This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible malware infection [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello all I have been noticing a serious lag in my internet connection as well as having an annoying toolbar that i continually uninstall but won't leave
I think I have found the right place for assistance.

hijack this log file:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:49:17 PM, on 1/1/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\zumodrive.exe
C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe
C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe
C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
C:\Program Files (x86)\GmoteServer\GmoteServer.exe
C:\Program Files (x86)\Java\jre6\bin\javaw.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Sandboxie\32\SbieSvc.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s=…hTerms}&f=4
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;192.168.*.*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll
O2 - BHO: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [ZumoDrive] "C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk
O4 - HKCU\..\Run: [Google Update] "C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Owner\Desktop\utorrent.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Remote Trackpad Server] C:\Program Files (x86)\Remote Trackpad Server\RemoteTrackpadServer.exe
O4 - Startup: Dropbox.lnk = Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
O4 - Global Startup: Snapfish PictureMover.lnk = C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{EEB0FB26-9366-481A-A8D5-77F806FAA72C}: NameServer = 172.25.129.1
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O23 - Service: 2X Publishing Agent - 2X Software Ltd. - C:\Program Files (x86)\2X\ApplicationServer\2XController.exe
O23 - Service: 2X Redundancy Service - 2X Software Ltd. - C:\Program Files (x86)\2X\ApplicationServer\2XRedundancy.exe
O23 - Service: 2X SecureClientGateway - 2X Software Ltd. - C:\Program Files (x86)\2X\ApplicationServer\2XProxyGateway.exe
O23 - Service: 2X Terminal Server Agent - 2X Software Ltd. - C:\Program Files (x86)\2X\ApplicationServer\2XAgent.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Red Bend Device Management Service (DMAgent) - Red Bend Ltd. - C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HideMyIpSRV - Hide My IP - C:\Program Files (x86)\Hide My IP\HideMyIpSrv.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files (x86)\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RoxioNow Service - Roxio - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TabletServiceWacom - Unknown owner - C:\Windows\system32\Wacom_Tablet.exe (file missing)
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\UltraVNC\winvnc.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Intel® PROSet/Wireless WiMAX Service (WiMAXAppSrv) - Intel® Corporation - C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wyse PocketCloud (WysePocketCloud) - Unknown owner - C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\PocketCloudService.exe

–
End of file - 18514 bytes


thanks I could download the other utilities I have seen in the other posts but I will wait to see if ya'll think it's necessary.

Thanks and Happy New Year :thumbup:
I apologize I have read the Are U Infected topic.

here is my Hijack this log file run as administrator

the last one wasn't

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:58:59 PM, on 1/1/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\zumodrive.exe
C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe
C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe
C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
C:\Program Files (x86)\Air Mouse\Air Mouse\Mobile Mouse Service.exe
C:\Program Files (x86)\GmoteServer\GmoteServer.exe
C:\Program Files (x86)\Java\jre6\bin\javaw.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Sandboxie\32\SbieSvc.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s=…hTerms}&f=4
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;192.168.*.*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll
O2 - BHO: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [ZumoDrive] "C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk
O4 - HKCU\..\Run: [Google Update] "C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Owner\Desktop\utorrent.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Remote Trackpad Server] C:\Program Files (x86)\Remote Trackpad Server\RemoteTrackpadServer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
O4 - Global Startup: Snapfish PictureMover.lnk = C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{EEB0FB26-9366-481A-A8D5-77F806FAA72C}: NameServer = 172.25.129.1
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O23 - Service: 2X Publishing Agent - 2X Software Ltd. - C:\Program Files (x86)\2X\ApplicationServer\2XController.exe
O23 - Service: 2X Redundancy Service - 2X Software Ltd. - C:\Program Files (x86)\2X\ApplicationServer\2XRedundancy.exe
O23 - Service: 2X SecureClientGateway - 2X Software Ltd. - C:\Program Files (x86)\2X\ApplicationServer\2XProxyGateway.exe
O23 - Service: 2X Terminal Server Agent - 2X Software Ltd. - C:\Program Files (x86)\2X\ApplicationServer\2XAgent.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Red Bend Device Management Service (DMAgent) - Red Bend Ltd. - C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HideMyIpSRV - Hide My IP - C:\Program Files (x86)\Hide My IP\HideMyIpSrv.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files (x86)\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RoxioNow Service - Roxio - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TabletServiceWacom - Unknown owner - C:\Windows\system32\Wacom_Tablet.exe (file missing)
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\UltraVNC\winvnc.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Intel® PROSet/Wireless WiMAX Service (WiMAXAppSrv) - Intel® Corporation - C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wyse PocketCloud (WysePocketCloud) - Unknown owner - C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\PocketCloudService.exe

–
End of file - 19011 bytes

thanks again I will post results from OTL and DDS shortly
OTL keeps freezing at scanning modules I will try it again in a minute here is my results from DDS the first part DDS.text . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 23:13:21.52 on Sun 01/01/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3894.1319 [GMT -7:00] . AV: Kaspersky Anti-Virus *Enabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Kaspersky Anti-Virus *Enabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\IDT\WDM\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Hpservice.exe C:\Program Files\Sandboxie\SbieSvc.exe C:\Windows\system32\vcsFPService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Program Files\DigitalPersona\Bin\DpHostW.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\2X\ApplicationServer\2XController.exe C:\Program Files (x86)\2X\ApplicationServer\2XRedundancy.exe C:\Program Files (x86)\2X\ApplicationServer\2XProxyGateway.exe C:\Program Files (x86)\2X\ApplicationServer\2XAgent.exe C:\Program Files\IDT\WDM\AESTSr64.exe C:\Windows\SysWOW64\svchost.exe -k Akamai C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe C:\Program Files (x86)\Sony\MD Simple Burner\NetMDSB.exe c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\Wacom_Tablet.exe C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe C:\Program Files\UltraVNC\winvnc.exe C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe C:\Windows\SysWOW64\vmnat.exe C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\PocketCloudService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\SysWOW64\vmnetdhcp.exe C:\Program Files\UltraVNC\winvnc.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe C:\Program Files (x86)\Hide My IP\HideMyIpSrv.exe C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe C:\Windows\system32\WTablet\Wacom_TabletUser.exe C:\Windows\system32\Wacom_Tablet.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe C:\Program Files\DigitalPersona\Bin\DPAgent.exe C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Sandboxie\SbieCtrl.exe C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\zumodrive.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files (x86)\PowerISO\PWRISOVM.EXE C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\DllHost.exe C:\Program Files (x86)\Air Mouse\Air Mouse\Mobile Mouse Service.exe C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files (x86)\GmoteServer\GmoteServer.exe C:\Program Files (x86)\Java\jre6\bin\javaw.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Sandboxie\SandboxieRpcSs.exe C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files\Sandboxie\32\SbieSvc.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\notepad.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Users\Owner\Desktop\dds.scr C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local;192.168.*.* mSearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 uURLSearchHooks: H - No File mWinlogon: Userinit=userinit.exe, BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll BHO: Virtual Storage Mount Notification: {5ff49fe8-b332-4cb9-b102-fb6951629e55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll TB: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden uRun: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk uRun: [Google Update] "C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" uRun: [uTorrent] "C:\Users\Owner\Desktop\utorrent.exe" uRun: [AdobeBridge] uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [Akamai NetSession Interface] "C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe" uRun: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED uRun: [Remote Trackpad Server] C:\Program Files (x86)\Remote Trackpad Server\RemoteTrackpadServer.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe mRun: [ZumoDrive] "C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk" mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin mRun: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE mRun: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\Users\Owner\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\Users\Owner\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PDANET~1.LNK - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SNAPFI~1.LNK - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-explorer: EnableShellExecuteHooks = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll LSP: C:\Windows\system32\HMIPCore.dll LSP: C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab TCP: {EEB0FB26-9366-481A-A8D5-77F806FAA72C} = 172.25.129.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll STS: Virtual Storage Mount Notification: {5ff49fe8-b332-4cb9-b102-fb6951629e55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll SEH: UrlHook Class: {afbdff94-346c-4c3d-ac24-3da0b41bb6cd} - C:\Program Files (x86)\2X\ApplicationServer\TUXUrlHandler.dll LSA: Notification Packages = DPPassFilter scecli mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll BHO-X64: IEVkbdBHO - No File BHO-X64: Virtual Storage Mount Notification: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll BHO-X64: Virtual Storage Mount Notification - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll BHO-X64: link filter bho - No File TB-X64: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe mRun-x64: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray mRun-x64: [IntelWirelessWiMAX] "C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe" /tasktray /nosplash mRun-x64: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background mRun-x64: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe mRun-x64: [PocketCloud Location] "C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe" mRun-x64: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" SSODL-X64: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll STS-X64: Virtual Storage Mount Notification: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll SEH-X64: UrlHook Class: {AFBDFF94-346C-4C3D-AC24-3DA0B41BB6CD} - C:\Program Files (x86)\2X\ApplicationServer\x64\TUXUrlHandler.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\nrsi313n.default\ FF - prefs.js: browser.search.selectedEngine - Facemoods Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll FF - plugin: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ============= SERVICES / DRIVERS =============== . R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-5-1 55280] R1 CbFs;CbFs;C:\Windows\System32\drivers\cbfs64.sys [2011-4-15 191960] R1 cbfs3;cbfs3;C:\Windows\System32\drivers\cbfs3.sys [2011-4-29 323472] R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R2 2X Publishing Agent;2X Publishing Agent;C:\Program Files (x86)\2X\ApplicationServer\2XController.exe [2011-12-1 2026376] R2 2X Redundancy Service;2X Redundancy Service;C:\Program Files (x86)\2X\ApplicationServer\2XRedundancy.exe [2011-12-1 1578888] R2 2X SecureClientGateway;2X SecureClientGateway;C:\Program Files (x86)\2X\ApplicationServer\2XProxyGateway.exe [2011-12-1 1660296] R2 2X Terminal Server Agent;2X Terminal Server Agent;C:\Program Files (x86)\2X\ApplicationServer\2XAgent.exe [2011-12-1 937864] R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2010-10-25 89600] R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 27136] R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-11-2 365336] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664] R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2010-6-7 408576] R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-6-21 85560] R2 HP Wireless Assistant Service;HP Wireless Assistant Service;C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-7-21 103992] R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-7-5 227384] R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-5-13 30520] R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-9 26680] R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-12-7 375176] R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2011-9-16 15928] R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2011-12-30 72216] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-27 652872] R2 MotoHelper;MotoHelper Service;C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2011-8-10 227184] R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-9-11 399344] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264] R2 TabletServiceWacom;TabletServiceWacom;C:\Windows\System32\Wacom_Tablet.exe [2011-5-13 6245744] R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-28 2984832] R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-25 2533400] R2 uvnc_service;uvnc_service;C:\Program Files\UltraVNC\winvnc.exe [2011-12-30 2169592] R2 vcsFPService;Validity VCS Fingerprint Service;C:\Windows\System32\vcsFPService.exe [2010-2-23 2192176] R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-3-25 539248] R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2010-6-7 911872] R2 WysePocketCloud;Wyse PocketCloud;C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\PocketCloudService.exe [2011-12-20 155552] R3 bpenum;bpenum;C:\Windows\System32\drivers\bpenum.sys [2010-5-16 71168] R3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\Windows\System32\drivers\bpmp.sys [2010-5-16 175104] R3 bpusb;bpusb;C:\Windows\System32\drivers\bpusb.sys [2010-5-16 81920] R3 clwvd;HP Webcam Splitter;C:\Windows\System32\drivers\clwvd.sys [2010-9-3 31088] R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-5-1 56344] R3 HideMyIpSRV;HideMyIpSRV;C:\Program Files (x86)\Hide My IP\HideMyIpSrv.exe [2011-12-12 3249512] R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-2-26 158976] R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-6-21 287232] R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-4-22 23152] R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETwNs64.sys [2011-7-21 8593920] R3 pneteth;PdaNet Broadband;C:\Windows\System32\drivers\pneteth.sys [2011-9-30 15360] R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2011-3-24 148072] R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2010-9-14 760168] R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2010-9-14 268648] R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2010-9-14 25960] R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2010-9-14 22376] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920] R3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2011-5-13 18216] R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2010-8-16 39832] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\System32\drivers\ssadadb.sys [2011-5-13 36328] S3 BTCFilterService;USB Networking Driver Filter Service;C:\Windows\System32\drivers\motfilt.sys [2009-1-29 6144] S3 motandroidusb;Mot ADB Interface Driver;C:\Windows\System32\drivers\motoandroid.sys [2009-7-10 31744] S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\System32\drivers\motccgp.sys [2011-4-4 21504] S3 motccgpfl;MotCcgpFlService;C:\Windows\System32\drivers\motccgpfl.sys [2009-1-29 9216] S3 Motousbnet;Motorola USB Networking Driver Service;C:\Windows\System32\drivers\Motousbnet.sys [2010-4-1 26624] S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-7-19 340240] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2011-4-14 7680512] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-3-30 20992] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-10-25 232992] S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-10-25 344680] S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\System32\drivers\RTL8187.sys [2010-1-7 448512] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864] S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864] S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\System32\drivers\ssadbus.sys [2011-5-13 157672] S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\System32\drivers\ssadmdfl.sys [2011-5-13 16872] S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\System32\drivers\ssadmdm.sys [2011-5-13 177640] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-30 59392] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-30 1255736] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120] . =============== Created Last 30 ================ . 2012-01-01 19:30:46 ——– d—–w- C:\Program Files (x86)\KRtech 2012-01-01 19:06:02 388096 —-a-r- C:\Users\Owner\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-01-01 19:06:01 ——– d—–w- C:\Program Files (x86)\Trend Micro 2012-01-01 09:28:07 69000 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{ECBDEA2C-DC93-4BD7-A7DF-E343A9DAE834}\offreg.dll 2012-01-01 09:28:04 8822856 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{ECBDEA2C-DC93-4BD7-A7DF-E343A9DAE834}\mpengine.dll 2011-12-31 22:20:22 ——– d—–w- C:\Windows\System32\appmgmt 2011-12-31 21:37:19 0 —-a-w- C:\Windows\SysWow64\sho3BC7.tmp 2011-12-31 19:59:15 0 —-a-w- C:\Windows\SysWow64\sho1F4.tmp 2011-12-31 02:13:43 ——– d—–w- C:\HP_TOOLS_mountHPSF 2011-12-30 20:35:37 ——– d—–w- C:\Program Files (x86)\No-IP 2011-12-30 10:26:47 ——– d—–w- C:\Users\Owner\AppData\Roaming\UltraVNC 2011-12-30 10:19:47 ——– d—–w- C:\Program Files\UltraVNC 2011-12-30 10:13:56 ——– d—–w- C:\Users\Owner\AppData\Local\APN 2011-12-30 09:54:39 ——– d—–w- C:\Users\Owner\AppData\Local\ElevatedDiagnostics 2011-12-30 07:18:33 ——– d—–w- C:\Users\Owner\AppData\Local\LogMeIn 2011-12-30 07:18:27 87456 —-a-w- C:\Windows\System32\LMIRfsClientNP.dll 2011-12-30 07:18:27 72216 —-a-w- C:\Windows\System32\drivers\LMIRfsDriver.sys 2011-12-30 07:18:27 59776 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\LMIproc.dll 2011-12-30 07:18:27 34688 —-a-w- C:\Windows\System32\LMIport.dll 2011-12-30 07:18:25 80768 —-a-w- C:\Windows\System32\LMIinit.dll 2011-12-30 07:18:21 ——– d—–w- C:\PROGRA~3\LogMeIn 2011-12-30 07:18:01 ——– d—–w- C:\Program Files (x86)\LogMeIn 2011-12-30 00:32:00 ——– d—–w- C:\Program Files\Bonjour Print Services 2011-12-30 00:31:36 ——– d—–w- C:\Users\Owner\AppData\Local\Apple 2011-12-30 00:31:24 ——– d—–w- C:\Program Files\Bonjour 2011-12-30 00:31:24 ——– d—–w- C:\Program Files (x86)\Bonjour 2011-12-30 00:26:27 ——– d—–w- C:\Users\Owner\AppData\Local\AirMouse 2011-12-30 00:24:28 ——– d—–w- C:\Users\Owner\AppData\Local\Downloaded Installations 2011-12-29 23:30:39 ——– d—–w- C:\Users\Owner\AppData\Roaming\TeamViewer 2011-12-29 11:14:25 0 —-a-w- C:\Windows\SysWow64\shoA50A.tmp 2011-12-29 08:27:22 ——– d—–w- C:\Users\Owner\AppData\Local\RemoteTrackpadServer 2011-12-29 08:23:32 ——– d—–w- C:\Program Files (x86)\Remote Trackpad Server 2011-12-28 23:34:22 810888 —-a-w- C:\Windows\System32\memshell.exe 2011-12-28 23:34:09 783752 —-a-w- C:\Windows\System32\2XUnivPrnPM.dll 2011-12-28 23:33:48 ——– d—–w- C:\Program Files (x86)\2X 2011-12-28 23:23:44 ——– d—–w- C:\Program Files (x86)\Wyse 2011-12-28 23:08:33 ——– d—–w- C:\Program Files (x86)\TeamViewer 2011-12-28 01:23:35 0 —-a-w- C:\Windows\SysWow64\sho905C.tmp 2011-12-19 08:09:57 ——– d—–w- C:\Program Files\Motorola Inc 2011-12-18 23:40:42 ——– d—–w- C:\Program Files (x86)\BitTorrent 2011-12-18 23:39:37 ——– d—–w- C:\Users\Owner\AppData\Roaming\BitTorrent 2011-12-18 22:47:55 2106216 —-a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2011-12-18 22:47:55 1998168 —-a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll 2011-12-16 01:20:07 0 —-a-w- C:\Windows\SysWow64\sho5F9C.tmp 2011-12-16 01:03:36 0 —-a-w- C:\Windows\SysWow64\sho477E.tmp 2011-12-15 06:09:42 737072 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2011-12-15 06:09:22 4283672 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-12-15 06:09:06 42776 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-12-15 06:08:57 539984 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2011-12-15 05:47:38 0 —-a-w- C:\Windows\SysWow64\shoBDB3.tmp 2011-12-15 05:29:41 0 —-a-w- C:\Windows\SysWow64\shoD27B.tmp 2011-12-15 05:28:37 ——– d-sh–w- C:\Windows\BitLockerDiscoveryVolumeContents 2011-12-15 05:28:37 ——– d—–w- C:\Windows\RemotePackages 2011-12-15 04:52:21 0 —-a-w- C:\Windows\SysWow64\sho5CCF.tmp 2011-12-15 04:34:43 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-12-15 04:33:48 723456 —-a-w- C:\Windows\System32\EncDec.dll 2011-12-15 04:33:47 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll 2011-12-15 04:09:08 ——– d—–w- C:\Users\Owner\AppData\Local\PackageAware 2011-12-14 01:37:12 0 —-a-w- C:\Windows\SysWow64\shoE501.tmp 2011-12-12 22:26:30 ——– d—–w- C:\Program Files (x86)\Transcribe! 2011-12-12 22:14:15 ——– d—–w- C:\Program Files (x86)\FastStone Player 2011-12-12 21:49:24 0 —-a-w- C:\Windows\SysWow64\sho1AC2.tmp 2011-12-12 21:46:54 424296 —-a-w- C:\Windows\System32\HMIPCore64.dll 2011-12-12 21:46:48 ——– d—–w- C:\Program Files (x86)\Hide My IP 2011-12-10 00:32:11 0 —-a-w- C:\Windows\SysWow64\sho4579.tmp 2011-12-07 18:59:18 0 —-a-w- C:\Windows\SysWow64\sho1363.tmp 2011-12-04 00:24:21 0 —-a-w- C:\Windows\SysWow64\sho2828.tmp . ==================== Find3M ==================== . 2011-12-30 01:34:28 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-12-15 05:51:53 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-12-10 22:24:08 23152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-11-29 23:20:50 0 —-a-w- C:\Windows\SysWow64\shoCBE9.tmp 2011-11-29 09:23:02 0 —-a-w- C:\Windows\SysWow64\sho38A1.tmp 2011-11-24 04:52:09 3145216 —-a-w- C:\Windows\System32\win32k.sys 2011-11-15 21:29:56 270720 ——w- C:\Windows\System32\MpSigStub.exe 2011-11-14 07:02:36 0 —-a-w- C:\Windows\SysWow64\sho1E69.tmp 2011-11-08 10:47:42 0 —-a-w- C:\Windows\SysWow64\shoECE1.tmp 2011-11-05 06:22:27 0 —-a-w- C:\Windows\SysWow64\sho549D.tmp 2011-11-05 05:32:50 2048 —-a-w- C:\Windows\System32\tzres.dll 2011-11-05 04:26:03 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2011-11-04 11:10:00 0 —-a-w- C:\Windows\SysWow64\sho4CB3.tmp 2011-11-04 01:53:39 2309120 —-a-w- C:\Windows\System32\jscript9.dll 2011-11-04 01:44:47 1390080 —-a-w- C:\Windows\System32\wininet.dll 2011-11-04 01:44:21 1493504 —-a-w- C:\Windows\System32\inetcpl.cpl 2011-11-04 01:34:43 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-11-03 22:47:42 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-11-03 22:40:21 1427456 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2011-11-03 22:39:47 1127424 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-11-03 22:31:57 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-10-29 06:44:01 0 —-a-w- C:\Windows\SysWow64\sho6DB9.tmp 2011-10-27 06:58:55 0 —-a-w- C:\Windows\SysWow64\sho7311.tmp 2011-10-27 01:31:41 0 —-a-w- C:\Windows\SysWow64\shoE22B.tmp 2011-10-26 05:21:20 43520 —-a-w- C:\Windows\System32\csrsrv.dll 2011-10-25 04:59:36 0 —-a-w- C:\Windows\SysWow64\shoDFF9.tmp 2011-10-21 04:53:55 0 —-a-w- C:\Windows\SysWow64\sho51F7.tmp 2011-10-20 03:28:14 0 —-a-w- C:\Windows\SysWow64\sho6931.tmp 2011-10-18 06:12:39 0 —-a-w- C:\Windows\SysWow64\sho7081.tmp 2011-10-17 19:22:15 0 —-a-w- C:\Windows\SysWow64\sho898A.tmp 2011-10-16 16:06:40 0 —-a-w- C:\Windows\SysWow64\sho7677.tmp 2011-10-15 05:42:50 0 —-a-w- C:\Windows\SysWow64\sho3E4C.tmp 2011-10-14 19:20:33 0 —-a-w- C:\Windows\SysWow64\sho9300.tmp 2011-10-14 06:16:18 0 —-a-w- C:\Windows\SysWow64\shoDC1E.tmp 2011-10-11 05:41:45 0 —-a-w- C:\Windows\SysWow64\shoFA39.tmp 2011-10-07 00:47:19 0 —-a-w- C:\Windows\SysWow64\sho3A42.tmp . ============= FINISH: 23:14:41.73 =============== i will attach the other part zipped as requested.

Attachments:

Here is the results from OTL

i gave it a couple more seconds and it worked


OTL logfile created on: 1/1/2012 11:22:49 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 1.29 Gb Available Physical Memory | 33.82% Memory free
7.60 Gb Paging File | 4.55 Gb Available in Paging File | 59.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 436.37 Gb Total Space | 241.04 Gb Free Space | 55.24% Space Free | Partition Type: NTFS
Drive D: | 29.10 Gb Total Space | 4.24 Gb Free Space | 14.57% Space Free | Partition Type: NTFS
Drive G: | 199.00 Mb Total Space | 132.80 Mb Free Space | 66.74% Space Free | Partition Type: NTFS
Drive Z: | 2.00 Gb Total Space | 2.00 Gb Free Space | 100.00% Space Free | Partition Type: FAT32

Computer Name: OWNER-HP | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Java\jre6\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\2X\ApplicationServer\2XProxyGateway.exe (2X Software Ltd.)
PRC - C:\Program Files (x86)\2X\ApplicationServer\2XRedundancy.exe (2X Software Ltd.)
PRC - C:\Program Files (x86)\2X\ApplicationServer\2XController.exe (2X Software Ltd.)
PRC - C:\Program Files (x86)\2X\ApplicationServer\2XAgent.exe (2X Software Ltd.)
PRC - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
PRC - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hide My IP\HideMyIpSrv.exe (Hide My IP)
PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
PRC - C:\Program Files\Sandboxie\32\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\zumodrive.exe (Zecter Inc.)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files (x86)\GmoteServer\GmoteServer.exe ()
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files (x86)\Sony\MD Simple Burner\NetMDSB.exe (Sony Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\Owner\AppData\Local\Temp\WindowsFolderWatcher.dll4082176897675895132.lib ()
MOD - C:\Users\Owner\AppData\Local\Temp\WindowsZFSJNI.dll660137509428536071.lib ()
MOD - C:\Users\Owner\AppData\Local\Temp\libsqlitejdbc-1738233861591784995.lib ()
MOD - C:\Users\Owner\AppData\Local\Temp\WindowsAPI.dll7738718499696308692.lib ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\32f68764be7200d3796b55e377311245\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
MOD - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\GmoteServer\GmoteServer.exe ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libx264_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\avcodec-51.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\libxml2-2.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\libiconv-2.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\libfreetype-6.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\libgcrypt-11.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\libfontconfig-1.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\libz-1-2.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\libgpg-error-0.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libvorbis_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libtaglib_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libtheora_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libtwolame_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libts_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libvod_rtsp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libvout_directx_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libvisual_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libty_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libvobsub_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libwaveout_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libvcd_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libwingdi_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libtransform_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libyuy2_i420_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libtelnet_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libwall_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libxtag_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libyuy2_i422_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libwav_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libvoc_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libtta_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libvmem_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libvc1_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libwave_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libxa_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libtrivial_channel_mixer_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libugly_resampler_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libtrivial_resampler_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libtrivial_mixer_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libqt4_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libskins2_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmkv_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libschroedinger_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libsdl_image_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libswscale_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmod_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpng_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmp4_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpostproc_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmpgatofixed32_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmux_ts_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libspeex_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libplaylist_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_rtp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libspatializer_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmux_ps_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libportaudio_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmux_mp4_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libogg_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpanoramix_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libsap_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpacketizer_mpeg4audio_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librc_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmux_asf_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpacketizer_h264_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_transcode_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_standard_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libremoteosd_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librealaudio_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libps_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmosaic_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libreal_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libsubtitle_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmux_ogg_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librtp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libsubsdec_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmux_avi_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librss_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpacketizer_vc1_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libsubsusf_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpacketizer_mpeg4video_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libopengl_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_mosaic_bridge_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmotiondetect_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpuzzle_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libnuv_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libosd_parser_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpva_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpacketizer_mpegvideo_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libspudec_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libsmf_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librotate_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libosdmenu_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmono_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmpeg_audio_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libscreen_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libsvcdsub_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librawvid_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpsychedelic_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_duplicate_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_bridge_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstats_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libscaletempo_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libparam_eq_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libntservice_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libnsv_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_es_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libquicktime_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmpga_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libsimple_channel_mixer_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libshout_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librealvideo_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librawdv_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libripple_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpodcast_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libnsc_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libnormvol_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmsn_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_gather_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_display_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libsharpen_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libscale_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librawvideo_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmux_wav_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libpacketizer_copy_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libnoise_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmux_mpjpeg_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmotionblur_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_autodel_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libshowintf_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmux_dummy_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmpgv_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_description_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libt140_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\librv32_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libstream_out_dummy_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libspdif_mixer_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liblive555_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\libvlccore.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libavformat_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcaca_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libgnutls_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_output_shout_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libfaad_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liblua_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libflac_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdvdnav_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libgoom_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdshow_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdtstofloat32_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libbda_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liblibmpeg2_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdvdread_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdvbsub_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libatmo_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libfreetype_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi420_rgb_sse2_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\libvlc.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libhttp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libkate_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liblibass_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libasf_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libavcodec_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_mms_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libavi_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libid3tag_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_http_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi420_rgb_mmx_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libflacsys_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcmml_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_rtmp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liba52tofloat32_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_realrtsp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdeinterlace_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcdda_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libblend_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaudioscrobbler_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaudio_format_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_ftp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdirect3d_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi420_rgb_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libequalizer_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_filter_timeshift_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_smb_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_filter_record_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi420_yuy2_sse2_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libbandlimited_resampler_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libhotkeys_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libadjust_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi422_yuy2_sse2_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdmo_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libglwin32_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaraw_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libconverter_float_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libgradient_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liblogo_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaout_directx_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcrop_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcc_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libadpcm_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libextract_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi420_yuy2_mmx_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdolby_surround_decoder_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmagnify_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdummy_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_directory_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmarq_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi422_yuy2_mmx_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcinepak_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_output_udp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi422_yuy2_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi420_yuy2_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdts_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liblogger_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libheadphone_channel_mixer_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libexport_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcroppadd_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libgaussianblur_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libfake_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liberase_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcvdsub_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libclone_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libbluescreen_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmjpeg_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libgestures_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liba52_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libimage_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_output_http_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liblinear_resampler_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcolorthres_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcdg_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libblendbench_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaout_file_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaiff_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdtssys_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_filter_dump_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmemcpymmxext_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmemcpymmx_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmemcpy3dn_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi422_i420_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libcanvas_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_file_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_fake_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liba52sys_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libm4a_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liblpcm_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libgrey_yuv_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libgrain_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libfloat32_mixer_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdtstospdif_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libau_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libalphamask_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_udp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_filter_bandwidth_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libm4v_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi420_ymga_mmx_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libh264_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdemuxdump_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libconverter_fixed_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_output_file_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libchain_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_tcp_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libinvert_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libfolder_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libdemux_cdg_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\liba52tospdif_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libi420_ymga_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libmemcpy_plugin.dll ()
MOD - C:\Program Files (x86)\GmoteServer\bin\VLC\plugins\libaccess_output_dummy_plugin.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (uvnc_service) – C:\Program Files\UltraVNC\winvnc.exe (UltraVNC)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (HPClientSvc) – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (WiMAXAppSrv) – C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe (Intel® Corporation)
SRV:64bit: - (DMAgent) – C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe (Red Bend Ltd.)
SRV:64bit: - (TabletServiceWacom) – C:\Windows\SysNative\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (WysePocketCloud) – C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\PocketCloudService.exe ()
SRV - (Akamai) – c:\program files (x86)\common files\akamai/netsession_win_b427739.dll ()
SRV - (TeamViewer7) – C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (2X SecureClientGateway) – C:\Program Files (x86)\2X\ApplicationServer\2XProxyGateway.exe (2X Software Ltd.)
SRV - (2X Redundancy Service) – C:\Program Files (x86)\2X\ApplicationServer\2XRedundancy.exe (2X Software Ltd.)
SRV - (2X Publishing Agent) – C:\Program Files (x86)\2X\ApplicationServer\2XController.exe (2X Software Ltd.)
SRV - (2X Terminal Server Agent) – C:\Program Files (x86)\2X\ApplicationServer\2XAgent.exe (2X Software Ltd.)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (MotoHelper) – C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (HideMyIpSRV) – C:\Program Files (x86)\Hide My IP\HideMyIpSrv.exe (Hide My IP)
SRV - (VMnetDHCP) – C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (VMUSBArbService) – C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (RoxioNow Service) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
SRV - (ufad-ws60) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe (VMware, Inc.)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (SSScsiSV) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (SonicStage Back-End Service) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (NetMDSB) – C:\Program Files (x86)\Sony\MD Simple Burner\NetMDSB.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (NETwNs64) ___ Intel® – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (pneteth) – C:\Windows\SysNative\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (NETw5s64) Intel® – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (motccgp) – C:\Windows\SysNative\drivers\motccgp.sys (Motorola)
DRV:64bit: - (motmodem) – C:\Windows\SysNative\drivers\motmodem.sys (Motorola)
DRV:64bit: - (vmx86) – C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (vmkbd) – C:\Windows\SysNative\drivers\VMkbd.sys (VMware, Inc.)
DRV:64bit: - (VMnetuserif) – C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:64bit: - (hcmon) – C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:64bit: - (vmusb) – C:\Windows\SysNative\drivers\vmusb.sys (VMware, Inc.)
DRV:64bit: - (VMnetBridge) – C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:64bit: - (VMnetAdapter) – C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:64bit: - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (cbfs3) – C:\Windows\SysNative\drivers\cbfs3.sys (EldoS Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (CbFs) – C:\Windows\SysNative\drivers\cbfs64.sys (EldoS Corporation)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (wdkmd) – C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (kl2) – C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (bpmp) Intel® Centrino® – C:\Windows\SysNative\drivers\bpmp.sys (Intel Corporation)
DRV:64bit: - (bpusb) – C:\Windows\SysNative\drivers\bpusb.sys (Intel Corporation)
DRV:64bit: - (bpenum) – C:\Windows\SysNative\drivers\bpenum.sys (Intel Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (SCDEmu) – C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV:64bit: - (Motousbnet) – C:\Windows\SysNative\drivers\Motousbnet.sys (Motorola)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8187) – C:\Windows\SysNative\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (motandroidusb) – C:\Windows\SysNative\drivers\motoandroid.sys (Motorola)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (motccgpfl) – C:\Windows\SysNative\drivers\motccgpfl.sys (Motorola)
DRV:64bit: - (BTCFilterService) – C:\Windows\SysNative\drivers\motfilt.sys (Motorola Inc)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (MotoSwitchService) – C:\Windows\SysNative\drivers\motswch.sys (Motorola)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - (vstor2-ws60) – C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys (VMware, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s;=…hTerms}&f;=4

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Facemoods Search"
FF - prefs.js..browser.search.selectedEngine: "Facemoods Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@photoproduct.rocketlife.com/RocketLife App Viewer;version=0.8: File not found
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/10/25 02:17:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2011/05/01 16:58:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\FFExt\[removed] [2011/06/04 14:52:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\FFExt\[removed] [2011/06/04 14:52:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/12/18 15:47:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/03/31 14:08:19 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2011/12/30 03:18:02 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\nrsi313n.default\extensions
[2011/12/30 03:18:02 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\nrsi313n.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/12/29 18:34:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/04/20 19:47:47 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/29 18:34:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2011/05/01 06:35:31 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
() (No name found) – C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NRSI313N.DEFAULT\EXTENSIONS\[removed]
[2011/12/18 15:47:55 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/12/18 15:47:53 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/04/26 22:36:53 | 000,002,048 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
[2011/12/18 15:47:53 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: facemoods (Enabled)
CHR - default_search_provider: search_url = http://start.facemoods.com/?a=ddrnw&s;=…hTerms}&f;=4
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60129.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\14.0.835.202\gears.dll
CHR - plugin: Windows Live Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.1.1_0\
CHR - Extension: AT_GoodSmileCo = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aecfjhbbloiepdanbklnmimlknahlfih\2_1\
CHR - Extension: Skype Extension = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7280_0\
CHR - Extension: Poppit = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\

O1 HOSTS File: ([2010/05/13 17:53:40 | 000,001,204 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Storage Mount Notification) - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Storage Mount Notification) - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [IntelWirelessWiMAX] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PocketCloud Location] C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe ()
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [vmware-tray] C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKLM..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk ()
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Owner\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [BitTorrent] C:\Program Files (x86)\BitTorrent\BitTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [Remote Trackpad Server] C:\Program Files (x86)\Remote Trackpad Server\RemoteTrackpadServer.exe ()
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - HKCU..\Run: [uTorrent] "C:\Users\Owner\Desktop\utorrent.exe" File not found
O4 - HKCU..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk ()
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O9:64bit: - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000016 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Windows\SysNative\HMIPCore64.dll (Hide My IP)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysWow64\HMIPCore.dll (Hide My IP)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{483AC147-E537-47B8-925A-BD0E606FD020}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EEB0FB26-9366-481A-A8D5-77F806FAA72C}: NameServer = 172.25.129.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O21:64bit: - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {AFBDFF94-346C-4C3D-AC24-3DA0B41BB6CD} - C:\Program Files (x86)\2X\ApplicationServer\x64\TUXUrlHandler.dll (2X Software Ltd.)
O28 - HKLM ShellExecuteHooks: {AFBDFF94-346C-4C3D-AC24-3DA0B41BB6CD} - C:\Program Files (x86)\2X\ApplicationServer\TUXUrlHandler.dll (2X Software Ltd.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/05/14 18:32:48 | 000,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2011/04/15 18:47:15 | 000,000,000 | —- | M] () - Z:\Drag files here.txt – [ FAT32 ]
O33 - MountPoints2\{78e4f27e-ebbc-11e0-80f8-8bccbf16f33c}\Shell - "" = AutoRun
O33 - MountPoints2\{78e4f27e-ebbc-11e0-80f8-8bccbf16f33c}\Shell\AutoRun\command - "" = G:\setup.exe -a
O33 - MountPoints2\{d55deae5-6935-11e0-979e-002315c20f24}\Shell - "" = AutoRun
O33 - MountPoints2\{d55deae5-6935-11e0-979e-002315c20f24}\Shell\AutoRun\command - "" = G:\setup.exe -a
O33 - MountPoints2\{f4f5e17e-72fa-11e0-82c4-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f4f5e17e-72fa-11e0-82c4-806e6f6e6963}\Shell\AutoRun\command - "" = G:\unlock.exe autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.VMnc - C:\Windows\SysWow64\vmnc.dll (VMware, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/01 23:03:53 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/01/01 15:12:13 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/01/01 12:34:41 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\registry backups
[2012/01/01 12:30:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNTgui
[2012/01/01 12:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\KRtech
[2012/01/01 12:29:16 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\ERUNTgui
[2012/01/01 12:06:02 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/01/01 12:06:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/12/31 15:20:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2011/12/31 11:54:47 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\RA
[2011/12/30 19:13:43 | 000,000,000 | —D | C] – C:\HP_TOOLS_mountHPSF
[2011/12/30 13:35:39 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No-IP DUC
[2011/12/30 13:35:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\No-IP
[2011/12/30 12:51:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PuTTY
[2011/12/30 12:51:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\PuTTY
[2011/12/30 03:26:47 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\UltraVNC
[2011/12/30 03:19:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraVNC
[2011/12/30 03:19:47 | 000,000,000 | —D | C] – C:\Program Files\UltraVNC
[2011/12/30 03:13:56 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\APN
[2011/12/30 02:54:39 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\ElevatedDiagnostics
[2011/12/30 00:18:33 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\LogMeIn
[2011/12/30 00:18:27 | 000,087,456 | —- | C] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIRfsClientNP.dll
[2011/12/30 00:18:27 | 000,072,216 | —- | C] (LogMeIn, Inc.) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys
[2011/12/30 00:18:27 | 000,034,688 | —- | C] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIport.dll
[2011/12/30 00:18:25 | 000,080,768 | —- | C] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIinit.dll
[2011/12/30 00:18:21 | 000,000,000 | —D | C] – C:\ProgramData\LogMeIn
[2011/12/30 00:18:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn
[2011/12/29 18:34:44 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/12/29 18:34:44 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/12/29 18:34:44 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/12/29 17:32:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bonjour Print Services
[2011/12/29 17:32:00 | 000,000,000 | —D | C] – C:\Program Files\Bonjour Print Services
[2011/12/29 17:31:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\Apple
[2011/12/29 17:31:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/12/29 17:31:24 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/12/29 17:31:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/12/29 17:31:24 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/12/29 17:26:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\AirMouse
[2011/12/29 17:24:28 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\Downloaded Installations
[2011/12/29 16:30:39 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\TeamViewer
[2011/12/29 01:27:22 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\RemoteTrackpadServer
[2011/12/29 01:23:32 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Remote Trackpad Server
[2011/12/29 01:23:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Remote Trackpad Server
[2011/12/28 16:34:22 | 000,810,888 | —- | C] (2X Software Ltd.) – C:\Windows\SysNative\memshell.exe
[2011/12/28 16:34:09 | 000,783,752 | —- | C] (2X Software Ltd.) – C:\Windows\SysNative\2XUnivPrnPM.dll
[2011/12/28 16:33:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2X
[2011/12/28 16:33:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\2X
[2011/12/28 16:23:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wyse
[2011/12/28 16:23:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wyse
[2011/12/28 16:08:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\TeamViewer
[2011/12/25 21:40:40 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\Droid Recordings
[2011/12/25 21:39:09 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\Wigle
[2011/12/19 16:06:23 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\sue wong and gz
[2011/12/19 01:09:57 | 000,000,000 | —D | C] – C:\Program Files\Motorola Inc
[2011/12/19 00:34:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Motorola
[2011/12/18 16:40:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\BitTorrent
[2011/12/18 16:39:37 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\BitTorrent
[2011/12/15 18:18:04 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\Pics of Sue Wong
[2011/12/14 22:51:50 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/12/14 22:28:37 | 000,000,000 | -HSD | C] – C:\Windows\BitLockerDiscoveryVolumeContents
[2011/12/14 22:28:37 | 000,000,000 | —D | C] – C:\Windows\RemotePackages
[2011/12/14 22:28:37 | 000,000,000 | —D | C] – C:\Windows\CSC
[2011/12/14 21:40:46 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/14 21:40:45 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/14 21:40:44 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/14 21:40:44 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/14 21:40:44 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/14 21:40:44 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/14 21:40:43 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/14 21:40:42 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/12/14 21:40:42 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/14 21:40:42 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/12/14 21:40:41 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/12/14 21:34:41 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/12/14 21:34:41 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/12/14 21:34:41 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/12/14 21:34:41 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/12/14 21:34:38 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/14 21:34:26 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/12/14 21:34:25 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/12/14 21:33:48 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/14 21:33:47 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/14 21:09:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\PackageAware
[2011/12/12 15:40:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\vlc
[2011/12/12 15:26:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Transcribe!
[2011/12/12 15:26:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Transcribe!
[2011/12/12 15:14:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FastStone Player
[2011/12/12 15:14:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Player
[2011/12/12 15:14:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\FastStone Player
[2011/12/12 14:46:54 | 000,424,296 | —- | C] (Hide My IP) – C:\Windows\SysNative\HMIPCore64.dll
[2011/12/12 14:46:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hide My IP
[2011/12/12 14:46:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Hide My IP
[65 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/01 23:19:34 | 000,003,866 | —- | M] () – C:\Users\Owner\Desktop\Attach.zip
[2012/01/01 23:05:09 | 000,625,664 | —- | M] () – C:\Users\Owner\Desktop\dds.scr
[2012/01/01 23:04:10 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2012/01/01 22:58:59 | 000,019,013 | —- | M] () – C:\Users\Owner\Desktop\run as root
[2012/01/01 22:51:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1638959737-4176312477-2179020440-1000UA.job
[2012/01/01 22:49:17 | 000,018,516 | —- | M] () – C:\Users\Owner\Desktop\zeus
[2012/01/01 20:15:26 | 000,016,226 | —- | M] () – C:\Users\Owner\Desktop\logosreal.gif
[2012/01/01 18:51:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1638959737-4176312477-2179020440-1000Core.job
[2012/01/01 15:33:48 | 000,007,599 | —- | M] () – C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2012/01/01 12:49:06 | 000,027,488 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/01 12:49:06 | 000,027,488 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/01 12:45:24 | 000,746,862 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/01 12:45:24 | 000,638,960 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/01/01 12:45:24 | 000,111,912 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/01/01 12:39:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/01 12:39:52 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2012/01/01 12:39:03 | 002,621,440 | -HS- | M] () – C:\Users\Owner\ntuser.bak
[2012/01/01 12:30:47 | 000,001,110 | —- | M] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\ERUNTgui.lnk
[2012/01/01 12:06:02 | 000,002,975 | —- | M] () – C:\Users\Owner\Desktop\HiJackThis.lnk
[2012/01/01 11:57:01 | 001,957,400 | —- | M] () – C:\Users\Owner\Desktop\ERUNTgui.zip
[2012/01/01 11:43:58 | 001,402,880 | —- | M] () – C:\Users\Owner\Desktop\HiJackThis(2).msi
[2011/12/30 12:51:27 | 000,000,951 | —- | M] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PuTTY.lnk
[2011/12/30 12:20:37 | 000,000,332 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOwner.job
[2011/12/30 00:18:24 | 000,001,024 | —- | M] () – C:\.rnd
[2011/12/30 00:15:15 | 013,143,482 | —- | M] () – C:\Users\Owner\Desktop\LogMeIn.exe
[2011/12/29 18:34:28 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2011/12/29 18:34:28 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/12/29 18:34:28 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/12/29 18:34:28 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/12/29 16:19:53 | 000,020,422 | —- | M] () – C:\Users\Owner\Desktop\andReceiver-1.1.3-eng.zip
[2011/12/29 02:34:42 | 000,679,313 | —- | M] () – C:\Users\Owner\Desktop\PRemoteDroid-Server (2).zip
[2011/12/29 02:32:59 | 000,679,313 | —- | M] () – C:\Users\Owner\Desktop\PRemoteDroid-Server.zip
[2011/12/29 01:22:16 | 000,479,232 | —- | M] () – C:\Users\Owner\Desktop\RemoteTrackpadServerInstaller_v1.1.msi
[2011/12/28 21:06:04 | 000,185,535 | —- | M] () – C:\Users\Owner\Desktop\google-checkout-zencart-v1.4.7.zip
[2011/12/28 20:44:34 | 000,121,368 | —- | M] () – C:\Users\Owner\Desktop\stock_by_attributes_1-4-14.zip
[2011/12/28 20:43:58 | 000,105,128 | —- | M] () – C:\Users\Owner\Desktop\stock_by_attributes_multiadd_with_table_filter__1.zip
[2011/12/28 20:42:16 | 000,231,733 | —- | M] () – C:\Users\Owner\Desktop\simple_seo_url_3-5-8.zip
[2011/12/28 20:35:38 | 000,096,755 | —- | M] () – C:\Users\Owner\Desktop\ultimate_seo_urls_2-110.zip
[2011/12/28 20:27:14 | 000,596,119 | —- | M] () – C:\Users\Owner\Desktop\3.8.5.zip
[2011/12/28 16:37:26 | 000,000,083 | —- | M] () – C:\Windows\2XConsole.INI
[2011/12/28 16:34:25 | 000,004,828 | —- | M] () – C:\Windows\Sandboxie.ini
[2011/12/28 11:10:05 | 000,691,065 | —- | M] () – C:\Users\Owner\Desktop\IMG_1741.MOV
[2011/12/27 18:21:33 | 000,001,097 | —- | M] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2011/12/19 01:09:31 | 002,443,264 | —- | M] () – C:\Users\Owner\Desktop\Motorola_End_User_Driver_Installation_5.2.0_64bit.msi
[2011/12/18 21:07:45 | 031,806,492 | —- | M] () – C:\Users\Owner\Desktop\Pics of Sue Wong.zip
[2011/12/18 16:40:43 | 000,000,951 | —- | M] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
[2011/12/18 16:40:43 | 000,000,927 | —- | M] () – C:\Users\Public\Desktop\BitTorrent.lnk
[2011/12/15 15:54:16 | 000,002,401 | —- | M] () – C:\Users\Owner\Desktop\Google Chrome.lnk
[2011/12/15 10:24:27 | 000,000,017 | —- | M] () – C:\Windows\SysWow64\shortcut_ex.dat
[2011/12/14 22:51:53 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/14 22:41:13 | 000,000,000 | -H– | M] () – C:\Users\Owner\Documents\Default.rdp
[2011/12/14 21:54:06 | 004,838,136 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/14 21:42:14 | 000,763,558 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/12/13 00:36:39 | 138,932,289 | —- | M] () – C:\Users\Owner\Desktop\backup-12.13.2011_01-09-41_sapphire.tar.gz
[2011/12/12 15:26:30 | 000,001,002 | —- | M] () – C:\Users\Owner\Desktop\Transcribe!.lnk
[2011/12/12 15:23:06 | 000,007,680 | —- | M] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/12 15:14:15 | 000,001,921 | —- | M] () – C:\Users\Owner\Desktop\FastStone Player.lnk
[2011/12/12 14:46:48 | 000,001,009 | —- | M] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Hide My IP.lnk
[2011/12/12 14:46:48 | 000,000,985 | —- | M] () – C:\Users\Owner\Desktop\Hide My IP.lnk
[2011/12/10 15:24:08 | 000,023,152 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/12/08 02:01:10 | 000,000,342 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOWNER-HP$.job
[2011/12/07 18:22:48 | 000,087,456 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIRfsClientNP.dll
[2011/12/07 18:22:36 | 000,080,768 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIinit.dll
[2011/12/07 18:22:36 | 000,034,688 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIport.dll
[2011/12/07 09:56:49 | 000,000,997 | —- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011/12/06 10:55:28 | 126,741,249 | —- | M] () – C:\Users\Owner\Desktop\Inta Omry Oud Lesson.wmv
[65 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/01 23:19:34 | 000,003,866 | —- | C] () – C:\Users\Owner\Desktop\Attach.zip
[2012/01/01 23:04:56 | 000,625,664 | —- | C] () – C:\Users\Owner\Desktop\dds.scr
[2012/01/01 22:58:59 | 000,019,013 | —- | C] () – C:\Users\Owner\Desktop\run as root
[2012/01/01 22:49:17 | 000,018,516 | —- | C] () – C:\Users\Owner\Desktop\zeus
[2012/01/01 20:15:26 | 000,016,226 | —- | C] () – C:\Users\Owner\Desktop\logosreal.gif
[2012/01/01 12:30:47 | 000,001,110 | —- | C] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\ERUNTgui.lnk
[2012/01/01 12:06:02 | 000,002,975 | —- | C] () – C:\Users\Owner\Desktop\HiJackThis.lnk
[2012/01/01 11:56:57 | 001,957,400 | —- | C] () – C:\Users\Owner\Desktop\ERUNTgui.zip
[2012/01/01 11:43:31 | 001,402,880 | —- | C] () – C:\Users\Owner\Desktop\HiJackThis(2).msi
[2011/12/30 12:51:27 | 000,000,951 | —- | C] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PuTTY.lnk
[2011/12/30 00:18:04 | 000,000,948 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn.lnk
[2011/12/30 00:13:57 | 013,143,482 | —- | C] () – C:\Users\Owner\Desktop\LogMeIn.exe
[2011/12/29 17:31:34 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/12/29 16:19:53 | 000,020,422 | —- | C] () – C:\Users\Owner\Desktop\andReceiver-1.1.3-eng.zip
[2011/12/29 02:34:41 | 000,679,313 | —- | C] () – C:\Users\Owner\Desktop\PRemoteDroid-Server (2).zip
[2011/12/29 02:32:59 | 000,679,313 | —- | C] () – C:\Users\Owner\Desktop\PRemoteDroid-Server.zip
[2011/12/29 01:22:15 | 000,479,232 | —- | C] () – C:\Users\Owner\Desktop\RemoteTrackpadServerInstaller_v1.1.msi
[2011/12/28 21:06:04 | 000,185,535 | —- | C] () – C:\Users\Owner\Desktop\google-checkout-zencart-v1.4.7.zip
[2011/12/28 20:44:34 | 000,121,368 | —- | C] () – C:\Users\Owner\Desktop\stock_by_attributes_1-4-14.zip
[2011/12/28 20:43:58 | 000,105,128 | —- | C] () – C:\Users\Owner\Desktop\stock_by_attributes_multiadd_with_table_filter__1.zip
[2011/12/28 20:42:15 | 000,231,733 | —- | C] () – C:\Users\Owner\Desktop\simple_seo_url_3-5-8.zip
[2011/12/28 20:35:38 | 000,096,755 | —- | C] () – C:\Users\Owner\Desktop\ultimate_seo_urls_2-110.zip
[2011/12/28 20:27:00 | 000,596,119 | —- | C] () – C:\Users\Owner\Desktop\3.8.5.zip
[2011/12/28 16:37:26 | 000,000,083 | —- | C] () – C:\Windows\2XConsole.INI
[2011/12/28 16:08:39 | 000,001,138 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2011/12/28 11:09:55 | 000,691,065 | —- | C] () – C:\Users\Owner\Desktop\IMG_1741.MOV
[2011/12/27 18:21:33 | 000,001,097 | —- | C] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2011/12/19 01:09:14 | 002,443,264 | —- | C] () – C:\Users\Owner\Desktop\Motorola_End_User_Driver_Installation_5.2.0_64bit.msi
[2011/12/18 20:57:07 | 031,806,492 | —- | C] () – C:\Users\Owner\Desktop\Pics of Sue Wong.zip
[2011/12/18 16:40:43 | 000,000,951 | —- | C] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
[2011/12/18 16:40:43 | 000,000,927 | —- | C] () – C:\Users\Public\Desktop\BitTorrent.lnk
[2011/12/15 10:24:27 | 000,000,017 | —- | C] () – C:\Windows\SysWow64\shortcut_ex.dat
[2011/12/14 22:41:13 | 000,000,000 | -H– | C] () – C:\Users\Owner\Documents\Default.rdp
[2011/12/14 22:27:57 | 000,051,867 | —- | C] () – C:\Windows\Ultimate.xml
[2011/12/13 00:29:17 | 138,932,289 | —- | C] () – C:\Users\Owner\Desktop\backup-12.13.2011_01-09-41_sapphire.tar.gz
[2011/12/12 15:26:30 | 000,001,002 | —- | C] () – C:\Users\Owner\Desktop\Transcribe!.lnk
[2011/12/12 15:14:15 | 000,001,921 | —- | C] () – C:\Users\Owner\Desktop\FastStone Player.lnk
[2011/12/12 14:46:48 | 000,001,009 | —- | C] () – C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Hide My IP.lnk
[2011/12/12 14:46:48 | 000,000,985 | —- | C] () – C:\Users\Owner\Desktop\Hide My IP.lnk
[2011/12/11 20:39:41 | 002,471,959 | —- | C] () – C:\Users\Owner\Desktop\NOTATION (2).pdf
[2011/12/06 10:53:26 | 126,741,249 | —- | C] () – C:\Users\Owner\Desktop\Inta Omry Oud Lesson.wmv
[2011/09/28 16:29:47 | 000,000,132 | —- | C] () – C:\Users\Owner\AppData\Roaming\Adobe AIFF Format CS5 Prefs
[2011/08/30 00:27:51 | 000,532,480 | —- | C] () – C:\Windows\SysWow64\CddbPlaylist2Sony.dll
[2011/05/14 18:42:17 | 000,000,848 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2011/05/14 02:21:53 | 000,001,456 | —- | C] () – C:\Users\Owner\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/04/28 11:21:13 | 000,001,854 | —- | C] () – C:\Users\Owner\AppData\Roaming\GhostObjGAFix.xml
[2011/04/27 16:04:52 | 000,001,620 | —- | C] () – C:\Windows\SysWow64\WLAN.INI
[2011/04/27 03:16:58 | 000,007,680 | —- | C] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/23 15:30:33 | 000,571,287 | —- | C] () – C:\ProgramData\bdinstall.bin
[2011/04/22 11:27:16 | 000,000,036 | —- | C] () – C:\Users\Owner\AppData\Local\housecall.guid.cache
[2011/04/22 03:48:04 | 000,004,828 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/04/22 00:08:16 | 000,007,599 | —- | C] () – C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2011/04/20 19:51:57 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/04/20 17:34:09 | 000,000,378 | —- | C] () – C:\Windows\pagebreeze.ini
[2011/04/20 17:34:09 | 000,000,069 | —- | C] () – C:\Windows\formbreeze.ini
[2011/04/04 23:42:20 | 000,763,558 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/17 02:26:22 | 000,066,856 | —- | C] () – C:\Windows\SysWow64\SynTPEnhPS.dll
[2010/10/25 01:37:42 | 000,000,299 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2010/10/25 01:37:42 | 000,000,240 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini
[2010/10/16 08:35:25 | 000,000,188 | —- | C] () – C:\Windows\SysWow64\HPWA.ini
[2010/09/21 10:30:44 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2010/07/28 15:08:44 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/28 15:08:42 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/07/28 15:08:40 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/07/28 14:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/28 14:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:59:36 | 001,498,564 | —- | C] () – C:\Windows\SysWow64\igkrng400.bin
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/05/14 18:37:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Autodesk
[2011/04/24 12:05:03 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\BitDefender
[2012/01/01 12:43:27 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\BitTorrent
[2011/03/31 18:55:10 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Blio
[2011/10/19 09:53:52 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/20 13:08:57 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/05/03 22:21:31 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1
[2011/03/30 05:45:55 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\DigitalPersona
[2012/01/01 12:43:31 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Dropbox
[2011/04/13 04:29:14 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\FileZilla
[2012/01/01 15:20:31 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Gmote
[2011/09/23 21:09:13 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Hide IP NG
[2011/09/01 18:04:53 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\IrfanView
[2011/04/08 16:05:02 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\JonathanLeger.com
[2011/04/13 17:37:51 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/09/07 00:01:32 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Nik Software
[2011/05/06 15:32:16 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Notepad++
[2011/04/21 01:46:49 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\OpenCandy
[2011/03/30 06:17:09 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\PictureMover
[2011/04/23 15:33:15 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\QuickScan
[2011/04/20 19:45:19 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Simple Star
[2011/12/18 23:56:25 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\SoftGrid Client
[2011/05/01 23:29:15 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/03/30 06:16:06 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Stardock
[2011/12/29 16:35:32 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\TeamViewer
[2011/04/04 23:43:22 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\TP
[2011/05/05 16:56:30 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\uTorrent
[2011/04/13 14:42:10 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Windows Live Writer
[2011/04/30 11:41:40 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Wuala
[2012/01/01 12:43:59 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\ZumoDrive
[2011/12/30 12:20:37 | 000,032,598 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2011/12/30 00:18:24 | 000,001,024 | —- | M] () – C:\.rnd
[2011/10/12 15:21:36 | 000,000,094 | —- | M] () – C:\AS.url
[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2011/04/13 04:33:12 | 000,000,710 | —- | M] () – C:\defaults
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/04/13 04:33:12 | 000,000,000 | —- | M] () – C:\grid
[2012/01/01 12:39:52 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:44:20 | 000,855,040 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2012/01/01 12:39:55 | 4083,007,488 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:50:40 | 001,927,956 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:53:12 | 000,242,176 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/11 09:33:08 | 000,000,221 | -HS- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/12/30 00:15:15 | 013,143,482 | —- | M] () – C:\Users\Owner\Desktop\LogMeIn.exe
[2012/01/01 23:04:10 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


Thanks in Advance :)
Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI