J_Rapp
Topic Starter
First off my system is Windows Vista Ultimate with Service Pack 1. My problem began last Sunday when I went to a sports site to view a blocked NFL game. It continually asked to download a plug in to play the video. I ignored that except to close the window as the video actually played. Suddenly the Windows Vista 2012 Security popup window popped up. Having removed this type of virus in the past. I went instantly to the Process tab in Task Manager and deleted the three random character exe process. I then went into my regedit and deleted all instances of that process. I left the sports page and did not go back. I still was getting redirects in my searches in Google and Yahoo. I eventually discovered that I have this PING.EXE 32* which I cannot remove. I do scans with Malware bits and Trend Micros program. Malware bits finds PUP.BitMiner and deletes it but it returns every time. I should note that I am unable to open Windows Defender or Windows Firewall on my computer. I have installed Zone Alarms firewall.
I did attempt to clear the problem with rkill but to no avail.
I ran OTL with the custom script you have in your Spyware removal sticky page. Here are the results:
OTL logfile created on: 12/16/2011 12:27:00 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\J_Rapp\Downloads
64bit-Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 5.79 Gb Available Physical Memory | 72.34% Memory free
8.16 Gb Paging File | 5.91 Gb Available in Paging File | 72.47% Paging File free
Paging file location(s): c:\pagefile.sys 400 1000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 39.06 Gb Total Space | 5.00 Gb Free Space | 12.80% Space Free | Partition Type: NTFS
Drive D: | 29.35 Gb Total Space | 16.76 Gb Free Space | 57.10% Space Free | Partition Type: NTFS
Drive E: | 100.27 Gb Total Space | 10.99 Gb Free Space | 10.96% Space Free | Partition Type: NTFS
Drive F: | 3.66 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 465.76 Gb Total Space | 37.84 Gb Free Space | 8.13% Space Free | Partition Type: NTFS
Drive H: | 465.76 Gb Total Space | 12.57 Gb Free Space | 2.70% Space Free | Partition Type: NTFS
Drive I: | 465.76 Gb Total Space | 24.07 Gb Free Space | 5.17% Space Free | Partition Type: NTFS
Computer Name: EDITOR1-PC | User Name: J_Rapp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/16 12:00:41 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\J_Rapp\Downloads\OTL.exe
PRC - [2011/11/11 12:34:36 | 000,924,632 | —- | M] (Mozilla Corporation) – D:\Programs\firefox.exe
PRC - [2011/11/11 12:34:35 | 000,016,856 | —- | M] (Mozilla Corporation) – D:\Programs\plugin-container.exe
PRC - [2011/11/09 20:05:42 | 002,420,616 | —- | M] (Check Point Software Technologies LTD) – D:\Programs\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2011/11/09 20:01:38 | 000,073,360 | —- | M] (Check Point Software Technologies LTD) – D:\Programs\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2011/08/31 17:00:48 | 001,047,208 | —- | M] (Malwarebytes Corporation) – D:\Programs\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | —- | M] (Malwarebytes Corporation) – D:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/06/24 11:34:52 | 000,091,456 | —- | M] () – C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnectService.exe
PRC - [2010/06/24 11:34:50 | 000,279,360 | —- | M] (Motorola) – C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnect.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | —- | M] (Safer Networking Limited) – D:\Programs\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/08/28 18:34:14 | 013,145,448 | —- | M] (Adobe Systems, Inc.) – D:\Applications\Adobe Bridge CS4\Bridge.exe
PRC - [2008/01/20 18:48:56 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\PING.EXE
========== Modules (No Company Name) ==========
MOD - [2011/11/11 12:34:35 | 001,989,592 | —- | M] () – D:\Programs\mozjs.dll
MOD - [2011/10/16 10:07:52 | 008,522,400 | —- | M] () – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2009/02/11 21:05:26 | 001,507,328 | —- | M] () – C:\Windows\SysWOW64\nView.dll
MOD - [2008/08/28 15:54:56 | 000,891,904 | —- | M] () – D:\Applications\Adobe Bridge CS4\FileInfo.dll
MOD - [2008/08/28 15:54:56 | 000,502,272 | —- | M] () – D:\Applications\Adobe Bridge CS4\AdobeXMPFiles.dll
MOD - [2008/08/28 15:54:56 | 000,424,960 | —- | M] () – D:\Applications\Adobe Bridge CS4\AdobeXMP.dll
MOD - [2008/08/28 15:53:58 | 000,073,728 | —- | M] () – D:\Applications\Adobe Bridge CS4\Symlib.dll
MOD - [2008/08/28 15:47:50 | 002,748,416 | —- | M] () – D:\Applications\Adobe Bridge CS4\libmysqld.dll
MOD - [2008/01/20 18:47:46 | 000,223,232 | —- | M] () – \\?\globalroot\systemroot\syswow64\mswsock.dll
MOD - [2008/01/20 18:47:46 | 000,223,232 | —- | M] () – \\.\globalroot\systemroot\syswow64\mswsock.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/11/03 06:44:42 | 000,827,520 | —- | M] (Check Point Software Technologies) [Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe – (IswSvc)
SRV:64bit: - [2009/03/13 17:17:28 | 001,038,088 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe – (FLEXnet Licensing Service 64)
SRV:64bit: - [2008/12/11 06:08:52 | 004,297,728 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe – (NVIDIA Performance Driver Service)
SRV:64bit: - [2008/01/20 18:50:23 | 000,195,584 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2011/11/09 20:05:42 | 002,420,616 | —- | M] (Check Point Software Technologies LTD) [Auto | Running] – D:\Programs\CheckPoint\ZoneAlarm\vsmon.exe – (vsmon)
SRV - [2011/08/31 17:00:48 | 000,366,152 | —- | M] (Malwarebytes Corporation) [Auto | Running] – D:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2010/06/24 11:34:52 | 000,091,456 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnectService.exe – (MotoConnect Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/08/25 22:20:39 | 000,288,112 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe – (Adobe Version Cue CS4)
SRV - [2009/03/13 17:15:16 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/07/27 10:03:13 | 000,069,632 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/01/20 18:46:08 | 000,428,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\WindowsMobile\wcescomm.dll – (WcesComm)
SRV - [2008/01/20 18:46:08 | 000,211,968 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\WindowsMobile\rapimgr.dll – (RapiMgr)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/11/03 06:44:22 | 000,033,672 | —- | M] (Check Point Software Technologies) [Kernel | Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys – (ISWKL)
DRV:64bit: - [2011/08/31 17:00:50 | 000,025,416 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2011/05/07 17:51:34 | 000,448,088 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\DRIVERS\vsdatant.sys – (Vsdatant)
DRV:64bit: - [2009/08/25 22:05:34 | 000,086,584 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\adfs.sys – (adfs)
DRV:64bit: - [2009/05/09 01:14:20 | 000,015,752 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\NuidFltr.sys – (NuidFltr)
DRV:64bit: - [2009/03/19 15:34:18 | 000,029,544 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/12/19 16:08:28 | 000,033,160 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\point64k.sys – (Point64)
DRV:64bit: - [2008/02/06 02:00:00 | 000,054,480 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2008/01/20 18:46:34 | 000,048,768 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\avc.sys – (Avc)
DRV:64bit: - [2008/01/20 18:46:34 | 000,017,536 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\avcstrm.sys – (AVCSTRM)
DRV:64bit: - [2008/01/20 18:46:08 | 000,056,448 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\mstape.sys – (MSTAPE)
DRV:64bit: - [2008/01/20 18:46:05 | 000,058,496 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\61883.sys – (61883)
DRV:64bit: - [2008/01/20 18:46:01 | 001,523,712 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS – (VST64_DPV)
DRV:64bit: - [2008/01/20 18:46:01 | 000,724,480 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS – (winachsf)
DRV:64bit: - [2008/01/20 18:46:01 | 000,392,704 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTBS26.SYS – (VST64HWBS2)
DRV:64bit: - [2008/01/20 18:46:01 | 000,061,568 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\msdv.sys – (MSDV)
DRV:64bit: - [2008/01/20 18:46:00 | 000,019,456 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\usb8023x.sys – (usb_rndisx)
DRV:64bit: - [2008/01/10 13:46:36 | 000,245,856 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\e1q60x64.sys – (e1qexpress) Intel®
DRV - [2009/08/25 22:05:34 | 000,086,584 | —- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysWow64\drivers\adfs.sys – (adfs)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.washingtonpost.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 74 4D A5 10 7F 60 B8 42 A9 03 DF C4 30 38 A0 3C [binary data]
IE - HKCU\..\URLSearchHook: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:57354
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:0.1.2008d
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.0.0
FF - prefs.js..extensions.enabledItems: [removed]:0.9
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Applications\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Programs\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\J_Rapp\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\J_Rapp\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER [2011/12/14 21:53:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2011/12/14 21:53:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: D:\Programs\components [2011/11/11 12:34:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: D:\Programs\plugins [2011/10/20 08:44:11 | 000,000,000 | —D | M]
[2010/07/15 14:02:42 | 000,000,000 | —D | M] (No name found) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Extensions
[2010/07/15 14:02:42 | 000,000,000 | —D | M] (No name found) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/12/14 21:40:16 | 000,000,000 | —D | M] (No name found) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions
[2011/08/24 21:54:52 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/12/11 11:19:32 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/12/11 13:56:58 | 000,000,000 | —D | M] (XUL Cache) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{7be3443a-4a65-4e89-ad22-b8cf7f1240b4}
[2011/10/27 18:40:18 | 000,000,000 | —D | M] (XUL Cache) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{82be057b-7579-42fd-bbf7-089f2b1d98d0}
[2011/11/11 12:34:45 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/10/03 12:29:15 | 000,000,000 | —D | M] (vShare Plugin) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\vshare@toolbar
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Timezone Definitions for Mozilla Calendar) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Default Shot Palette) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (MSN-Smileys) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (DOM Inspector) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Blackened) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Depth) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Minimal) – D:\CELTEX\EXTENSIONS\[removed]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\J_Rapp\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin5.dll
CHR - plugin: Java™ Platform SE 6 U13 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Java™ Platform SE 6 U13 (Enabled) = D:\Programs\plugins\npdeploytk.dll
CHR - plugin: Adobe Acrobat (Disabled) = D:\Programs\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\J_Rapp\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\J_Rapp\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = D:\Programs\plugins\npLegitCheckPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\J_Rapp\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: iTunes Application Detector (Enabled) = D:\Applications\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\J_Rapp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Users\J_Rapp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Gmail = C:\Users\J_Rapp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
Hosts file not found
O2:64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll ()
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.dll ()
O4:64bit: - HKLM..\Run: [nwiz] C:\Windows\SysNative\nwiz.exe ()
O4:64bit: - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Programs\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] D:\Programs\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [ZoneAlarm] D:\Programs\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [AdobeBridge] D:\Applications\Adobe Bridge CS4\Bridge.exe (Adobe Systems, Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data]
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O12 - Plugin for: .bcf - C:\Program Files (x86)\Internet Explorer\Plugins\NPBelv32.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9E94CFD7-4BF6-485E-A76B-4EB375EB6987}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18 - Protocol\Handler\belarc - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe ()
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\PFW: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\tropeln: DllName - (C:\Windows\system32\config\systemprofile\AppData\Local\tropeln.dll) - C:\Windows\SysWOW64\config\systemprofile\AppData\Local\tropeln.dll ()
O24 - Desktop WallPaper: G:\080629 Yosemite\P1013193.JPG
O24 - Desktop BackupWallPaper: G:\080629 Yosemite\P1013193.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/21 12:00:00 | 000,000,122 | R— | M] () - F:\autorun.inf – [ UDF ]
O33 - MountPoints2\{31343533-0c1c-11de-be1b-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Recycled\ctfmon.exe
O33 - MountPoints2\{31343533-0c1c-11de-be1b-806e6f6e6963}\Shell\Open(&0)\command - "" = F:\Recycled\ctfmon.exe
O33 - MountPoints2\{31343534-0c1c-11de-be1b-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Recycled\ctfmon.exe
O33 - MountPoints2\{3ae57791-07a0-11de-9647-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Recycled\ctfmon.exe
O33 - MountPoints2\{4f87f67c-0a96-11de-8dd2-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Recycled\ctfmon.exe
O33 - MountPoints2\{50c4cd62-1fac-11de-bbcc-003048c60327}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL L:\Recycled\ctfmon.exe
O33 - MountPoints2\{50c4cd62-1fac-11de-bbcc-003048c60327}\Shell\Open(&0)\command - "" = L:\Recycled\ctfmon.exe
O33 - MountPoints2\{6e8450b1-0a83-11de-982c-95d02e640b6d}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL H:\Recycled\ctfmon.exe
O33 - MountPoints2\{98104999-8093-11df-9470-003048c60327}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\Recycled\ctfmon.exe
O33 - MountPoints2\{98104999-8093-11df-9470-003048c60327}\Shell\Open(&0)\command - "" = J:\Recycled\ctfmon.exe
O33 - MountPoints2\{c176ada6-0a93-11de-bb1f-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Recycled\ctfmon.exe
O33 - MountPoints2\{c411b74d-0163-11e0-8cfb-003048c60327}\Shell - "" = AutoRun
O33 - MountPoints2\{c411b74d-0163-11e0-8cfb-003048c60327}\Shell\AutoRun\command - "" = P:\setup.exe -a
O33 - MountPoints2\{d731ab09-b12a-11de-8798-806e6f6e6963}\Shell - "" = AutoRun
LS\x00\x00\x00\x00
I did attempt to clear the problem with rkill but to no avail.
I ran OTL with the custom script you have in your Spyware removal sticky page. Here are the results:
OTL logfile created on: 12/16/2011 12:27:00 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\J_Rapp\Downloads
64bit-Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 5.79 Gb Available Physical Memory | 72.34% Memory free
8.16 Gb Paging File | 5.91 Gb Available in Paging File | 72.47% Paging File free
Paging file location(s): c:\pagefile.sys 400 1000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 39.06 Gb Total Space | 5.00 Gb Free Space | 12.80% Space Free | Partition Type: NTFS
Drive D: | 29.35 Gb Total Space | 16.76 Gb Free Space | 57.10% Space Free | Partition Type: NTFS
Drive E: | 100.27 Gb Total Space | 10.99 Gb Free Space | 10.96% Space Free | Partition Type: NTFS
Drive F: | 3.66 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 465.76 Gb Total Space | 37.84 Gb Free Space | 8.13% Space Free | Partition Type: NTFS
Drive H: | 465.76 Gb Total Space | 12.57 Gb Free Space | 2.70% Space Free | Partition Type: NTFS
Drive I: | 465.76 Gb Total Space | 24.07 Gb Free Space | 5.17% Space Free | Partition Type: NTFS
Computer Name: EDITOR1-PC | User Name: J_Rapp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/16 12:00:41 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\J_Rapp\Downloads\OTL.exe
PRC - [2011/11/11 12:34:36 | 000,924,632 | —- | M] (Mozilla Corporation) – D:\Programs\firefox.exe
PRC - [2011/11/11 12:34:35 | 000,016,856 | —- | M] (Mozilla Corporation) – D:\Programs\plugin-container.exe
PRC - [2011/11/09 20:05:42 | 002,420,616 | —- | M] (Check Point Software Technologies LTD) – D:\Programs\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2011/11/09 20:01:38 | 000,073,360 | —- | M] (Check Point Software Technologies LTD) – D:\Programs\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2011/08/31 17:00:48 | 001,047,208 | —- | M] (Malwarebytes Corporation) – D:\Programs\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | —- | M] (Malwarebytes Corporation) – D:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/06/24 11:34:52 | 000,091,456 | —- | M] () – C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnectService.exe
PRC - [2010/06/24 11:34:50 | 000,279,360 | —- | M] (Motorola) – C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnect.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | —- | M] (Safer Networking Limited) – D:\Programs\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/08/28 18:34:14 | 013,145,448 | —- | M] (Adobe Systems, Inc.) – D:\Applications\Adobe Bridge CS4\Bridge.exe
PRC - [2008/01/20 18:48:56 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\PING.EXE
========== Modules (No Company Name) ==========
MOD - [2011/11/11 12:34:35 | 001,989,592 | —- | M] () – D:\Programs\mozjs.dll
MOD - [2011/10/16 10:07:52 | 008,522,400 | —- | M] () – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2009/02/11 21:05:26 | 001,507,328 | —- | M] () – C:\Windows\SysWOW64\nView.dll
MOD - [2008/08/28 15:54:56 | 000,891,904 | —- | M] () – D:\Applications\Adobe Bridge CS4\FileInfo.dll
MOD - [2008/08/28 15:54:56 | 000,502,272 | —- | M] () – D:\Applications\Adobe Bridge CS4\AdobeXMPFiles.dll
MOD - [2008/08/28 15:54:56 | 000,424,960 | —- | M] () – D:\Applications\Adobe Bridge CS4\AdobeXMP.dll
MOD - [2008/08/28 15:53:58 | 000,073,728 | —- | M] () – D:\Applications\Adobe Bridge CS4\Symlib.dll
MOD - [2008/08/28 15:47:50 | 002,748,416 | —- | M] () – D:\Applications\Adobe Bridge CS4\libmysqld.dll
MOD - [2008/01/20 18:47:46 | 000,223,232 | —- | M] () – \\?\globalroot\systemroot\syswow64\mswsock.dll
MOD - [2008/01/20 18:47:46 | 000,223,232 | —- | M] () – \\.\globalroot\systemroot\syswow64\mswsock.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/11/03 06:44:42 | 000,827,520 | —- | M] (Check Point Software Technologies) [Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe – (IswSvc)
SRV:64bit: - [2009/03/13 17:17:28 | 001,038,088 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe – (FLEXnet Licensing Service 64)
SRV:64bit: - [2008/12/11 06:08:52 | 004,297,728 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe – (NVIDIA Performance Driver Service)
SRV:64bit: - [2008/01/20 18:50:23 | 000,195,584 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2011/11/09 20:05:42 | 002,420,616 | —- | M] (Check Point Software Technologies LTD) [Auto | Running] – D:\Programs\CheckPoint\ZoneAlarm\vsmon.exe – (vsmon)
SRV - [2011/08/31 17:00:48 | 000,366,152 | —- | M] (Malwarebytes Corporation) [Auto | Running] – D:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2010/06/24 11:34:52 | 000,091,456 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnectService.exe – (MotoConnect Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/08/25 22:20:39 | 000,288,112 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe – (Adobe Version Cue CS4)
SRV - [2009/03/13 17:15:16 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/07/27 10:03:13 | 000,069,632 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/01/20 18:46:08 | 000,428,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\WindowsMobile\wcescomm.dll – (WcesComm)
SRV - [2008/01/20 18:46:08 | 000,211,968 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\WindowsMobile\rapimgr.dll – (RapiMgr)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/11/03 06:44:22 | 000,033,672 | —- | M] (Check Point Software Technologies) [Kernel | Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys – (ISWKL)
DRV:64bit: - [2011/08/31 17:00:50 | 000,025,416 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2011/05/07 17:51:34 | 000,448,088 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\DRIVERS\vsdatant.sys – (Vsdatant)
DRV:64bit: - [2009/08/25 22:05:34 | 000,086,584 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\adfs.sys – (adfs)
DRV:64bit: - [2009/05/09 01:14:20 | 000,015,752 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\NuidFltr.sys – (NuidFltr)
DRV:64bit: - [2009/03/19 15:34:18 | 000,029,544 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/12/19 16:08:28 | 000,033,160 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\point64k.sys – (Point64)
DRV:64bit: - [2008/02/06 02:00:00 | 000,054,480 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2008/01/20 18:46:34 | 000,048,768 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\avc.sys – (Avc)
DRV:64bit: - [2008/01/20 18:46:34 | 000,017,536 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\avcstrm.sys – (AVCSTRM)
DRV:64bit: - [2008/01/20 18:46:08 | 000,056,448 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\mstape.sys – (MSTAPE)
DRV:64bit: - [2008/01/20 18:46:05 | 000,058,496 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\61883.sys – (61883)
DRV:64bit: - [2008/01/20 18:46:01 | 001,523,712 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS – (VST64_DPV)
DRV:64bit: - [2008/01/20 18:46:01 | 000,724,480 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS – (winachsf)
DRV:64bit: - [2008/01/20 18:46:01 | 000,392,704 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTBS26.SYS – (VST64HWBS2)
DRV:64bit: - [2008/01/20 18:46:01 | 000,061,568 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\msdv.sys – (MSDV)
DRV:64bit: - [2008/01/20 18:46:00 | 000,019,456 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\usb8023x.sys – (usb_rndisx)
DRV:64bit: - [2008/01/10 13:46:36 | 000,245,856 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\e1q60x64.sys – (e1qexpress) Intel®
DRV - [2009/08/25 22:05:34 | 000,086,584 | —- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysWow64\drivers\adfs.sys – (adfs)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.washingtonpost.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 74 4D A5 10 7F 60 B8 42 A9 03 DF C4 30 38 A0 3C [binary data]
IE - HKCU\..\URLSearchHook: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:57354
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:0.1.2008d
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.0.0
FF - prefs.js..extensions.enabledItems: [removed]:0.9
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Applications\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Programs\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\J_Rapp\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\J_Rapp\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER [2011/12/14 21:53:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2011/12/14 21:53:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: D:\Programs\components [2011/11/11 12:34:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: D:\Programs\plugins [2011/10/20 08:44:11 | 000,000,000 | —D | M]
[2010/07/15 14:02:42 | 000,000,000 | —D | M] (No name found) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Extensions
[2010/07/15 14:02:42 | 000,000,000 | —D | M] (No name found) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/12/14 21:40:16 | 000,000,000 | —D | M] (No name found) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions
[2011/08/24 21:54:52 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/12/11 11:19:32 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/12/11 13:56:58 | 000,000,000 | —D | M] (XUL Cache) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{7be3443a-4a65-4e89-ad22-b8cf7f1240b4}
[2011/10/27 18:40:18 | 000,000,000 | —D | M] (XUL Cache) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{82be057b-7579-42fd-bbf7-089f2b1d98d0}
[2011/11/11 12:34:45 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/10/03 12:29:15 | 000,000,000 | —D | M] (vShare Plugin) – C:\Users\J_Rapp\AppData\Roaming\Mozilla\Firefox\Profiles\wdvgq1s4.default\extensions\vshare@toolbar
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Timezone Definitions for Mozilla Calendar) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Default Shot Palette) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (MSN-Smileys) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (DOM Inspector) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Blackened) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Depth) – D:\CELTEX\EXTENSIONS\[removed]
[2010/07/15 13:59:48 | 000,000,000 | —D | M] (Minimal) – D:\CELTEX\EXTENSIONS\[removed]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\J_Rapp\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.1.6 (Enabled) = D:\Programs\plugins\npqtplugin5.dll
CHR - plugin: Java™ Platform SE 6 U13 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Java™ Platform SE 6 U13 (Enabled) = D:\Programs\plugins\npdeploytk.dll
CHR - plugin: Adobe Acrobat (Disabled) = D:\Programs\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\J_Rapp\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\J_Rapp\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = D:\Programs\plugins\npLegitCheckPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\J_Rapp\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: iTunes Application Detector (Enabled) = D:\Applications\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\J_Rapp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Users\J_Rapp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Gmail = C:\Users\J_Rapp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
Hosts file not found
O2:64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll ()
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.dll ()
O4:64bit: - HKLM..\Run: [nwiz] C:\Windows\SysNative\nwiz.exe ()
O4:64bit: - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Programs\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] D:\Programs\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [ZoneAlarm] D:\Programs\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [AdobeBridge] D:\Applications\Adobe Bridge CS4\Bridge.exe (Adobe Systems, Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data]
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O12 - Plugin for: .bcf - C:\Program Files (x86)\Internet Explorer\Plugins\NPBelv32.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9E94CFD7-4BF6-485E-A76B-4EB375EB6987}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18 - Protocol\Handler\belarc - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe ()
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\PFW: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\tropeln: DllName - (C:\Windows\system32\config\systemprofile\AppData\Local\tropeln.dll) - C:\Windows\SysWOW64\config\systemprofile\AppData\Local\tropeln.dll ()
O24 - Desktop WallPaper: G:\080629 Yosemite\P1013193.JPG
O24 - Desktop BackupWallPaper: G:\080629 Yosemite\P1013193.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/21 12:00:00 | 000,000,122 | R— | M] () - F:\autorun.inf – [ UDF ]
O33 - MountPoints2\{31343533-0c1c-11de-be1b-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Recycled\ctfmon.exe
O33 - MountPoints2\{31343533-0c1c-11de-be1b-806e6f6e6963}\Shell\Open(&0)\command - "" = F:\Recycled\ctfmon.exe
O33 - MountPoints2\{31343534-0c1c-11de-be1b-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Recycled\ctfmon.exe
O33 - MountPoints2\{3ae57791-07a0-11de-9647-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Recycled\ctfmon.exe
O33 - MountPoints2\{4f87f67c-0a96-11de-8dd2-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Recycled\ctfmon.exe
O33 - MountPoints2\{50c4cd62-1fac-11de-bbcc-003048c60327}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL L:\Recycled\ctfmon.exe
O33 - MountPoints2\{50c4cd62-1fac-11de-bbcc-003048c60327}\Shell\Open(&0)\command - "" = L:\Recycled\ctfmon.exe
O33 - MountPoints2\{6e8450b1-0a83-11de-982c-95d02e640b6d}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL H:\Recycled\ctfmon.exe
O33 - MountPoints2\{98104999-8093-11df-9470-003048c60327}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\Recycled\ctfmon.exe
O33 - MountPoints2\{98104999-8093-11df-9470-003048c60327}\Shell\Open(&0)\command - "" = J:\Recycled\ctfmon.exe
O33 - MountPoints2\{c176ada6-0a93-11de-bb1f-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Recycled\ctfmon.exe
O33 - MountPoints2\{c411b74d-0163-11e0-8cfb-003048c60327}\Shell - "" = AutoRun
O33 - MountPoints2\{c411b74d-0163-11e0-8cfb-003048c60327}\Shell\AutoRun\command - "" = P:\setup.exe -a
O33 - MountPoints2\{d731ab09-b12a-11de-8798-806e6f6e6963}\Shell - "" = AutoRun
LS\x00\x00\x00\x00