2011/07/17 23:01:16 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\TuneUpMedia
[2011/01/22 11:15:57 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Unity
[2011/12/16 03:39:56 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\uTorrent
[2011/03/05 15:21:00 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Western Digital
[2011/03/01 20:30:41 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Windows Live Writer
[2011/03/15 15:42:17 | 000,000,000 | —D | M] – C:\Users\Joseph\AppData\Roaming\Xilisoft
[2011/12/16 23:45:43 | 000,032,530 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/11/20 06:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/01/05 23:53:38 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/12/17 02:49:53 | 000,019,293 | —- | M] () – C:\ComboFix.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2008/04/11 09:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/12/18 12:45:26 | 3217,199,104 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 09:32:30 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 09:32:30 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 09:32:30 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 09:32:30 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 09:32:30 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 09:32:30 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 09:32:30 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 09:32:30 | 000,092,176 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 09:32:30 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 09:32:30 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/12/01 23:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/12/18 12:45:32 | 4289,601,536 | -HS- | M] () – C:\pagefile.sys
[2011/12/16 02:22:22 | 000,082,634 | —- | M] () – C:\TDSSKiller.2.6.23.0_16.12.2011_02.21.47_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/13 23:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 14:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/22 18:19:30 | 000,000,221 | -HS- | M] () – C:\Users\Joseph\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/12/09 05:26:15 | 000,030,391 | —- | M] () – C:\Users\Joseph\Desktop\Algorithms.exe
[2011/12/16 21:14:13 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\Joseph\Desktop\aswMBR.exe
[2011/12/17 02:18:34 | 004,341,424 | R— | M] (Swearware) – C:\Users\Joseph\Desktop\ComboFix.exe
[2011/04/22 20:55:02 | 000,939,360 | —- | M] (techPowerUp (www.techpowerup.com)) – C:\Users\Joseph\Desktop\GPU-Z.0.5.3.exe
[2011/12/16 02:38:57 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Joseph\Desktop\HiJackThis.exe
[2011/12/17 12:17:22 | 009,852,544 | —- | M] (Malwarebytes Corporation ) – C:\Users\Joseph\Desktop\mbam-setup-1.51.2.1300.exe
[2011/12/16 02:38:51 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Joseph\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Will do, here's the report. ComboFix 11-12-18.01 - Joseph 12/18/2011 16:47:44.2.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4091.2844 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: COMODO Antivirus *Disabled/Updated* {7554F4C5-5EC0-2FC6-8192-8DF831DBED51} FW: COMODO Firewall *Disabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A} SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 ))))))))))))))))))))))))))))))) . . 2011-12-18 22:55 . 2011-12-18 22:55 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-12-18 05:08 . 2011-12-18 05:08 ——– d—–w- c:\program files (x86)\ESET 2011-12-17 18:18 . 2011-12-17 18:18 ——– d—–w- c:\users\Joseph\AppData\Roaming\Malwarebytes 2011-12-17 18:18 . 2011-12-17 18:18 ——– d—–w- c:\programdata\Malwarebytes 2011-12-17 18:18 . 2011-12-17 18:18 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-12-17 18:18 . 2011-08-31 23:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-16 06:31 . 2011-12-16 06:31 ——– d—–w- c:\program files\iTunes 2011-12-16 06:31 . 2011-12-16 06:31 ——– d—–w- c:\program files\iPod 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-12-16 06:27 . 2011-12-16 06:27 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-12-15 20:45 . 2011-11-22 08:53 ——– d—–w- c:\program files (x86)\Batman - Arkham City 2011-12-15 20:18 . 2011-12-15 20:18 ——– d—–w- c:\users\Joseph\AppData\Roaming\FreeArc 2011-12-15 20:18 . 2011-12-15 20:18 ——– d—–w- c:\program files (x86)\FreeArc 2011-12-15 07:46 . 2011-12-16 19:25 ——– d—–w- c:\users\UpdatusUser 2011-12-15 07:44 . 2011-11-24 02:47 6004544 —-a-w- c:\windows\system32\nvcpl.dll 2011-12-15 07:44 . 2011-11-24 02:41 3028800 —-a-w- c:\windows\system32\nvsvc64.dll 2011-12-15 07:44 . 2011-11-24 02:38 2562368 —-a-w- c:\windows\system32\nvsvcr.dll 2011-12-15 07:44 . 2011-11-24 02:38 889664 —-a-w- c:\windows\system32\nvvsvc.exe 2011-12-15 07:44 . 2011-11-24 02:38 63296 —-a-w- c:\windows\system32\nvshext.dll 2011-12-15 07:44 . 2011-11-24 02:38 118080 —-a-w- c:\windows\system32\nvmctray.dll 2011-12-15 07:44 . 2011-12-15 07:44 ——– d—–w- c:\programdata\NVIDIA Corporation 2011-12-15 07:38 . 2011-12-15 07:46 ——– d—–w- c:\program files (x86)\NVIDIA Corporation 2011-12-15 07:27 . 2011-11-09 14:21 31040 —-a-w- c:\windows\system32\nvhdap64.dll 2011-12-15 07:27 . 2011-11-09 14:21 72512 —-a-w- c:\windows\system32\nvapo64v.dll 2011-12-15 07:27 . 2011-11-09 14:21 187200 —-a-w- c:\windows\system32\drivers\nvhda64v.sys 2011-12-15 07:27 . 2011-11-09 14:21 1451840 —-a-w- c:\windows\system32\nvhdagenco6420103.dll 2011-12-13 23:55 . 2011-10-26 05:21 43520 —-a-w- c:\windows\system32\csrsrv.dll 2011-12-13 23:55 . 2011-11-24 04:52 3145216 —-a-w- c:\windows\system32\win32k.sys 2011-12-13 23:54 . 2011-10-15 06:31 723456 —-a-w- c:\windows\system32\EncDec.dll 2011-12-13 23:54 . 2011-10-15 05:38 534528 —-a-w- c:\windows\SysWow64\EncDec.dll 2011-12-13 23:54 . 2011-11-05 05:32 2048 —-a-w- c:\windows\system32\tzres.dll 2011-12-13 23:54 . 2011-11-05 04:26 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2011-12-08 07:26 . 2011-12-15 09:53 ——– d—–w- c:\users\Joseph\AppData\Roaming\To the Moon - Freebird Games 2011-12-08 07:24 . 2011-12-08 07:24 291827 —-a-w- c:\windows\To the Moon Uninstaller.exe 2011-12-08 07:23 . 2011-12-08 07:25 ——– d—–w- c:\program files (x86)\To the Moon 2011-12-05 20:34 . 2011-12-05 20:48 ——– d—–w- c:\users\Joseph\AppData\Roaming\redsn0w 2011-12-05 18:43 . 2009-05-18 19:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-12-05 18:43 . 2008-04-17 18:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-12-05 18:43 . 2008-04-17 18:12 107368 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-12-05 18:41 . 2011-12-05 18:41 ——– d—–w- c:\program files\Bonjour 2011-12-05 18:41 . 2011-12-05 18:41 ——– d—–w- c:\program files (x86)\Bonjour 2011-11-29 19:25 . 2011-12-01 20:59 ——– d—–w- c:\programdata\CPA_VA 2011-11-26 05:13 . 2011-11-26 05:13 ——– d—–w- c:\programdata\id Software 2011-11-25 22:48 . 2011-11-26 04:35 ——– d—–w- c:\program files (x86)\Common Files\BOSS 2011-11-25 04:29 . 2011-11-25 06:38 ——– d—–w- c:\users\Joseph\AppData\Local\Oblivion 2011-11-24 03:53 . 2011-11-24 03:53 ——– d—–w- c:\users\Joseph\AppData\Roaming\digipen 2011-11-24 03:53 . 2011-11-24 03:53 ——– d—–w- c:\users\Joseph\AppData\Local\digipen 2011-11-24 03:03 . 2011-11-24 03:03 ——– d—–w- c:\program files (x86)\Digipen . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-27 06:04 . 2011-06-01 15:21 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-12 08:52 . 2011-11-12 08:52 1700352 —-a-w- c:\windows\SysWow64\gdiplus.dll 2011-10-24 20:29 . 2011-10-24 20:29 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2011-10-24 20:29 . 2011-10-24 20:29 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts 2011-10-08 00:48 . 2011-10-08 00:48 93200 —-a-w- c:\windows\system32\drivers\inspect.sys 2011-10-08 00:47 . 2011-10-08 00:47 574216 —-a-w- c:\windows\system32\drivers\cmdGuard.sys 2011-10-08 00:47 . 2011-10-08 00:47 43248 —-a-w- c:\windows\system32\drivers\cmdhlp.sys 2011-10-08 00:47 . 2011-10-08 00:47 16528 —-a-w- c:\windows\system32\drivers\cmderd.sys 2011-10-08 00:47 . 2011-10-08 00:47 41200 —-a-w- c:\windows\system32\cmdcsr.dll 2011-10-08 00:47 . 2011-10-08 00:47 300200 —-a-w- c:\windows\SysWow64\guard32.dll 2011-10-08 00:47 . 2011-10-08 00:47 388280 —-a-w- c:\windows\system32\guard64.dll 2011-10-07 04:16 . 2011-11-11 22:50 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{69556484-62FB-40E4-990B-612BC2438C5C}\mpengine.dll 2011-10-03 11:06 . 2011-01-06 04:09 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-09-29 16:29 . 2011-11-08 22:32 1923952 —-a-w- c:\windows\system32\drivers\tcpip.sys . . ((((((((((((((((((((((((((((( SnapShot@2011-12-17_08.43.52 ))))))))))))))))))))))))))))))))))))))))) . + 2011-01-06 04:40 . 2011-12-18 22:38 37738 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin - 2009-07-14 05:10 . 2011-12-17 08:45 40136 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-12-18 22:38 40136 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-01-06 04:26 . 2011-12-18 22:38 16354 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3141220578-551946994-1010253117-1000_UserData.bin - 2011-01-06 05:59 . 2011-12-17 08:41 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-01-06 05:59 . 2011-12-18 22:36 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-01-06 05:59 . 2011-12-17 08:41 65536 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-01-06 05:59 . 2011-12-18 22:36 65536 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-12-18 22:36 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2011-12-17 08:41 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-12-18 22:36 . 2011-12-18 22:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-12-17 08:41 . 2011-12-17 08:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2011-12-18 22:36 . 2011-12-18 22:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-12-17 08:41 . 2011-12-17 08:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-07-14 05:01 . 2011-12-18 19:35 285964 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2011-12-17 08:40 285964 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-01-06 05:17 . 2011-12-18 05:01 1474832 c:\windows\system32\drivers\sfi.dat - 2011-01-06 05:17 . 2011-12-17 03:45 1474832 c:\windows\system32\drivers\sfi.dat - 2011-01-06 05:17 . 2011-12-16 23:59 7103312 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3141220578-551946994-1010253117-1000-12288.dat + 2011-01-06 05:17 . 2011-12-18 11:58 7103312 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3141220578-551946994-1010253117-1000-12288.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\lxdnserv.exe [2009-04-28 29184] R3 appliand;Applian Network Service;c:\windows\system32\DRIVERS\appliand.sys [x] R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe [2011-12-15 131912] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 1267000] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe [2007-11-28 1039872] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2011-11-24 2348864] S3 appliandMP;appliandMP;c:\windows\system32\DRIVERS\appliand.sys [x] S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2mdx64.sys [x] S3 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sdx64.sys [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-12-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3141220578-551946994-1010253117-1000Core.job - c:\users\Joseph\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-06 05:10] . 2011-12-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3141220578-551946994-1010253117-1000UA.job - c:\users\Joseph\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-06 05:10] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184] "lxdnmon.exe"="c:\program files (x86)\Lexmark 2600 Series\lxdnmon.exe" [2010-02-04 660136] "lxdnamon"="c:\program files (x86)\Lexmark 2600 Series\lxdnamon.exe" [2010-02-04 16040] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 9264456] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\guard64.dll . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download with Mipony - file://c:\program files (x86)\MiPony\Browser\IEContext.htm TCP: DhcpNameServer = 192.168.1.1 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3141220578-551946994-1010253117-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3141220578-551946994-1010253117-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-12-18 16:58:18 ComboFix-quarantined-files.txt 2011-12-18 22:58 ComboFix2.txt 2011-12-17 08:49 . Pre-Run: 13,068,668,928 bytes free Post-Run: 13,028,626,432 bytes free . - - End Of File - - 77BABC2BB9E72764B3F18B3E69E5DD84
Thanks. After reading over the link, it seems svchost is running alright. All else seems to be fine as well on the machine . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 20:02:05.14 on Sun 12/18/2011 Internet Explorer: 9.0.8112.16421 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4091.2625 [GMT -6:00] . AV: COMODO Antivirus *Disabled/Updated* {7554F4C5-5EC0-2FC6-8192-8DF831DBED51} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC} FW: COMODO Firewall *Disabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k HsfXAudioService C:\Windows\system32\DRIVERS\o2flash.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Windows\System32\StikyNot.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\MiPony\MiPony.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\rundll32.exe C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Joseph\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Joseph\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: Download with Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun mRun-x64: [lxdnmon.exe] "C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe" mRun-x64: [lxdnamon] "C:\Program Files (x86)\Lexmark 2600 Series\lxdnamon.exe" mRun-x64: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h AppInit_DLLs-X64: C:\Windows\System32\guard64.dll . ============= SERVICES / DRIVERS =============== . R1 cmderd;COMODO Internet Security Eradication Driver;C:\Windows\System32\drivers\cmderd.sys [2011-10-7 16528] R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\System32\drivers\cmdGuard.sys [2011-10-7 574216] R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\System32\drivers\cmdhlp.sys [2011-10-7 43248] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2011-1-29 21992] R2 HsfXAudioService;HsfXAudioService;C:\Windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 27136] R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2011-12-15 2348864] R3 appliandMP;appliandMP;C:\Windows\System32\drivers\appliand.sys [2010-6-24 33888] R3 CAXHWAZL;CAXHWAZL;C:\Windows\System32\drivers\CAXHWAZL.sys [2011-1-5 292864] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-12-17 25416] R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2010-1-13 7675392] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2011-12-15 187200] R3 O2MDRDR;O2MDRDR;C:\Windows\System32\drivers\o2mdx64.sys [2009-5-7 63264] R3 O2SDRDR;O2SDRDR;C:\Windows\System32\drivers\o2sdx64.sys [2009-5-7 49696] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264] S2 CLPSLS;COMODO livePCsupport Service;C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 1267000] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 lxdn_device;lxdn_device;C:\Windows\system32\lxdncoms.exe -service –> C:\Windows\system32\lxdncoms.exe -service [?] S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;C:\Windows\System32\spool\drivers\x64\3\lxdnserv.exe [2009-4-28 29184] S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-17 366152] S3 appliand;Applian Network Service;C:\Windows\System32\drivers\appliand.sys [2010-6-24 33888] S3 Desura Install Service;Desura Install Service;C:\Program Files (x86)\Common Files\Desura\desura_service.exe [2011-6-5 131912] S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-1-29 48488] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2010-12-25 5435904] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-3-12 20992] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864] S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-12 59392] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-12-14 1255736] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2009-2-13 14464] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2011-12-18 23:01:38 ——– d-sh–w- C:\$RECYCLE.BIN 2011-12-18 05:08:33 ——– d—–w- C:\Program Files (x86)\ESET 2011-12-17 18:18:53 ——– d—–w- C:\Users\Joseph\AppData\Roaming\Malwarebytes 2011-12-17 18:18:18 ——– d—–w- C:\PROGRA~3\Malwarebytes 2011-12-17 18:18:15 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-12-17 18:18:15 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-12-17 08:27:52 98816 —-a-w- C:\Windows\sed.exe 2011-12-17 08:27:52 518144 —-a-w- C:\Windows\SWREG.exe 2011-12-17 08:27:52 256000 —-a-w- C:\Windows\PEV.exe 2011-12-17 08:27:52 208896 —-a-w- C:\Windows\MBR.exe 2011-12-16 06:31:05 ——– d—–w- C:\Program Files\iTunes 2011-12-16 06:31:05 ——– d—–w- C:\Program Files\iPod 2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-12-16 06:27:17 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-12-15 20:45:31 ——– d—–w- C:\Program Files (x86)\Batman - Arkham City 2011-12-15 20:18:39 ——– d—–w- C:\Users\Joseph\AppData\Roaming\FreeArc 2011-12-15 20:18:21 ——– d—–w- C:\Program Files (x86)\FreeArc 2011-12-15 07:44:59 889664 —-a-w- C:\Windows\System32\nvvsvc.exe 2011-12-15 07:44:59 63296 —-a-w- C:\Windows\System32\nvshext.dll 2011-12-15 07:44:59 6004544 —-a-w- C:\Windows\System32\nvcpl.dll 2011-12-15 07:44:59 3028800 —-a-w- C:\Windows\System32\nvsvc64.dll 2011-12-15 07:44:59 2562368 —-a-w- C:\Windows\System32\nvsvcr.dll 2011-12-15 07:44:59 118080 —-a-w- C:\Windows\System32\nvmctray.dll 2011-12-15 07:44:02 ——– d—–w- C:\PROGRA~3\NVIDIA Corporation 2011-12-15 07:38:40 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation 2011-12-15 07:27:49 72512 —-a-w- C:\Windows\System32\nvapo64v.dll 2011-12-15 07:27:49 31040 —-a-w- C:\Windows\System32\nvhdap64.dll 2011-12-15 07:27:49 187200 —-a-w- C:\Windows\System32\drivers\nvhda64v.sys 2011-12-15 07:27:49 1451840 —-a-w- C:\Windows\System32\nvhdagenco6420103.dll 2011-12-13 23:55:34 43520 —-a-w- C:\Windows\System32\csrsrv.dll 2011-12-13 23:55:13 3145216 —-a-w- C:\Windows\System32\win32k.sys 2011-12-13 23:54:51 723456 —-a-w- C:\Windows\System32\EncDec.dll 2011-12-13 23:54:51 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll 2011-12-13 23:54:35 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2011-12-13 23:54:35 2048 —-a-w- C:\Windows\System32\tzres.dll 2011-12-08 07:26:58 ——– d—–w- C:\Users\Joseph\AppData\Roaming\To the Moon - Freebird Games 2011-12-08 07:24:24 291827 —-a-w- C:\Windows\To the Moon Uninstaller.exe 2011-12-08 07:23:47 ——– d—–w- C:\Program Files (x86)\To the Moon 2011-12-05 20:34:06 ——– d—–w- C:\Users\Joseph\AppData\Roaming\redsn0w 2011-12-05 18:43:39 34152 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2011-12-05 18:43:39 126312 —-a-w- C:\Windows\System32\GEARAspi64.dll 2011-12-05 18:43:39 107368 —-a-w- C:\Windows\SysWow64\GEARAspi.dll 2011-12-05 18:41:46 ——– d—–w- C:\Program Files\Bonjour 2011-12-05 18:41:46 ——– d—–w- C:\Program Files (x86)\Bonjour 2011-11-29 19:25:20 ——– d—–w- C:\PROGRA~3\CPA_VA 2011-11-26 05:13:25 ——– d—–w- C:\PROGRA~3\id Software 2011-11-25 22:48:57 ——– d—–w- C:\Program Files (x86)\Common Files\BOSS 2011-11-25 04:29:22 ——– d—–w- C:\Users\Joseph\AppData\Local\Oblivion 2011-11-24 03:53:18 ——– d—–w- C:\Users\Joseph\AppData\Roaming\digipen 2011-11-24 03:53:18 ——– d—–w- C:\Users\Joseph\AppData\Local\digipen 2011-11-24 03:03:48 ——– d—–w- C:\Program Files (x86)\Digipen . ==================== Find3M ==================== . 2011-11-27 06:04:02 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-12 08:52:32 1700352 —-a-w- C:\Windows\SysWow64\gdiplus.dll 2011-11-04 01:53:39 2309120 —-a-w- C:\Windows\System32\jscript9.dll 2011-11-04 01:44:47 1390080 —-a-w- C:\Windows\System32\wininet.dll 2011-11-04 01:44:21 1493504 —-a-w- C:\Windows\System32\inetcpl.cpl 2011-11-04 01:34:43 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-11-03 22:47:42 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-11-03 22:40:21 1427456 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2011-11-03 22:39:47 1127424 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-11-03 22:31:57 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-10-24 20:29:02 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2011-10-24 20:29:02 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2011-10-08 00:47:58 574216 —-a-w- C:\Windows\System32\drivers\cmdGuard.sys 2011-10-08 00:47:58 43248 —-a-w- C:\Windows\System32\drivers\cmdhlp.sys 2011-10-08 00:47:56 16528 —-a-w- C:\Windows\System32\drivers\cmderd.sys 2011-10-08 00:47:14 41200 —-a-w- C:\Windows\System32\cmdcsr.dll 2011-10-08 00:47:12 300200 —-a-w- C:\Windows\SysWow64\guard32.dll 2011-10-08 00:47:10 388280 —-a-w- C:\Windows\System32\guard64.dll 2011-10-03 11:06:03 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-09-29 16:29:28 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys . ============= FINISH: 20:03:01.98 ===============
Hi,

Looks good, just some housekeeping to do now, please do the following:


You can delete the TDSSKiller, DDS and aswMBR logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI