This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Applications not working - Am I Infected ? [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

As the title suggests my computer has become very difficult to use

Applications when double clicked fail to launch and error messages display - So am i infected ?? i have to shut down and and restart then they work for a little while then stop working again

please can you help me

I downloaded OTL but it will not run to the end - it starts but then the program stops responding

I have been able to provide the other logs from hijackthis and DDS :)

Many Thanks
ED

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:37:26, on 24/12/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\PrinterShare\paConsole.exe
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
G:\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - (no file)
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Windows; Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [WheelMouse] "C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v3] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" /source=HKLM
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [iKeyWorks] "C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DVDSentry] "C:\WINDOWS\System32\DSentry.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BCMSMMSG] "BCMSMMSG.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [JagexProperties] C:\.jagex_cache_32\jagd.jar
O4 - HKCU\..\Run: [JaGeXDaemon] C:\.jagex_cache_32\jagc.jar
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PrinterShare] C:\Program Files\PrinterShare\paConsole.exe -minimized
O4 - HKCU\..\Run: [Facebook Update] "C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User '?')
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" (User '?')
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [Google Update] "C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (User '?')
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [JagexProperties] C:\.jagex_cache_32\jagd.jar (User '?')
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [JaGeXDaemon] C:\.jagex_cache_32\jagc.jar (User '?')
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User '?')
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [PrinterShare] C:\Program Files\PrinterShare\paConsole.exe -minimized (User '?')
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [Facebook Update] "C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver (User '?')
O4 - HKUS\S-1-5-21-10512063-1881097818-1119676352-1006\..\Run: [LDM] \Program\ (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-10512063-1881097818-1119676352-1006 Startup: .jagex_runescape_preferences.jar (User '?')
O4 - S-1-5-21-10512063-1881097818-1119676352-1006 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User '?')
O4 - S-1-5-21-10512063-1881097818-1119676352-1006 Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User '?')
O4 - Startup: .jagex_runescape_preferences.jar
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Search; - http://tbedits.guffins.com/one-toolbaredit…mp;n=2011121516
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: PDF Download - {F1C0FD6C-A6A0-49a7-A932-71A56461867F} - C:\Program Files\Nitro PDF\PDF Download\NitroPDF.dll (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.orange.co.uk
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/Dcode/ActiveX/MSDcode.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} (SonyOnlineInstallerX) - http://launcher.station.sony.com/weblaunch…ebInstaller.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos-beta/OnlineScanner.cab
O16 - DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} (Wizard101GameLauncher) - https://secure.footprint.net/kingsisle/stat…ameLauncher.CAB
O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} (CInstallLPCtrl Object) - http://u3.sandisk.com/download/apps/LPInstaller.CAB
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: bw+0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: offline-8876480 - {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: pdfFactory Pro Dispatcher v3 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe
O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\DOCUME~1\LEEEDG~1\LOCALS~1\Temp\500064-PMLPatch\HPZipm12.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 30972 bytes

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
.
==== Disk Partitions =========================
.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
.
µTorrent
A4Tech iKeyWorks 7.64
A4Tech iWheelWorks 7.64
ABBYY FineReader 6.0 Sprint
abgx360 v1.0.5
Adobe AIR
Adobe Download Manager 1.2 (Remove Only)
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Adobe Media Player
Adobe Reader X (10.1.1)
Adobe Shockwave Player 11.6
Advanced Archive Password Recovery (remove only)
AmortizeIT! v3.2
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Camera Suite 1.3
avast! Free Antivirus
Avery Wizard 3.1
BookSmart® 3.0.2 3.0.2
Broadcom Management Programs
Camera RAW Plug-In for EPSON Creativity Suite
Camera Support Core Library
Canon Camera Support Core Library
Canon Internet Library for ZoomBrowser EX
CardRecovery 5.20
CDDRV_Installer
Cheat Engine 5.5
Cheat Engine 6.0
CLUE Classic
ConvertXtoDVD 2.2.3.258
ConvertXtoDVD 3.0.0.1
ConvertXtoDVD 4.0.10.324
COVKITS Screensaver
COVKITS[1] Screensaver
Critical Update for Windows Media Player 11 (KB959772)
DAO
Dell Media Experience
Dell Picture Studio - Dell Image Expert
Dell Solution Center
Digital Camera
DVD Decrypter (Remove Only)
DVDSentry
EA SPORTS Gameface Browser Plugin [removed]
EPSON Attach To Email
EPSON Easy Photo Print
EPSON File Manager
EPSON Scan
EPSON Scan Assistant
EPSON Stylus SX200_SX400_TX200_TX400 Manual
EPSON Stylus SX400 Series Printer Uninstall
EPSON Web-To-Page
erLT
ERUNT 1.1j
Eusing Free Registry Cleaner
Facebook Video Calling 1.0.0.8953
FinePix Studio
FinePixViewer Resource
FinePixViewer Ver.5.5
Football Manager 2008
GetDiz 3.0
Google Chrome
Google Earth
Google Update Helper
Halo Tool Box
Help and Support Customization
Highfieldroad Screensaver
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB922120-v6)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HTC BMP USB Driver
Icatch(IV) Camera Driver
ImgBurn
iMoneyManager 1.1.1
Intel® Extreme Graphics Driver
Internet Library
IrfanView (remove only)
iTunes
Java Auto Updater
Java™ 6 Update 29
Junk Mail filter update
KhalInstallWrapper
Logitech Desktop Messenger
Logitech Legacy USB Camera Driver Package
Logitech QuickCam
Logitech QuickCam Driver Package
Logitech SetPoint
Malwarebytes' Anti-Malware version 1.51.2.1300
Mega Manager
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2572067)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Excel Viewer 2003
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2003
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office Word Viewer 2003
Microsoft OpenType Font File Properties Extension
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Windows Media Video 9 VCM
Microsoft Windows XP Video Decoder Checkup Utility
Microsoft Works 7.0
Mobipocket Creator 4.2
modding programs
Modem Helper
Mozilla Firefox 6.0 (x86 en-GB)
MP3 Player Utilities 3.68
MSVC80_x86_v2
MSVC90_x86
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 and SOAP Toolkit 3.0
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
Nero Suite
Nokia Connectivity Cable Driver
Nokia Ovi Suite
Nokia Ovi Suite Software Updater
Office Animation Runtime
Orange Search Toolbar
Ovi Desktop Sync Engine
OviMPlatform
Paint Shop Pro 7
PartyTool 1.24
PC Connectivity Solution
PDF Download for Internet Explorer
pdfFactory Pro
PeerBlock 1.1 (r518)
PokerSidekick
PonyProg v1.17h
PowerDVD
PrinterShare 2.3.06
Protector Eclipse
QuickSFV (Remove only)
QuickTime
RAR Password Recovery v1.1 RC16 (remove only)
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Roxio Easy DVD Copy 2
Sage Invoicing and Start-up
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Groove 2007 (KB2552997)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Microsoft Windows (KB2564958)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2491683)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Segoe UI
SkyBlue70s Screensaver
Skype add-on for IE
Skype Click to Call
Skype™ 5.5
SontheVilla Screensaver
Sony Ericsson Media Manager 1.0
Sony Ericsson PC Suite 1.20.224
SopCast 3.2.9
Space Invaders 1.1.0
Spectaculator 6.25
SpeedTouch USB Software
SpywareGuard v2.2
SSC Service Utility v4.30
SUPERAntiSpyware
swMSM
TEAM MANAGER Lite 6.0
TeamViewer 4
TuneUp Utilities 2007
TweetDeck
U.B. Funkeys
Ulead Photo Express 4.0 SE
Unity Web Player
Unlocker 1.8.5
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Microsoft Windows (KB971513)
Update for Outlook 2007 Junk Email Filter (KB2596560)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2492386)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2607712)
Update for Windows XP (KB2616676-v2)
Update for Windows XP (KB2641690)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
User Profile Hive Cleanup Service
Veetle TV 0.9.18
Viewpoint Media Player
VLC media player 1.1.11
VoiceOver Kit
WebFldrs XP
Windows Backup Utility
Windows Defender Signatures
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows Resource Kit Tools - SubInAcl.exe
Windows XP Service Pack 3
WinISO 5.3
WinRAR archiver
Wizard101(UK)
XB360 Modder v4.0
Yahoo! Software Update
Yahoo! Toolbar
.
==== End Of File ===========================


.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 10:39:42.64 on 24/12/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
mURLSearchHooks: H - No File
BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\phone\ieplugin\SkypeIEPlugin.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Wanadoo: {8b68564d-53fd-4293-b80c-993a9f3988ee} -
TB: {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - No File
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe"
uRun: [Google Update] "c:\documents and settings\lee edgar\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [JagexProperties] c:\.jagex_cache_32\jagd.jar
uRun: [JaGeXDaemon] c:\.jagex_cache_32\jagc.jar
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [PrinterShare] c:\program files\printershare\paConsole.exe -minimized
uRun: [Facebook Update] "c:\documents and settings\lee edgar\local settings\application data\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [LDM] \Program\
mRun: [avast] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [WheelMouse] "c:\progra~1\a4tech\mouse\Amoumain.exe"
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [pdfFactory Pro Dispatcher v3] "c:\windows\system32\spool\drivers\w32x86\3\fppdis3a.exe" /source=HKLM
mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles startup
mRun: [NeroFilterCheck] "c:\windows\system32\NeroCheck.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [Logitech Hardware Abstraction Layer] "KHALMNPR.EXE"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [iKeyWorks] "c:\progra~1\a4tech\keyboard\Ikeymain.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [DVDSentry] "c:\windows\system32\DSentry.exe"
mRun: [BluetoothAuthenticationAgent] "rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [BCMSMMSG] "BCMSMMSG.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\documents and settings\lee edgar\start menu\programs\startup\.jagex_runescape_preferences.jar
StartupFolder: c:\docume~1\leeedg~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\leeedg~1\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\exifla~1.lnk - c:\program files\finepixviewer\QuickDCF2.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: &Search; - http://tbedits.guffins.com/one-toolbaredit…mp;n=2011121516
IE: Download Link Using Mega Manager… - c:\program files\megaupload\mega manager\mm_file.htm
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\phone\ieplugin\SkypeIEPlugin.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
Trusted Zone: securesuite.co.uk\www
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/Dcode/ActiveX/MSDcode.cab
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} - hxxp://pcpitstop.com/internet/pcpConnCheck.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {32505657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} - hxxp://launcher.station.sony.com/weblauncher/plugin/1.0.3.84/SOEWebInstaller.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://secure.footprint.net/kingsisle/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} - hxxp://u3.sandisk.com/download/apps/LPInstaller.CAB
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab
DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxsrvc.dll
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\leeedg~1\applic~1\mozilla\firefox\profiles\ndizvsja.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q;=
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\lee edgar\application data\electronic arts\game face\npGameFacePlugin.dll
FF - plugin: c:\documents and settings\lee edgar\local settings\application data\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\documents and settings\lee edgar\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\documents and settings\lee edgar\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.68\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\guffins\bar\1.bin\NPu4Stub.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\sony online entertainment\npsoe.dll
FF - plugin: c:\program files\sony online entertainment\npsoeact.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
—- FIREFOX POLICIES —-
FF - user.js: keyword.enabled - 1
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2011-12-18 10:23:08 11776 —-a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll
2011-12-18 10:22:33 ——– d—–w- c:\program files\common files\xing shared
2011-12-18 10:22:01 150696 —-a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
2011-12-18 10:21:36 108544 —-a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
2011-12-15 19:52:59 ——– d—–w- c:\documents and settings\lee edgar\.thumbnails
2011-12-15 19:50:04 ——– d—–w- c:\documents and settings\lee edgar\.gimp-2.6
2011-11-26 10:13:56 ——– d—–w- C:\DVR111D
.
==================== Find3M ====================
.
2011-12-18 10:21:17 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-12-18 10:21:17 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-11-28 18:01:25 41184 —-a-w- c:\windows\avastSS.scr
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-20 00:52:58 18553 —-a-w- c:\docume~1\leeedg~1\applic~1\test.exe
2011-11-12 14:23:07 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 19:20:51 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:51 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:51 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23:59 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-03 04:06:03 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 01:37:52 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 10:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2000-01-14 14:46:28 24576 ——w- c:\program files\common files\XCPCMenu.exe
2000-01-14 14:46:26 696320 ——w- c:\program files\common files\XCMHook.dll
.
============= FINISH: 10:44:29.98 ===============
Hi,

Please run the following:

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
Hi Catbyte Merry Christmas to you and your family, Thanks so much for giving up your time to help me especially during the festive period. As i had not heard much on my thread (which i fully understand during this time of year) i have been deleting some old programs off my computer and generally cleaning it up and it actually seems a little better however since you have taken the trouble to help me perhaps you could give my scans a look over as it highlighted 2 infected files Thanks ED And here is your info……………… aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software Run date: 2011-12-27 21:47:07 —————————– 21:47:07.984 OS Version: Windows 5.1.2600 Service Pack 3 21:47:07.984 Number of processors: 1 586 0x209 21:47:07.984 ComputerName: MAINCOMPUTER UserName: Lee Edgar 21:47:10.109 Initialize success 21:47:11.390 AVAST engine defs: 11122702 21:47:51.109 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 21:47:51.109 Disk 0 Vendor: ST380011A 3.16 Size: 76293MB BusType: 3 21:47:51.109 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c 21:47:51.109 Disk 1 Vendor: ST3160022ACE 9.51 Size: 152627MB BusType: 3 21:47:53.140 Disk 0 MBR read successfully 21:47:53.140 Disk 0 MBR scan 21:47:53.140 Disk 0 Windows XP default MBR code 21:47:53.140 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 47 MB offset 63 21:47:53.171 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76238 MB offset 96390 21:47:53.171 Disk 0 scanning sectors +156232125 21:47:53.250 Disk 0 scanning C:\WINDOWS\system32\drivers 21:48:21.593 Service scanning 21:48:23.343 Modules scanning 21:48:53.687 Disk 0 trace - called modules: 21:48:53.734 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 21:48:53.734 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x877d3ab8] 21:48:53.734 3 CLASSPNP.SYS[f78a5fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x877d6b00] 21:48:55.046 AVAST engine scan C:\WINDOWS 21:49:25.687 AVAST engine scan C:\WINDOWS\system32 21:52:57.140 AVAST engine scan C:\WINDOWS\system32\drivers 21:53:22.593 AVAST engine scan C:\Documents and Settings\Lee Edgar 22:07:39.296 File: C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Update\1.3.21.79\GoogleCrashHandler.exe **INFECTED** Win32:Malware-gen 22:11:02.812 File: C:\Documents and Settings\Lee Edgar\Local Settings\temp\{B88E8330-8F31-484E-AF1C-82443E5EFD0B}\GoogleCrashHandler.exe **INFECTED** Win32:Malware-gen 22:49:06.093 AVAST engine scan C:\Documents and Settings\All Users 22:56:24.421 Scan finished successfully 22:57:40.281 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Lee Edgar\Desktop\MBR.dat" 22:57:40.312 The log file has been saved successfully to "C:\Documents and Settings\Lee Edgar\Desktop\aswMBR.txt"

Attachments:

Hi,

Please do the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT



Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Here are the reports

Thanks again……………..


23:26:38.0078 9724 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
23:26:38.0296 9724 ============================================================
23:26:38.0296 9724 Current date / time: 2011/12/27 23:26:38.0296
23:26:38.0296 9724 SystemInfo:
23:26:38.0296 9724
23:26:38.0296 9724 OS Version: 5.1.2600 ServicePack: 3.0
23:26:38.0296 9724 Product type: Workstation
23:26:38.0296 9724 ComputerName: MAINCOMPUTER
23:26:38.0296 9724 UserName: Lee Edgar
23:26:38.0296 9724 Windows directory: C:\WINDOWS
23:26:38.0296 9724 System windows directory: C:\WINDOWS
23:26:38.0296 9724 Processor architecture: Intel x86
23:26:38.0296 9724 Number of processors: 1
23:26:38.0296 9724 Page size: 0x1000
23:26:38.0296 9724 Boot type: Normal boot
23:26:38.0296 9724 ============================================================
23:26:40.0078 9724 Initialize success
23:26:41.0515 8812 ============================================================
23:26:41.0515 8812 Scan started
23:26:41.0515 8812 Mode: Manual;
23:26:41.0515 8812 ============================================================
23:26:42.0671 8812 Aavmker4 (b6de0336f9f4b687b4ff57939f7b657a) C:\WINDOWS\system32\drivers\Aavmker4.sys
23:26:42.0687 8812 Aavmker4 - ok
23:26:42.0765 8812 Abiosdsk - ok
23:26:42.0906 8812 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS
23:26:42.0906 8812 abp480n5 - ok
23:26:43.0093 8812 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
23:26:43.0109 8812 ACPI - ok
23:26:43.0203 8812 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
23:26:43.0203 8812 ACPIEC - ok
23:26:43.0281 8812 Ad-Watch Connect Filter - ok
23:26:43.0343 8812 Ad-Watch Real-Time Scanner - ok
23:26:43.0421 8812 Ad-Watch Registry Filter - ok
23:26:43.0500 8812 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys
23:26:43.0500 8812 adpu160m - ok
23:26:43.0609 8812 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
23:26:43.0609 8812 aeaudio - ok
23:26:43.0796 8812 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
23:26:43.0812 8812 aec - ok
23:26:43.0968 8812 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
23:26:43.0984 8812 AFD - ok
23:26:44.0156 8812 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\System32\DRIVERS\agp440.sys
23:26:44.0156 8812 agp440 - ok
23:26:44.0296 8812 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\System32\DRIVERS\agpCPQ.sys
23:26:44.0296 8812 agpCPQ - ok
23:26:44.0484 8812 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\System32\DRIVERS\aha154x.sys
23:26:44.0921 8812 Aha154x - ok
23:26:45.0062 8812 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys
23:26:45.0062 8812 aic78u2 - ok
23:26:45.0156 8812 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys
23:26:45.0156 8812 aic78xx - ok
23:26:45.0281 8812 alcan5wn (0940030d5a5869067ccc03e3b0b8dec7) C:\WINDOWS\system32\DRIVERS\alcan5wn.sys
23:26:45.0281 8812 alcan5wn - ok
23:26:45.0421 8812 alcaudsl (4c9577888c53243e2991456f510488a1) C:\WINDOWS\system32\DRIVERS\alcaudsl.sys
23:26:45.0421 8812 alcaudsl - ok
23:26:45.0609 8812 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\System32\DRIVERS\aliide.sys
23:26:45.0609 8812 AliIde - ok
23:26:45.0765 8812 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\System32\DRIVERS\alim1541.sys
23:26:45.0765 8812 alim1541 - ok
23:26:45.0921 8812 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\System32\DRIVERS\amdagp.sys
23:26:45.0921 8812 amdagp - ok
23:26:46.0062 8812 Amps2prt (a6215b60b98ba023ec5606a360d502af) C:\WINDOWS\system32\DRIVERS\Amps2prt.sys
23:26:46.0062 8812 Amps2prt - ok
23:26:46.0203 8812 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\System32\DRIVERS\amsint.sys
23:26:46.0203 8812 amsint - ok
23:26:46.0375 8812 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\System32\DRIVERS\asc.sys
23:26:46.0375 8812 asc - ok
23:26:46.0531 8812 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\System32\DRIVERS\asc3350p.sys
23:26:46.0531 8812 asc3350p - ok
23:26:46.0671 8812 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\System32\DRIVERS\asc3550.sys
23:26:46.0671 8812 asc3550 - ok
23:26:46.0859 8812 Aspi32 (b979979ab8027f7f53fb16ec4229b7db) C:\WINDOWS\system32\drivers\Aspi32.sys
23:26:46.0859 8812 Aspi32 - ok
23:26:47.0015 8812 aswFsBlk (054df24c92b55427e0757cfff160e4f2) C:\WINDOWS\system32\drivers\aswFsBlk.sys
23:26:47.0031 8812 aswFsBlk - ok
23:26:47.0218 8812 aswMon2 (ef0e9ad83380724bd6fbbb51d2d0f5b8) C:\WINDOWS\system32\drivers\aswMon2.sys
23:26:47.0234 8812 aswMon2 - ok
23:26:47.0390 8812 aswRdr (352d5a48ebab35a7693b048679304831) C:\WINDOWS\system32\drivers\aswRdr.sys
23:26:47.0390 8812 aswRdr - ok
23:26:47.0562 8812 aswSnx (8d34d2b24297e27d93e847319abfdec4) C:\WINDOWS\system32\drivers\aswSnx.sys
23:26:47.0578 8812 aswSnx - ok
23:26:47.0734 8812 aswSP (010012597333da1f46c3243f33f8409e) C:\WINDOWS\system32\drivers\aswSP.sys
23:26:47.0734 8812 aswSP - ok
23:26:47.0906 8812 aswTdi (f9f84364416658e9786235904d448d37) C:\WINDOWS\system32\drivers\aswTdi.sys
23:26:47.0906 8812 aswTdi - ok
23:26:48.0093 8812 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
23:26:48.0093 8812 AsyncMac - ok
23:26:48.0281 8812 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
23:26:48.0281 8812 atapi - ok
23:26:48.0421 8812 Atdisk - ok
23:26:48.0578 8812 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
23:26:48.0578 8812 Atmarpc - ok
23:26:48.0640 8812 ATWPKT2 - ok
23:26:48.0812 8812 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
23:26:48.0812 8812 audstub - ok
23:26:49.0015 8812 bcm4sbxp (b60f57b4d9cdbc663cc03eb8af7ec34e) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
23:26:49.0015 8812 bcm4sbxp - ok
23:26:49.0218 8812 BCMModem (2b028f4b6812bc236d9dc1b9fea9853a) C:\WINDOWS\system32\DRIVERS\BCMSM.sys
23:26:49.0234 8812 BCMModem - ok
23:26:49.0359 8812 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
23:26:49.0359 8812 Beep - ok
23:26:49.0437 8812 BlueletAudio - ok
23:26:49.0500 8812 BlueletSCOAudio - ok
23:26:49.0578 8812 BT - ok
23:26:49.0640 8812 BTCOMM - ok
23:26:49.0703 8812 Btcsrusb - ok
23:26:49.0796 8812 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
23:26:49.0796 8812 BthEnum - ok
23:26:49.0921 8812 BTHidEnum - ok
23:26:50.0156 8812 BTHidMgr - ok
23:26:50.0406 8812 BTHMODEM (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys
23:26:50.0406 8812 BTHMODEM - ok
23:26:50.0484 8812 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
23:26:50.0484 8812 BthPan - ok
23:26:50.0656 8812 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys
23:26:50.0671 8812 BTHPORT - ok
23:26:50.0828 8812 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
23:26:50.0828 8812 BTHUSB - ok
23:26:50.0968 8812 BTKRNBDG - ok
23:26:51.0046 8812 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\WINDOWS\system32\drivers\BVRPMPR5.SYS
23:26:51.0046 8812 BVRPMPR5 - ok
23:26:51.0187 8812 bvrp_pci - ok
23:26:51.0265 8812 Ca533av - ok
23:26:51.0375 8812 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\DRIVERS\cbidf2k.sys
23:26:51.0375 8812 cbidf - ok
23:26:51.0453 8812 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
23:26:51.0453 8812 cbidf2k - ok
23:26:51.0531 8812 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
23:26:51.0531 8812 CCDECODE - ok
23:26:51.0703 8812 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\System32\DRIVERS\cd20xrnt.sys
23:26:51.0703 8812 cd20xrnt - ok
23:26:51.0875 8812 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
23:26:51.0875 8812 Cdaudio - ok
23:26:51.0984 8812 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
23:26:51.0984 8812 Cdfs - ok
23:26:52.0187 8812 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
23:26:52.0187 8812 Cdrom - ok
23:26:52.0312 8812 Changer - ok
23:26:52.0468 8812 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\System32\DRIVERS\cmdide.sys
23:26:52.0468 8812 CmdIde - ok
23:26:52.0656 8812 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\System32\DRIVERS\cpqarray.sys
23:26:52.0671 8812 Cpqarray - ok
23:26:52.0796 8812 CSRBC01 - ok
23:26:52.0921 8812 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\System32\DRIVERS\dac2w2k.sys
23:26:52.0921 8812 dac2w2k - ok
23:26:53.0093 8812 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\System32\DRIVERS\dac960nt.sys
23:26:53.0093 8812 dac960nt - ok
23:26:53.0250 8812 DCamUSBSQTECH (100ff3d9e16afb3163bd6f9aaaab7c55) C:\WINDOWS\system32\Drivers\SQcaptur.sys
23:26:53.0250 8812 DCamUSBSQTECH - ok
23:26:53.0421 8812 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
23:26:53.0437 8812 Disk - ok
23:26:53.0609 8812 DLPortIO (1d95d36db805787d54eb50e45ed4af40) C:\WINDOWS\system32\DRIVERS\DLPortIO.SYS
23:26:53.0609 8812 DLPortIO - ok
23:26:53.0796 8812 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
23:26:53.0796 8812 dmboot - ok
23:26:53.0968 8812 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
23:26:53.0984 8812 dmio - ok
23:26:54.0125 8812 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
23:26:54.0125 8812 dmload - ok
23:26:54.0234 8812 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
23:26:54.0234 8812 DMusic - ok
23:26:54.0406 8812 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys
23:26:54.0421 8812 dpti2o - ok
23:26:54.0515 8812 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
23:26:54.0531 8812 drmkaud - ok
23:26:54.0718 8812 dtsoftbus01 (fb38473835476a6fb272215a1d972af9) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
23:26:54.0718 8812 dtsoftbus01 - ok
23:26:54.0875 8812 dvd43llh (1fc1eed3ea0c3a0ecf8a95b97e1b4831) C:\WINDOWS\system32\DRIVERS\dvd43llh.sys
23:26:54.0875 8812 dvd43llh - ok
23:26:55.0046 8812 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
23:26:55.0046 8812 EL90XBC - ok
23:26:55.0250 8812 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
23:26:55.0250 8812 Fastfat - ok
23:26:55.0421 8812 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
23:26:55.0421 8812 Fdc - ok
23:26:55.0531 8812 FilterService (1edc0df2da14e04504dd3bac21aa32cd) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
23:26:55.0531 8812 FilterService - ok
23:26:55.0687 8812 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
23:26:55.0687 8812 Fips - ok
23:26:55.0843 8812 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
23:26:55.0843 8812 Flpydisk - ok
23:26:56.0000 8812 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
23:26:56.0000 8812 FltMgr - ok
23:26:56.0171 8812 fssfltr (e0087225b137e57239ff40f8ae82059b) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
23:26:56.0171 8812 fssfltr - ok
23:26:56.0359 8812 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:26:56.0359 8812 Fs_Rec - ok
23:26:56.0468 8812 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
23:26:56.0468 8812 Ftdisk - ok
23:26:56.0625 8812 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
23:26:56.0625 8812 GEARAspiWDM - ok
23:26:56.0781 8812 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
23:26:56.0796 8812 Gpc - ok
23:26:56.0984 8812 HidBth (7bd2de4c85eb4241eed57672b16a7d8d) C:\WINDOWS\system32\DRIVERS\hidbth.sys
23:26:56.0984 8812 HidBth - ok
23:26:57.0171 8812 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
23:26:57.0171 8812 HidUsb - ok
23:26:57.0312 8812 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\System32\DRIVERS\hpn.sys
23:26:57.0328 8812 hpn - ok
23:26:57.0468 8812 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
23:26:57.0468 8812 HPZid412 - ok
23:26:57.0562 8812 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
23:26:57.0562 8812 HPZipr12 - ok
23:26:57.0718 8812 HPZius12 (ca990306ed4ef732af9695bff24fc96f) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
23:26:57.0718 8812 HPZius12 - ok
23:26:57.0859 8812 HTCAND32 - ok
23:26:57.0984 8812 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
23:26:58.0000 8812 HTTP - ok
23:26:58.0250 8812 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
23:26:58.0312 8812 i2omgmt - ok
23:26:58.0531 8812 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\System32\DRIVERS\i2omp.sys
23:26:58.0531 8812 i2omp - ok
23:26:59.0078 8812 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
23:26:59.0078 8812 i8042prt - ok
23:26:59.0484 8812 i81x (06b7ef73ba5f302eecc294cdf7e19702) C:\WINDOWS\system32\DRIVERS\i81xnt5.sys
23:26:59.0562 8812 i81x - ok
23:26:59.0875 8812 iAimFP0 (7b5b44efe5eb9dadfb8ee29700885d23) C:\WINDOWS\system32\DRIVERS\wADV01nt.sys
23:27:00.0359 8812 iAimFP0 - ok
23:27:01.0812 8812 iAimFP1 (eb1f6bab6c22ede0ba551b527475f7e9) C:\WINDOWS\system32\DRIVERS\wADV02NT.sys
23:27:01.0812 8812 iAimFP1 - ok
23:27:02.0312 8812 iAimFP2 (03ce989d846c1aa81145cb22fcb86d06) C:\WINDOWS\system32\DRIVERS\wADV05NT.sys
23:27:02.0312 8812 iAimFP2 - ok
23:27:02.0593 8812 iAimFP3 (525849b4469de021d5d61b4db9be3a9d) C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys
23:27:02.0625 8812 iAimFP3 - ok
23:27:02.0828 8812 iAimFP4 (589c2bcdb5bd602bf7b63d210407ef8c) C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys
23:27:02.0859 8812 iAimFP4 - ok
23:27:03.0187 8812 iAimTV0 (d83bdd5c059667a2f647a6be5703a4d2) C:\WINDOWS\system32\DRIVERS\wATV01nt.sys
23:27:03.0187 8812 iAimTV0 - ok
23:27:03.0390 8812 iAimTV1 (ed968d23354daa0d7c621580c012a1f6) C:\WINDOWS\system32\DRIVERS\wATV02NT.sys
23:27:03.0421 8812 iAimTV1 - ok
23:27:03.0687 8812 iAimTV3 (d738273f218a224c1ddac04203f27a84) C:\WINDOWS\system32\DRIVERS\wATV04nt.sys
23:27:03.0687 8812 iAimTV3 - ok
23:27:03.0875 8812 iAimTV4 (0052d118995cbab152daabe6106d1442) C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys
23:27:03.0875 8812 iAimTV4 - ok
23:27:04.0031 8812 ialm (44b7d5a4f2bd9fe21aea0bb0bace38c4) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
23:27:04.0062 8812 ialm - ok
23:27:04.0218 8812 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
23:27:04.0234 8812 Imapi - ok
23:27:04.0406 8812 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\System32\DRIVERS\ini910u.sys
23:27:04.0406 8812 ini910u - ok
23:27:04.0593 8812 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys
23:27:04.0593 8812 IntelIde - ok
23:27:04.0703 8812 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
23:27:04.0703 8812 intelppm - ok
23:27:04.0859 8812 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
23:27:04.0875 8812 ip6fw - ok
23:27:05.0093 8812 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:27:05.0093 8812 IpFilterDriver - ok
23:27:05.0296 8812 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
23:27:05.0312 8812 IpInIp - ok
23:27:05.0421 8812 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
23:27:05.0421 8812 IpNat - ok
23:27:05.0593 8812 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
23:27:05.0593 8812 IPSec - ok
23:27:05.0750 8812 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
23:27:05.0765 8812 IRENUM - ok
23:27:05.0875 8812 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
23:27:05.0875 8812 isapnp - ok
23:27:06.0031 8812 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
23:27:06.0031 8812 Kbdclass - ok
23:27:06.0265 8812 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
23:27:06.0296 8812 kbdhid - ok
23:27:06.0421 8812 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
23:27:06.0421 8812 kmixer - ok
23:27:06.0562 8812 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
23:27:06.0640 8812 KSecDD - ok
23:27:06.0859 8812 L8042Kbd (0c6e346cde730cf1356dd69ad6e9bc42) C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
23:27:06.0921 8812 L8042Kbd - ok
23:27:07.0078 8812 L8042mou (8a5993705add14352c9a279fa8338334) C:\WINDOWS\system32\DRIVERS\L8042mou.Sys
23:27:07.0265 8812 L8042mou - ok
23:27:07.0406 8812 lbrtfdc - ok
23:27:07.0546 8812 LHidFilt (7f9c7b28cf1c859e1c42619eea946dc8) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
23:27:07.0546 8812 LHidFilt - ok
23:27:07.0765 8812 LHidKe (31b582394da3290dff300f10952e9a4d) C:\WINDOWS\system32\DRIVERS\LHidKE.Sys
23:27:07.0828 8812 LHidKe - ok
23:27:07.0968 8812 LHidUsbK (cbd1c6bff70e170cec6e1502e7fcfef6) C:\WINDOWS\system32\Drivers\LHidUsbK.Sys
23:27:08.0046 8812 LHidUsbK - ok
23:27:08.0265 8812 LMouFilt (ab33792a87285344f43b5ce23421bab0) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
23:27:08.0265 8812 LMouFilt - ok
23:27:08.0828 8812 LMouKE (9837e55673818ecd8febb47f7f77521a) C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
23:27:08.0843 8812 LMouKE - ok
23:27:09.0187 8812 LUsbFilt (77030525cd86a93f1af34fa9b96d33ce) C:\WINDOWS\system32\Drivers\LUsbFilt.Sys
23:27:09.0218 8812 LUsbFilt - ok
23:27:09.0828 8812 LVPr2Mon (f96cfb47903854f228baaf3e2d41a0a3) C:\WINDOWS\system32\Drivers\LVPr2Mon.sys
23:27:09.0828 8812 LVPr2Mon - ok
23:27:10.0046 8812 LVRS (e22fd7852e74f04cceb6b8a684a51f3e) C:\WINDOWS\system32\DRIVERS\lvrs.sys
23:27:10.0046 8812 LVRS - ok
23:27:10.0140 8812 LVUSBSta (5f987fc1aad215ec2c60cf07719b1cce) C:\WINDOWS\system32\drivers\LVUSBSta.sys
23:27:10.0156 8812 LVUSBSta - ok
23:27:10.0578 8812 LVUVC (e89df2b88ee659954de79827ddf46dc9) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
23:27:10.0625 8812 LVUVC - ok
23:27:10.0718 8812 Machnm32 (fd65bef5ff8275711d9a56f0b8bb43f1) C:\WINDOWS\system32\Machnm32.sys
23:27:10.0718 8812 Machnm32 - ok
23:27:10.0906 8812 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
23:27:10.0921 8812 mnmdd - ok
23:27:11.0015 8812 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
23:27:11.0015 8812 Modem - ok
23:27:11.0203 8812 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
23:27:11.0203 8812 MODEMCSA - ok
23:27:11.0328 8812 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
23:27:11.0328 8812 Mouclass - ok
23:27:11.0484 8812 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
23:27:11.0500 8812 mouhid - ok
23:27:11.0671 8812 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
23:27:11.0671 8812 MountMgr - ok
23:27:11.0859 8812 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\System32\DRIVERS\mraid35x.sys
23:27:11.0875 8812 mraid35x - ok
23:27:12.0046 8812 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
23:27:12.0062 8812 MRxDAV - ok
23:27:12.0265 8812 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:27:12.0265 8812 MRxSmb - ok
23:27:12.0421 8812 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
23:27:12.0421 8812 Msfs - ok
23:27:12.0515 8812 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
23:27:12.0515 8812 MSKSSRV - ok
23:27:12.0671 8812 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
23:27:12.0671 8812 MSPCLOCK - ok
23:27:12.0828 8812 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
23:27:12.0828 8812 MSPQM - ok
23:27:12.0984 8812 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
23:27:12.0984 8812 mssmbios - ok
23:27:13.0140 8812 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
23:27:13.0140 8812 MSTEE - ok
23:27:13.0203 8812 MTK - ok
23:27:13.0328 8812 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
23:27:13.0343 8812 Mup - ok
23:27:13.0812 8812 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
23:27:14.0531 8812 NABTSFEC - ok
23:27:14.0734 8812 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
23:27:14.0750 8812 NDIS - ok
23:27:14.0890 8812 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
23:27:14.0890 8812 NdisIP - ok
23:27:14.0968 8812 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:27:14.0968 8812 NdisTapi - ok
23:27:15.0125 8812 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
23:27:15.0125 8812 Ndisuio - ok
23:27:15.0218 8812 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:27:15.0218 8812 NdisWan - ok
23:27:15.0375 8812 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
23:27:15.0390 8812 NDProxy - ok
23:27:15.0546 8812 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
23:27:15.0546 8812 NetBIOS - ok
23:27:15.0703 8812 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
23:27:15.0703 8812 NetBT - ok
23:27:15.0828 8812 nmwcd (28e36e677849174c910faaead3e60e9e) C:\WINDOWS\system32\drivers\ccdcmb.sys
23:27:15.0828 8812 nmwcd - ok
23:27:16.0000 8812 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
23:27:16.0015 8812 Npfs - ok
23:27:16.0125 8812 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
23:27:16.0140 8812 Ntfs - ok
23:27:16.0328 8812 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
23:27:16.0328 8812 Null - ok
23:27:16.0796 8812 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
23:27:16.0812 8812 nv - ok
23:27:17.0093 8812 NvNdis - ok
23:27:17.0140 8812 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
23:27:17.0140 8812 NwlnkFlt - ok
23:27:17.0218 8812 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
23:27:17.0218 8812 NwlnkFwd - ok
23:27:17.0328 8812 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys
23:27:17.0328 8812 omci - ok
23:27:17.0515 8812 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys
23:27:17.0531 8812 P3 - ok
23:27:17.0687 8812 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
23:27:17.0687 8812 Parport - ok
23:27:17.0781 8812 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
23:27:17.0781 8812 PartMgr - ok
23:27:17.0968 8812 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
23:27:17.0968 8812 ParVdm - ok
23:27:18.0062 8812 pbfilter (61a5701e3f543861b21bbe0932c4cc03) C:\Program Files\PeerBlock\pbfilter.sys
23:27:18.0062 8812 pbfilter - ok
23:27:18.0187 8812 PCANDIS5 (2f9806b52cb3748b1e49222744b28e3c) C:\WINDOWS\system32\PCANDIS5.SYS
23:27:18.0203 8812 PCANDIS5 - ok
23:27:18.0343 8812 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
23:27:18.0343 8812 pccsmcfd - ok
23:27:18.0437 8812 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
23:27:18.0437 8812 PCI - ok
23:27:18.0562 8812 PCIDump - ok
23:27:18.0703 8812 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
23:27:18.0703 8812 PCIIde - ok
23:27:18.0859 8812 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
23:27:18.0859 8812 Pcmcia - ok
23:27:19.0015 8812 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
23:27:19.0015 8812 pcouffin - ok
23:27:19.0140 8812 PDCOMP - ok
23:27:19.0296 8812 PDFRAME - ok
23:27:19.0375 8812 PDRELI - ok
23:27:19.0468 8812 PDRFRAME - ok
23:27:19.0531 8812 pepifilter - ok
23:27:19.0609 8812 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\System32\DRIVERS\perc2.sys
23:27:19.0609 8812 perc2 - ok
23:27:19.0703 8812 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\System32\DRIVERS\perc2hib.sys
23:27:19.0703 8812 perc2hib - ok
23:27:19.0796 8812 pfc - ok
23:27:19.0859 8812 PID_PEPI - ok
23:27:20.0046 8812 PORTIO64 - ok
23:27:20.0125 8812 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
23:27:20.0125 8812 PptpMiniport - ok
23:27:20.0281 8812 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
23:27:20.0281 8812 Processor - ok
23:27:20.0406 8812 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
23:27:20.0421 8812 PSched - ok
23:27:20.0546 8812 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
23:27:20.0562 8812 Ptilink - ok
23:27:20.0656 8812 PxHelp20 (0457e25bb122b854e267cf552dcdc370) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
23:27:20.0656 8812 PxHelp20 - ok
23:27:20.0828 8812 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\System32\DRIVERS\ql1080.sys
23:27:20.0828 8812 ql1080 - ok
23:27:21.0015 8812 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\System32\DRIVERS\ql10wnt.sys
23:27:21.0015 8812 Ql10wnt - ok
23:27:21.0093 8812 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\System32\DRIVERS\ql12160.sys
23:27:21.0093 8812 ql12160 - ok
23:27:21.0187 8812 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\System32\DRIVERS\ql1240.sys
23:27:21.0187 8812 ql1240 - ok
23:27:21.0281 8812 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\System32\DRIVERS\ql1280.sys
23:27:21.0296 8812 ql1280 - ok
23:27:21.0421 8812 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:27:21.0421 8812 RasAcd - ok
23:27:21.0531 8812 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
23:27:21.0531 8812 Rasl2tp - ok
23:27:21.0703 8812 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:27:21.0703 8812 RasPppoe - ok
23:27:21.0875 8812 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
23:27:21.0875 8812 Raspti - ok
23:27:22.0031 8812 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:27:22.0046 8812 Rdbss - ok
23:27:22.0218 8812 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
23:27:22.0218 8812 RDPCDD - ok
23:27:22.0328 8812 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
23:27:22.0328 8812 rdpdr - ok
23:27:22.0484 8812 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
23:27:22.0500 8812 RDPWD - ok
23:27:22.0640 8812 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
23:27:22.0656 8812 redbook - ok
23:27:22.0812 8812 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
23:27:22.0812 8812 RFCOMM - ok
23:27:22.0953 8812 RimUsb (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys
23:27:22.0968 8812 RimUsb - ok
23:27:23.0078 8812 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
23:27:23.0078 8812 ROOTMODEM - ok
23:27:23.0171 8812 rspndr (743d7d59767073a617b1dcc6c546f234) C:\WINDOWS\system32\DRIVERS\rspndr.sys
23:27:23.0187 8812 rspndr - ok
23:27:23.0359 8812 s117bus (1f561844318914e7eb6e54673a4cc54c) C:\WINDOWS\system32\DRIVERS\s117bus.sys
23:27:23.0359 8812 s117bus - ok
23:27:23.0453 8812 s117mdfl (ba93eec3cdf6a63b77ae66221aa4f902) C:\WINDOWS\system32\DRIVERS\s117mdfl.sys
23:27:23.0468 8812 s117mdfl - ok
23:27:23.0625 8812 s117mdm (cba12fd8a8ee5b5cdfbbae2381cd6703) C:\WINDOWS\system32\DRIVERS\s117mdm.sys
23:27:23.0625 8812 s117mdm - ok
23:27:23.0781 8812 s117mgmt (bd6483e64b1da17e812b34bcdefd9459) C:\WINDOWS\system32\DRIVERS\s117mgmt.sys
23:27:23.0796 8812 s117mgmt - ok
23:27:23.0937 8812 s117nd5 (c7ca36c3054b4cd47a1f6611b046e2f9) C:\WINDOWS\system32\DRIVERS\s117nd5.sys
23:27:23.0953 8812 s117nd5 - ok
23:27:24.0046 8812 s117obex (e290b3a6b58fb72ca97dd48d64e4fc1c) C:\WINDOWS\system32\DRIVERS\s117obex.sys
23:27:24.0046 8812 s117obex - ok
23:27:24.0203 8812 s117unic (5c4d1ba23c7511ac880e8ba7baa80dba) C:\WINDOWS\system32\DRIVERS\s117unic.sys
23:27:24.0218 8812 s117unic - ok
23:27:24.0328 8812 SABProcEnum - ok
23:27:24.0406 8812 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
23:27:24.0406 8812 SASDIFSV - ok
23:27:24.0562 8812 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
23:27:24.0562 8812 SASKUTIL - ok
23:27:24.0734 8812 SE27bus (59a9eb4073a39895af314780d0a032fa) C:\WINDOWS\system32\DRIVERS\SE27bus.sys
23:27:24.0734 8812 SE27bus - ok
23:27:24.0890 8812 SE27mdfl (d53e7e53107d1796825540129f8fe89f) C:\WINDOWS\system32\DRIVERS\SE27mdfl.sys
23:27:24.0890 8812 SE27mdfl - ok
23:27:24.0984 8812 SE27mdm (2afa2f65a6e91da5b5070e734769827e) C:\WINDOWS\system32\DRIVERS\SE27mdm.sys
23:27:24.0984 8812 SE27mdm - ok
23:27:25.0156 8812 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
23:27:25.0171 8812 Secdrv - ok
23:27:25.0390 8812 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
23:27:25.0406 8812 serenum - ok
23:27:25.0562 8812 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
23:27:25.0562 8812 Serial - ok
23:27:25.0796 8812 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
23:27:25.0796 8812 Sfloppy - ok
23:27:25.0875 8812 Simbad - ok
23:27:26.0000 8812 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\System32\DRIVERS\sisagp.sys
23:27:26.0000 8812 sisagp - ok
23:27:26.0171 8812 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
23:27:26.0171 8812 SLIP - ok
23:27:26.0328 8812 smwdm (31fd0707c7dbe715234f2823b27214fe) C:\WINDOWS\system32\drivers\smwdm.sys
23:27:26.0343 8812 smwdm - ok
23:27:26.0515 8812 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\System32\DRIVERS\sparrow.sys
23:27:26.0515 8812 Sparrow - ok
23:27:26.0625 8812 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
23:27:26.0625 8812 splitter - ok
23:27:26.0796 8812 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
23:27:26.0796 8812 sr - ok
23:27:26.0937 8812 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
23:27:26.0953 8812 Srv - ok
23:27:27.0125 8812 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
23:27:27.0125 8812 streamip - ok
23:27:27.0312 8812 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
23:27:27.0312 8812 swenum - ok
23:27:27.0437 8812 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
23:27:27.0437 8812 swmidi - ok
23:27:27.0609 8812 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys
23:27:27.0625 8812 symc810 - ok
23:27:27.0781 8812 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys
23:27:27.0781 8812 symc8xx - ok
23:27:27.0906 8812 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys
23:27:27.0906 8812 sym_hi - ok
23:27:28.0046 8812 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys
23:27:28.0046 8812 sym_u3 - ok
23:27:28.0156 8812 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
23:27:28.0156 8812 sysaudio - ok
23:27:28.0359 8812 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
23:27:28.0359 8812 Tcpip - ok
23:27:28.0531 8812 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
23:27:28.0531 8812 TDPIPE - ok
23:27:28.0656 8812 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
23:27:28.0671 8812 TDTCP - ok
23:27:28.0750 8812 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
23:27:28.0765 8812 TermDD - ok
23:27:28.0953 8812 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\System32\DRIVERS\toside.sys
23:27:28.0968 8812 TosIde - ok
23:27:29.0109 8812 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
23:27:29.0125 8812 Udfs - ok
23:27:29.0328 8812 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\System32\DRIVERS\ultra.sys
23:27:29.0328 8812 ultra - ok
23:27:29.0406 8812 UnlockerDriver5 (b2af2ba8a3205a8458b61f638fb431dd) C:\Program Files\Unlocker\UnlockerDriver5.sys
23:27:29.0406 8812 UnlockerDriver5 - ok
23:27:29.0562 8812 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
23:27:29.0578 8812 Update - ok
23:27:29.0765 8812 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
23:27:29.0765 8812 USBAAPL - ok
23:27:29.0921 8812 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
23:27:29.0921 8812 usbaudio - ok
23:27:30.0125 8812 USBCamera - ok
23:27:30.0343 8812 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
23:27:30.0359 8812 usbccgp - ok
23:27:30.0656 8812 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
23:27:30.0656 8812 usbehci - ok
23:27:30.0812 8812 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
23:27:30.0812 8812 usbhub - ok
23:27:30.0953 8812 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
23:27:30.0953 8812 usbprint - ok
23:27:31.0140 8812 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:27:31.0140 8812 usbscan - ok
23:27:31.0234 8812 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
23:27:31.0250 8812 USBSTOR - ok
23:27:31.0437 8812 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
23:27:31.0437 8812 usbuhci - ok
23:27:31.0593 8812 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
23:27:31.0593 8812 usbvideo - ok
23:27:31.0687 8812 vad_multi - ok
23:27:31.0781 8812 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
23:27:31.0796 8812 vaxscsi - ok
23:27:31.0921 8812 VComm - ok
23:27:32.0062 8812 VcommMgr - ok
23:27:32.0187 8812 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
23:27:32.0187 8812 VgaSave - ok
23:27:32.0375 8812 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\System32\DRIVERS\viaagp.sys
23:27:32.0390 8812 viaagp - ok
23:27:32.0562 8812 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys
23:27:32.0578 8812 ViaIde - ok
23:27:32.0687 8812 viamraid - ok
23:27:32.0859 8812 viapdsk (f314359357b6960eb727620470ffc9cf) C:\WINDOWS\system32\DRIVERS\viapdsk.sys
23:27:32.0859 8812 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\viapdsk.sys. Real md5: f314359357b6960eb727620470ffc9cf, Fake md5: 8a46a4bc77a3f321996ff4079f834054
23:27:32.0859 8812 viapdsk ( ForgedFile.Multi.Generic ) - warning
23:27:32.0859 8812 viapdsk - detected ForgedFile.Multi.Generic (1)
23:27:33.0015 8812 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
23:27:33.0015 8812 VolSnap - ok
23:27:33.0140 8812 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:27:33.0140 8812 Wanarp - ok
23:27:33.0265 8812 wanatw - ok
23:27:33.0375 8812 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
23:27:33.0375 8812 Wdf01000 - ok
23:27:33.0515 8812 WDICA - ok
23:27:33.0609 8812 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
23:27:33.0625 8812 wdmaud - ok
23:27:33.0796 8812 WinDriver6 (94e4312d546048bf31604a8b2ad13fc0) C:\WINDOWS\system32\drivers\windrvr6.sys
23:27:33.0812 8812 WinDriver6 - ok
23:27:34.0093 8812 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
23:27:34.0093 8812 WpdUsb - ok
23:27:34.0265 8812 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
23:27:34.0281 8812 WS2IFSL - ok
23:27:34.0390 8812 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
23:27:34.0406 8812 WSTCODEC - ok
23:27:34.0562 8812 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
23:27:34.0562 8812 WudfPf - ok
23:27:34.0781 8812 {6080A529-897E-4629-A488-ABA0C29B635E} (61002db7b6efb5711685b9d79b8e8ce6) C:\WINDOWS\system32\drivers\ialmsbw.sys
23:27:34.0781 8812 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
23:27:34.0953 8812 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (35ce2baa708ea038ab72359de87bab87) C:\WINDOWS\system32\drivers\ialmkchw.sys
23:27:34.0953 8812 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
23:27:35.0000 8812 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
23:27:35.0171 8812 \Device\Harddisk0\DR0 - ok
23:27:35.0203 8812 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
23:27:35.0671 8812 \Device\Harddisk1\DR1 - ok
23:27:35.0703 8812 Boot (0x1200) (a7cdfd43ba1c913a2bdf2ea18680f4d8) \Device\Harddisk0\DR0\Partition0
23:27:35.0703 8812 \Device\Harddisk0\DR0\Partition0 - ok
23:27:35.0734 8812 Boot (0x1200) (95e6f1233b25629be68ef4056d5f0abe) \Device\Harddisk1\DR1\Partition0
23:27:35.0734 8812 \Device\Harddisk1\DR1\Partition0 - ok
23:27:35.0734 8812 ============================================================
23:27:35.0734 8812 Scan finished
23:27:35.0734 8812 ============================================================
23:27:35.0765 10272 Detected object count: 1
23:27:35.0765 10272 Actual detected object count: 1
23:27:45.0171 10272 HKLM\SYSTEM\ControlSet004\services\viapdsk - will be deleted on reboot
23:27:45.0171 10272 HKLM\SYSTEM\ControlSet005\services\viapdsk - will be deleted on reboot
23:27:45.0203 10272 C:\WINDOWS\system32\DRIVERS\viapdsk.sys - will be deleted on reboot
23:27:45.0203 10272 viapdsk ( ForgedFile.Multi.Generic ) - User select action: Delete
23:27:54.0218 8720 Deinitialize success



ComboFix 11-12-27.01 - Lee Edgar 27/12/2011 23:46:03.6.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Lee Edgar\Application Data\Config
c:\documents and settings\Lee Edgar\Application Data\Lee Edgar3SQLite3.dll
c:\documents and settings\Lee Edgar\Application Data\new43.exe
c:\documents and settings\Lee Edgar\Application Data\test.exe
c:\documents and settings\Lee Edgar\Application Data\vso_ts_preview.xml
C:\Setup.exe
C:\Thumbs.db
c:\windows\bwUnin-7.2.0.137-8876480SL.exe
c:\windows\dwbreader.exe
c:\windows\iun6002.exe
c:\windows\SET1E.tmp
c:\windows\SSFM1032.DLL
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\XSxS
.
.
((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-28 )))))))))))))))))))))))))))))))
.
.
2011-12-27 17:14 . 2011-12-27 17:14 239168 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-12-27 17:14 . 2011-12-27 17:14 ——– d—–w- c:\program files\DAEMON Tools Lite
2011-12-27 17:13 . 2011-12-27 17:17 ——– d—–w- c:\documents and settings\Lee Edgar\Application Data\DAEMON Tools Lite
2011-12-27 17:13 . 2011-12-27 17:13 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2011-12-27 16:09 . 2011-12-27 16:09 ——– d—–w- c:\program files\Conduit
2011-12-27 16:09 . 2011-12-27 16:13 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Conduit
2011-12-27 16:07 . 2011-12-27 16:07 ——– d—–w- c:\program files\uTorrent
2011-12-27 16:06 . 2011-12-27 16:06 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\uTorrent
2011-12-27 11:20 . 2011-12-27 11:20 ——– d—–w- c:\documents and settings\Lee Edgar\Application Data\Yahoo!
2011-12-27 09:57 . 2011-12-27 09:57 ——– d—–w- c:\program files\VS Revo Group
2011-12-18 10:23 . 2011-12-18 10:23 11776 —-a-w- c:\program files\Mozilla Firefox\plugins\nprjplug.dll
2011-12-18 10:22 . 2011-12-18 10:22 ——– d—–w- c:\program files\Common Files\xing shared
2011-12-18 10:22 . 2011-12-18 10:22 150696 —-a-w- c:\program files\Mozilla Firefox\plugins\nppl3260.dll
2011-12-18 10:21 . 2011-12-18 10:21 108544 —-a-w- c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
2011-12-15 19:53 . 2011-12-15 19:53 ——– d—–w- c:\documents and settings\Lee Edgar\Application Data\gtk-2.0
2011-12-15 19:52 . 2011-12-15 19:52 ——– d—–w- c:\documents and settings\Lee Edgar\.thumbnails
2011-12-15 19:50 . 2011-12-16 19:37 ——– d—–w- c:\documents and settings\Lee Edgar\.gimp-2.6
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 10:21 . 2003-03-18 20:14 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-12-18 10:21 . 2003-02-21 04:42 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-11-28 18:01 . 2010-08-28 16:22 41184 —-a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2009-09-10 18:38 199816 —-a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-03-15 20:30 435032 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2009-09-10 18:39 314456 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2009-09-10 18:39 34392 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2009-09-10 18:39 52952 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2009-09-10 18:39 111320 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2009-09-10 18:39 105176 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2009-09-10 18:39 20568 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2009-09-10 18:39 30808 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-23 13:25 . 2002-08-29 05:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-12 14:23 . 2011-08-11 06:19 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 19:20 . 2004-08-23 19:32 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2002-08-29 05:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2002-08-29 05:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-05-05 20:06 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2002-08-29 05:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2009-04-16 06:22 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2009-04-16 06:22 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2002-08-29 05:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2004-06-07 13:19 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-03 04:06 . 2010-05-15 07:57 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 01:37 . 2011-02-24 19:14 73728 —-a-w- c:\windows\system32\javacpl.cpl
2000-01-14 14:46 . 2006-09-07 20:58 24576 ——w- c:\program files\Common Files\XCPCMenu.exe
2000-01-14 14:46 . 2006-09-07 20:58 696320 ——w- c:\program files\Common Files\XCMHook.dll
2011-09-21 21:37 . 2011-04-18 14:33 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="\Program\" [X]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-12-18 4616064]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-14 1957888]
"JagexProperties"="c:\.jagex_cache_32\jagd.jar" [2011-07-10 29816]
"JaGeXDaemon"="c:\.jagex_cache_32\jagc.jar" [2011-12-28 35298]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"PrinterShare"="c:\program files\PrinterShare\paConsole.exe" [2011-09-08 1124352]
"Facebook Update"="c:\documents and settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2011-10-20 137536]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-11-28 3744552]
"WheelMouse"="c:\progra~1\A4Tech\Mouse\Amoumain.exe" [2004-09-01 147456]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2010-03-18 614400]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"iKeyWorks"="c:\progra~1\A4Tech\Keyboard\Ikeymain.exe" [2004-08-31 61440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-12-18 296056]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\Lee Edgar\Start Menu\Programs\Startup\
.jagex_runescape_preferences.jar [2011-12-28 35298]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2010-8-4 303104]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-6-11 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-6-11 813584]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-11 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 12:28 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe"
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Orange\\Livebox\\RGWREPAIR.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\PrinterShare\\paConsole.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Lee Edgar\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16193:TCP"= 16193:TCP:BitComet 16193 TCP
"16193:UDP"= 16193:UDP:BitComet 16193 UDP
"55064:TCP"= 55064:TCP:bitcomet 55064 tcp
"55064:UDP"= 55064:UDP:bitcomet 55064 udp
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\Drivers\Ca533av.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 136176]
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\DRIVERS\Amps2prt.sys [2004-08-25 9984]
R3 BTCOMM;BTCOMM;c:\windows\system32\drivers\Btcomm.sys [x]
R3 BTKRNBDG;Bluetooth COM Bridge;c:\windows\system32\DRIVERS\btkrnbdg.sys [x]
R3 CSRBC01;%CSRBC01.SvcDesc%;c:\windows\system32\Drivers\csrbc01.sys [x]
R3 DLPortIO;DriverLINX Port I/O Driver;c:\windows\system32\DRIVERS\DLPortIO.SYS [2000-06-29 3584]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 136176]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 MTK;Media Technology Kernel Driver;c:\windows\system32\Drivers\mtk.sys [x]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2010-11-06 19056]
R3 PORTIO64;PORTIO64;c:\docume~1\LEEEDG~1\LOCALS~1\Temp\PIOAD6.tmp [x]
R3 SecureSrv;SecureSrv; [x]
R3 vad_multi;Windigo Virtual Audio Device (WDM);c:\windows\system32\drivers\vadmulti.sys [x]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2006-08-10 223128]
R3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe [2008-04-14 14336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-12-27 239168]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-08-11 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-08-11 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-19 116608]
S2 aswFsBlk;aswFsBlk; [x]
S2 pdfFactory Pro Dispatcher v3;pdfFactory Pro Dispatcher v3;c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe [2010-03-18 614400]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2006-12-16 47360]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-23 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 21:51]
.
2011-12-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
2011-12-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006Core.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-20 16:42]
.
2011-12-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006UA.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-20 16:42]
.
2011-12-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 18:38]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 18:38]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006Core.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-05-18 23:44]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006UA.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-05-18 23:44]
.
2011-12-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-10512063-1881097818-1119676352-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2011-12-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-10512063-1881097818-1119676352-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2011-12-27 c:\windows\Tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
Trusted Zone: securesuite.co.uk\www
TCP: DhcpNameServer = 192.168.0.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://secure.footprint.net/kingsisle/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
FF - ProfilePath - c:\documents and settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q;=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-27762978.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-28 00:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
C:\## aswSnx private storage
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\PORTIO64]
"ImagePath"="\??\c:\docume~1\LEEEDG~1\LOCALS~1\Temp\PIOAD6.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-10512063-1881097818-1119676352-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2a,d9,db,11,cc,c7,6e,95,52,b5,58,cb,a0,cf,e4,ad,27,de,53,33,93,32,9f,
ab,3a,83,12,94,c7,4b,50,8d,67,ec,61,46,52,f3,d8,a0,97,05,fc,c5,b7,1e,48,5d,\
"??"=hex:56,52,75,73,36,e9,4b,67,3c,6b,47,2a,09,08,ac,8b
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(684)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(6544)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\Unlocker\UnlockerHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\UPHClean\uphclean.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\windows\system32\rundll32.exe
c:\windows\BCMSMMSG.exe
c:\program files\Java\jre6\bin\javaw.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Java\jre6\bin\javaw.exe
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2011-12-28 00:43:50 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-28 00:43
.
Pre-Run: 21,842,145,280 bytes free
Post-Run: 22,462,140,416 bytes free
.
- - End Of File - - 3D79AAF2B0E763373F4EDA2897EDEAA5
Hi

Please run the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2011.12.28.02 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Lee Edgar :: MAINCOMPUTER [administrator] 28/12/2011 08:41:59 mbam-log-2011-12-28 (08-41-59).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 237795 Time elapsed: 12 minute(s), 1 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESETSCAN C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000783 a variant of Win32/InstallCore.D application C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\Cache\A\2D\2FD43d01 a variant of Win32/AdInstaller application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP273\A0040911.exe a variant of Win32/Toolbar.MyWebSearch.O application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP273\A0040914.dll a variant of Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP289\A0043013.dll a variant of Win32/Toolbar.MyWebSearch.A application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP289\A0043019.dll probably a variant of Win32/Toolbar.MyWebSearch.F application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP289\A0043020.dll probably a variant of Win32/Toolbar.MyWebSearch.B application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP289\A0043023.dll probably a variant of Win32/Toolbar.MyWebSearch.P application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP289\A0043028.dll a variant of Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP289\A0043034.dll a variant of Win32/Toolbar.MyWebSearch.P application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0046031.exe a variant of Win32/HackTool.SystemCall.AA application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0046032.exe a variant of Win32/HackTool.SystemCall.AA application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0046035.sys Win32/HackTool.CheatEngine application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0046036.dll a variant of Win32/HackTool.CheatEngine.AA application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0046044.exe a variant of Win32/HackTool.CheatEngine.AA application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0046061.sys probably a variant of Win32/HackTool.CheatEngine.AA application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0046074.exe a variant of Win32/HackTool.CheatEngine.AB application C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP328\A0049688.exe multiple threats C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP328\A0049689.exe multiple threats
Hi,

Please do the following:

Note: Please allow ComboFix to update if it asks to do so.

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000783 
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\Cache\A\2D\2FD43d01 

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 29 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


NEXT

Please advise how the computer is running now and if there are any outstanding issues.
Hi Catbyte

ComboFix log attached, Adobe,Java updates done, Computer seems fine with no issues :thumbup:

Thanks ED



ComboFix 11-12-28.03 - Lee Edgar 28/12/2011 14:42:47.7.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Lee Edgar\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.
FILE ::
"c:\documents and settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000783"
"c:\documents and settings\Lee Edgar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\Cache\A\2D\2FD43d01"
.
.
((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-28 )))))))))))))))))))))))))))))))
.
.
2011-12-28 09:01 . 2011-12-28 09:01 ——– d—–w- c:\program files\ESET
2011-12-27 17:14 . 2011-12-27 17:14 239168 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-12-27 17:14 . 2011-12-27 17:14 ——– d—–w- c:\program files\DAEMON Tools Lite
2011-12-27 17:13 . 2011-12-27 17:17 ——– d—–w- c:\documents and settings\Lee Edgar\Application Data\DAEMON Tools Lite
2011-12-27 17:13 . 2011-12-27 17:13 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2011-12-27 16:09 . 2011-12-27 16:09 ——– d—–w- c:\program files\Conduit
2011-12-27 16:09 . 2011-12-27 16:13 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Conduit
2011-12-27 16:07 . 2011-12-27 16:07 ——– d—–w- c:\program files\uTorrent
2011-12-27 16:06 . 2011-12-27 16:06 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\uTorrent
2011-12-27 11:20 . 2011-12-27 11:20 ——– d—–w- c:\documents and settings\Lee Edgar\Application Data\Yahoo!
2011-12-27 09:57 . 2011-12-27 09:57 ——– d—–w- c:\program files\VS Revo Group
2011-12-18 10:23 . 2011-12-18 10:23 11776 —-a-w- c:\program files\Mozilla Firefox\plugins\nprjplug.dll
2011-12-18 10:22 . 2011-12-18 10:22 ——– d—–w- c:\program files\Common Files\xing shared
2011-12-18 10:22 . 2011-12-18 10:22 150696 —-a-w- c:\program files\Mozilla Firefox\plugins\nppl3260.dll
2011-12-18 10:21 . 2011-12-18 10:21 108544 —-a-w- c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
2011-12-15 19:53 . 2011-12-15 19:53 ——– d—–w- c:\documents and settings\Lee Edgar\Application Data\gtk-2.0
2011-12-15 19:52 . 2011-12-15 19:52 ——– d—–w- c:\documents and settings\Lee Edgar\.thumbnails
2011-12-15 19:50 . 2011-12-16 19:37 ——– d—–w- c:\documents and settings\Lee Edgar\.gimp-2.6
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 10:21 . 2003-03-18 20:14 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-12-18 10:21 . 2003-02-21 04:42 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-12-10 15:24 . 2009-04-09 21:01 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-28 18:01 . 2010-08-28 16:22 41184 —-a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2009-09-10 18:38 199816 —-a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-03-15 20:30 435032 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2009-09-10 18:39 314456 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2009-09-10 18:39 34392 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2009-09-10 18:39 52952 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2009-09-10 18:39 111320 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2009-09-10 18:39 105176 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2009-09-10 18:39 20568 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2009-09-10 18:39 30808 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-23 13:25 . 2002-08-29 05:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-12 14:23 . 2011-08-11 06:19 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 19:20 . 2004-08-23 19:32 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2002-08-29 05:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2002-08-29 05:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-05-05 20:06 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2002-08-29 05:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2009-04-16 06:22 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2009-04-16 06:22 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2002-08-29 05:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2004-06-07 13:19 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-03 04:06 . 2010-05-15 07:57 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 01:37 . 2011-02-24 19:14 73728 —-a-w- c:\windows\system32\javacpl.cpl
2000-01-14 14:46 . 2006-09-07 20:58 24576 ——w- c:\program files\Common Files\XCPCMenu.exe
2000-01-14 14:46 . 2006-09-07 20:58 696320 ——w- c:\program files\Common Files\XCMHook.dll
2011-09-21 21:37 . 2011-04-18 14:33 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="\Program\" [X]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-12-18 4616064]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-14 1957888]
"JagexProperties"="c:\.jagex_cache_32\jagd.jar" [2011-07-10 29816]
"JaGeXDaemon"="c:\.jagex_cache_32\jagc.jar" [2011-12-28 35298]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"PrinterShare"="c:\program files\PrinterShare\paConsole.exe" [2011-09-08 1124352]
"Facebook Update"="c:\documents and settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2011-10-20 137536]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-11-28 3744552]
"WheelMouse"="c:\progra~1\A4Tech\Mouse\Amoumain.exe" [2004-09-01 147456]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2010-03-18 614400]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"iKeyWorks"="c:\progra~1\A4Tech\Keyboard\Ikeymain.exe" [2004-08-31 61440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-12-18 296056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\Lee Edgar\Start Menu\Programs\Startup\
.jagex_runescape_preferences.jar [2011-12-28 35298]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2010-8-4 303104]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-6-11 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-6-11 813584]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-11 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 12:28 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe"
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Orange\\Livebox\\RGWREPAIR.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\PrinterShare\\paConsole.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Lee Edgar\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16193:TCP"= 16193:TCP:BitComet 16193 TCP
"16193:UDP"= 16193:UDP:BitComet 16193 UDP
"55064:TCP"= 55064:TCP:bitcomet 55064 tcp
"55064:UDP"= 55064:UDP:bitcomet 55064 udp
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\Drivers\Ca533av.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 136176]
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\DRIVERS\Amps2prt.sys [2004-08-25 9984]
R3 BTCOMM;BTCOMM;c:\windows\system32\drivers\Btcomm.sys [x]
R3 BTKRNBDG;Bluetooth COM Bridge;c:\windows\system32\DRIVERS\btkrnbdg.sys [x]
R3 CSRBC01;%CSRBC01.SvcDesc%;c:\windows\system32\Drivers\csrbc01.sys [x]
R3 DLPortIO;DriverLINX Port I/O Driver;c:\windows\system32\DRIVERS\DLPortIO.SYS [2000-06-29 3584]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 136176]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 MTK;Media Technology Kernel Driver;c:\windows\system32\Drivers\mtk.sys [x]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2010-11-06 19056]
R3 PORTIO64;PORTIO64;c:\docume~1\LEEEDG~1\LOCALS~1\Temp\PIOAD6.tmp [x]
R3 SecureSrv;SecureSrv; [x]
R3 vad_multi;Windigo Virtual Audio Device (WDM);c:\windows\system32\drivers\vadmulti.sys [x]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2006-08-10 223128]
R3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe [2008-04-14 14336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-12-27 239168]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-08-11 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-08-11 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-19 116608]
S2 aswFsBlk;aswFsBlk; [x]
S2 pdfFactory Pro Dispatcher v3;pdfFactory Pro Dispatcher v3;c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe [2010-03-18 614400]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2006-12-16 47360]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-23 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 21:51]
.
2011-12-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
2011-12-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006Core.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-20 16:42]
.
2011-12-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006UA.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-20 16:42]
.
2011-12-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 18:38]
.
2011-12-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 18:38]
.
2011-12-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006Core.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-05-18 23:44]
.
2011-12-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006UA.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-05-18 23:44]
.
2011-12-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-10512063-1881097818-1119676352-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2011-12-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-10512063-1881097818-1119676352-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2011-12-27 c:\windows\Tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
Trusted Zone: securesuite.co.uk\www
TCP: DhcpNameServer = 192.168.0.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://secure.footprint.net/kingsisle/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
FF - ProfilePath - c:\documents and settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q;=
FF - user.js: keyword.enabled - 1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-28 15:09
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\PORTIO64]
"ImagePath"="\??\c:\docume~1\LEEEDG~1\LOCALS~1\Temp\PIOAD6.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-10512063-1881097818-1119676352-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2a,d9,db,11,cc,c7,6e,95,52,b5,58,cb,a0,cf,e4,ad,27,de,53,33,93,32,9f,
ab,3a,83,12,94,c7,4b,50,8d,67,ec,61,46,52,f3,d8,a0,97,05,fc,c5,b7,1e,48,5d,\
"??"=hex:56,52,75,73,36,e9,4b,67,3c,6b,47,2a,09,08,ac,8b
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(684)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(15480)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\hnetcfg.dll
.
Completion time: 2011-12-28 15:17:58
ComboFix-quarantined-files.txt 2011-12-28 15:17
ComboFix2.txt 2011-12-28 00:43
.
Pre-Run: 22,370,443,264 bytes free
Post-Run: 22,347,902,976 bytes free
.
- - End Of File - - 62372774B00D757FA74E466AE1AD7038
Hi

Just some housekeeping to do now,

Please do the following:


You can delete the TDSSKiller, DDS and aswMBR logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI