This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

BitTorrent Bar & other malware removal [Solved]

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I installed BitTorrent in a flash of not thinking and with it came BitTorrentBar. I've removed it from Programs and Add-ons for Chrome & FF (didn't see it in IE) but want to make sure all of the associated files are removed - I am still seeing search redirects to search-results in the FF browser bar.

I'm posting the logs below, thanks in advance for any help.

~~~~
OTL
~~~~

OTL logfile created on: 1/18/2012 12:46:11 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Bianca\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.73 Gb Total Physical Memory | 2.02 Gb Available Physical Memory | 54.12% Memory free
7.47 Gb Paging File | 5.54 Gb Available in Paging File | 74.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 454.39 Gb Total Space | 386.12 Gb Free Space | 84.97% Space Free | Partition Type: NTFS
Drive D: | 198.36 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: BIANCA-PC | User Name: Bianca | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Bianca\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\avutil-51.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\avformat-53.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\gcswf32.dll ()
MOD - C:\Program Files (x86)\Webroot\Security\Current\Framework\frameworkresources.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WiMAXAppSrv) – C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe (Intel® Corporation)
SRV:64bit: - (DMAgent) – C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe (Red Bend Ltd.)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (Thpsrv) – C:\Windows\SysNative\ThpSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (WRConsumerService) – C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) – C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (BrYNSvc) – C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (TMachInfo) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (ssidrv) – C:\Windows\SysNative\drivers\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (ssfmonm) – C:\Windows\SysNative\drivers\ssfmonm.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (NETwNs64) ___ Intel® – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (wdkmd) – C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (bpmp) Intel® Centrino® – C:\Windows\SysNative\drivers\bpmp.sys (Intel Corporation)
DRV:64bit: - (bpusb) – C:\Windows\SysNative\drivers\bpusb.sys (Intel Corporation)
DRV:64bit: - (bpenum) – C:\Windows\SysNative\drivers\bpenum.sys (Intel Corporation)
DRV:64bit: - (tos_sps64) – C:\Windows\SysNative\drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (risdpcie) – C:\Windows\SysNative\drivers\risdpe64.sys (REDC)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (e1kexpress) Intel® – C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Thpevm) – C:\Windows\SysNative\drivers\Thpevm.sys (TOSHIBA Corporation)
DRV:64bit: - (Thpdrv) – C:\Windows\SysNative\drivers\thpdrv.sys (TOSHIBA Corporation)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (Ser2pl) – C:\Windows\SysNative\drivers\ser2pl64.sys (Prolific Technology Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…D&bmod;=TSND

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://start.toshiba.com/g/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/01/18 12:41:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/18 18:56:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/01/18 12:41:52 | 000,000,000 | —D | M]

[2011/08/10 16:57:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Bianca\AppData\Roaming\Mozilla\Extensions
[2012/01/18 11:18:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\extensions
[2012/01/18 11:59:10 | 000,000,000 | —D | M] (No name found) – C:\Users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/08/04 21:10:09 | 000,002,501 | —- | M] () – C:\Users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\searchplugins\SearchResults.xml
[2011/11/08 14:11:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/09/18 18:56:11 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/08/25 13:59:32 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/08/04 21:10:09 | 000,002,501 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Bianca\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Bianca\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Bianca\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Write Space = C:\Users\Bianca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aimodnlfiikjjnmdchihablmkdeobhad\0.60_0\
CHR - Extension: Write Space = C:\Users\Bianca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aimodnlfiikjjnmdchihablmkdeobhad\0.60_0\~
CHR - Extension: YouTube = C:\Users\Bianca\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Users\Bianca\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Pin yer interest! = C:\Users\Bianca\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbfjhllmkehmdajjlkolhdjjlfcmmlpl\3.0_0\
CHR - Extension: Andrew@ChromeFans = C:\Users\Bianca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdkkfheckcdppiaiabobmennhijkknn\4.7.2_0\
CHR - Extension: bitly | a simple URL shortener = C:\Users\Bianca\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic\1.3.1.5_0\
CHR - Extension: Send from Gmail (by Google) = C:\Users\Bianca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc\1.12_0\
CHR - Extension: Gmail = C:\Users\Bianca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/10/07 13:28:22 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg64.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [IntelWirelessWiMAX] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [ThpSrv] C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\Toshiba\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TOSDCR] C:\Program Files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe ()
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [WebrootTrayApp] C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - Startup: C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DD41ED09-7755-4883-A6C6-3EE39E1D55B3}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EB847384-7E8F-4355-ACC1-1933C9B785C4}: DhcpNameServer = 192.168.2.1 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/09/25 21:00:00 | 000,000,064 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/18 12:27:16 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/01/18 11:59:49 | 000,518,144 | —- | C] (SteelWerX) – C:\windows\SWREG.exe
[2012/01/18 11:59:49 | 000,406,528 | —- | C] (SteelWerX) – C:\windows\SWSC.exe
[2012/01/18 11:59:49 | 000,060,416 | —- | C] (NirSoft) – C:\windows\NIRCMD.exe
[2012/01/18 11:59:18 | 000,000,000 | —D | C] – C:\Qoobox
[2012/01/18 11:58:00 | 004,387,138 | R— | C] (Swearware) – C:\Users\Bianca\Desktop\ComboFix.exe
[2012/01/18 11:53:38 | 004,713,472 | —- | C] (AVAST Software) – C:\Users\Bianca\Desktop\aswMBR.exe
[2012/01/18 10:59:20 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Bianca\Desktop\HiJackThis.exe
[2012/01/18 10:59:03 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Bianca\Desktop\OTL.exe
[2012/01/18 09:27:00 | 001,975,600 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Bianca\Desktop\TDSSKiller.exe
[2012/01/18 08:41:45 | 052,128,560 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\MRT.exe
[2012/01/16 12:05:47 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Roaming\ooVoo Details
[2012/01/16 12:05:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
[2012/01/16 12:05:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\ooVoo
[2012/01/10 21:47:59 | 001,572,864 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\quartz.dll
[2012/01/10 21:47:59 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\quartz.dll
[2012/01/10 21:47:59 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\qdvd.dll
[2012/01/10 21:47:59 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\qdvd.dll
[2012/01/10 21:47:58 | 000,918,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2012/01/10 21:47:58 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2012/01/10 21:47:56 | 001,731,920 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntdll.dll
[2012/01/10 21:47:56 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\packager.dll
[2012/01/10 21:47:56 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\packager.dll
[2012/01/10 10:30:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
[2012/01/10 10:30:35 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Local\Conduit
[2012/01/03 05:10:52 | 000,053,656 | —- | C] (Adobe Systems Inc) – C:\windows\SysNative\AdobePDF.dll
[2012/01/03 05:10:48 | 000,024,984 | —- | C] (Adobe Systems Inc.) – C:\windows\SysNative\AdobePDFUI.dll
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Users\Bianca\Documents\*.tmp files -> C:\Users\Bianca\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/18 12:43:39 | 000,015,792 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/18 12:43:39 | 000,015,792 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/18 12:41:53 | 000,002,037 | —- | M] () – C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2012/01/18 12:39:00 | 000,000,912 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/18 12:34:07 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/18 12:33:03 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/01/18 12:32:48 | 3007,647,744 | -HS- | M] () – C:\hiberfil.sys
[2012/01/18 12:20:40 | 005,038,712 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2012/01/18 11:58:23 | 004,387,138 | R— | M] (Swearware) – C:\Users\Bianca\Desktop\ComboFix.exe
[2012/01/18 11:56:44 | 001,975,600 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Bianca\Desktop\TDSSKiller.exe
[2012/01/18 11:54:18 | 004,713,472 | —- | M] (AVAST Software) – C:\Users\Bianca\Desktop\aswMBR.exe
[2012/01/18 11:48:31 | 000,625,664 | —- | M] () – C:\Users\Bianca\Desktop\dds.scr
[2012/01/18 10:59:16 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Bianca\Desktop\HiJackThis.exe
[2012/01/18 10:58:52 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Bianca\Desktop\OTL.exe
[2012/01/16 12:05:21 | 000,001,868 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[2012/01/13 15:19:23 | 000,001,456 | —- | M] () – C:\Users\Bianca\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/01/11 12:20:54 | 000,846,831 | —- | M] () – C:\Users\Bianca\Holiday2011.jpg
[2012/01/11 12:17:41 | 000,004,244 | —- | M] () – C:\Users\Bianca\Holiday2011
[2012/01/10 12:08:03 | 000,048,192 | —- | M] () – C:\Users\Bianca\Documents\mm_bc_finalv2_front.pdf
[2012/01/09 16:01:43 | 000,000,000 | -H– | M] () – C:\Users\Bianca\Documents\.BridgeLabelsAndRatings
[2012/01/04 17:15:16 | 052,128,560 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\MRT.exe
[2012/01/04 10:09:02 | 000,741,240 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2012/01/04 10:09:02 | 000,624,640 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2012/01/04 10:09:02 | 000,106,726 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2012/01/03 05:10:52 | 000,053,656 | —- | M] (Adobe Systems Inc) – C:\windows\SysNative\AdobePDF.dll
[2012/01/03 05:10:48 | 000,024,984 | —- | M] (Adobe Systems Inc.) – C:\windows\SysNative\AdobePDFUI.dll
[2011/12/21 15:11:52 | 000,001,033 | —- | M] () – C:\Users\Bianca\Desktop\Dropbox.lnk
[2011/12/21 15:11:52 | 000,001,013 | —- | M] () – C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Users\Bianca\Documents\*.tmp files -> C:\Users\Bianca\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/18 11:59:49 | 000,256,000 | —- | C] () – C:\windows\PEV.exe
[2012/01/18 11:59:49 | 000,208,896 | —- | C] () – C:\windows\MBR.exe
[2012/01/18 11:59:49 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2012/01/18 11:59:49 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2012/01/18 11:59:49 | 000,068,096 | —- | C] () – C:\windows\zip.exe
[2012/01/18 11:48:27 | 000,625,664 | —- | C] () – C:\Users\Bianca\Desktop\dds.scr
[2012/01/16 12:05:21 | 000,001,868 | —- | C] () – C:\Users\Public\Desktop\ooVoo.lnk
[2012/01/12 20:00:02 | 000,001,456 | —- | C] () – C:\Users\Bianca\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/01/11 12:21:10 | 000,846,831 | —- | C] () – C:\Users\Bianca\Holiday2011.jpg
[2012/01/11 12:18:11 | 000,004,244 | —- | C] () – C:\Users\Bianca\Holiday2011
[2012/01/10 12:08:03 | 000,048,192 | —- | C] () – C:\Users\Bianca\Documents\mm_bc_finalv2_front.pdf
[2012/01/09 16:01:43 | 000,000,000 | -H– | C] () – C:\Users\Bianca\Documents\.BridgeLabelsAndRatings
[2011/04/26 20:22:06 | 000,003,584 | —- | C] () – C:\Users\Bianca\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/25 14:58:02 | 000,030,424 | —- | C] () – C:\windows\SysWow64\wrLZMA.dll
[2011/03/12 21:36:12 | 000,743,534 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/03/11 09:24:37 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/07/28 20:08:46 | 000,127,868 | —- | C] () – C:\windows\SysWow64\igcompkrng575.bin
[2010/07/28 20:08:44 | 000,104,796 | —- | C] () – C:\windows\SysWow64\igfcg575m.bin
[2010/04/30 10:17:38 | 000,870,560 | —- | C] () – C:\windows\SysWow64\igkrng575.bin
[2010/04/30 09:42:24 | 000,208,896 | —- | C] () – C:\windows\SysWow64\iglhsip32.dll
[2010/04/30 09:42:24 | 000,143,360 | —- | C] () – C:\windows\SysWow64\iglhcp32.dll
[2009/07/13 21:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 18:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 18:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 16:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 15:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 13:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 13:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
[2005/01/16 23:10:16 | 000,045,056 | —- | C] () – C:\windows\SysWow64\BRTCPCON.DLL
[2004/08/08 23:00:42 | 000,000,114 | —- | C] () – C:\windows\SysWow64\BRLMW03A.INI

========== LOP Check ==========

[2011/07/26 11:10:09 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/03 09:56:33 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/01/18 12:37:12 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Dropbox
[2012/01/16 12:05:54 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\ooVoo Details
[2011/08/24 08:22:42 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\SoftGrid Client
[2012/01/18 10:24:29 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Spotify
[2011/09/26 14:29:18 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/11/09 14:22:14 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Toshiba
[2011/03/12 21:37:19 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\TP
[2011/03/08 20:24:09 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\WinBatch
[2011/04/19 11:40:24 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Windows Live Writer
[2011/12/19 10:11:47 | 000,032,628 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/19 12:08:44 | 000,018,153 | —- | M] () – C:\1020.log
[2009/07/13 17:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/07/29 17:29:57 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/01/18 12:32:48 | 3007,647,744 | -HS- | M] () – C:\hiberfil.sys
[2012/01/18 12:32:52 | 4010,201,088 | -HS- | M] () – C:\pagefile.sys
[2012/01/18 11:57:36 | 000,080,024 | —- | M] () – C:\TDSSKiller.2.7.5.0_18.01.2012_11.57.01_log.txt
[2 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2009/07/13 21:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 12:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 20:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/08 20:26:17 | 000,000,221 | -HS- | M] () – C:\Users\Bianca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/01/18 11:54:18 | 004,713,472 | —- | M] (AVAST Software) – C:\Users\Bianca\Desktop\aswMBR.exe
[2012/01/18 11:58:23 | 004,387,138 | R— | M] (Swearware) – C:\Users\Bianca\Desktop\ComboFix.exe
[2012/01/18 10:59:16 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Bianca\Desktop\HiJackThis.exe
[2012/01/18 10:58:52 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Bianca\Desktop\OTL.exe
[2012/01/18 11:56:44 | 001,975,600 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Bianca\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

~~~~
OTL Extras did not appear.

~~~~
HijackThis
~~~~

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:11:58 PM, on 1/18/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Bianca\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [TOSDCR] "%ProgramFiles%\TOSHIBA\PasswordUtility\TOSDCR.exe"
O4 - HKLM\..\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [WebrootTrayApp] "C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe"
O4 - HKLM\..\Run: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - .DEFAULT User Startup: Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (User 'Default user')
O4 - Startup: Dropbox.lnk = Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Red Bend Device Management Service (DMAgent) - Red Bend Ltd. - C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - Unknown owner - C:\windows\system32\ThpSrv.exe (file missing)
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Service (WiMAXAppSrv) - Intel® Corporation - C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe

–
End of file - 13564 bytes

~~~~
DDS
~~~~


.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 13:13:00.86 on Wed 01/18/2012
Internet Explorer: 8.0.7601.17514
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3824.1641 [GMT -8:00]
.
AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\system32\conhost.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\windows\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\ThpSrv.exe
C:\windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe
C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\taskhost.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Toshiba\TECO\Teco.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\igfxtray.exe
C:\windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\windows\system32\igfxext.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\SearchIndexer.exe
C:\Users\Bianca\Desktop\OTL.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\system32\NOTEPAD.EXE
C:\Users\Bianca\Desktop\HiJackThis.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Bianca\Desktop\dds.scr
C:\windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod;=TSND
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TOSHIBA Media Controller Plug-in: {f3c88694-effa-4d78-b409-54b7b2535b14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [AdobeBridge]
mRun: [TOSDCR] "%ProgramFiles%\TOSHIBA\PasswordUtility\TOSDCR.exe"
mRun: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun: [WebrootTrayApp] "C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe"
mRun: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
mRun: []
StartupFolder: C:\Users\Bianca\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver; - C:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg64.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [IntelWirelessWiMAX] "C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe" /tasktray /nosplash
mRun-x64: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun-x64: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun-x64: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun-x64: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun-x64: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
mRun-x64: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun-x64: [TosSENotify] "C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe"
mRun-x64: [ThpSrv] "C:\windows\system32\thpsrv" /logon
mRun-x64: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun-x64: [TosVolRegulator] "C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe"
mRun-x64: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun-x64: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun-x64: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
mRun-x64: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
mRun-x64: [IgfxTray] "C:\windows\system32\igfxtray.exe"
mRun-x64: [HotKeysCmds] "C:\windows\system32\hkcmd.exe"
mRun-x64: [Persistence] "C:\windows\system32\igfxpers.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn\components\WCFirefoxExtn.dll
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\Windows\System32\drivers\thpdrv.sys [2009-6-29 34880]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\Windows\System32\drivers\Thpevm.sys [2009-6-29 14784]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\Windows\System32\drivers\tos_sps64.sys [2010-11-22 482384]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2010-6-7 408576]
R2 risdpcie;risdpcie;C:\Windows\System32\drivers\risdpe64.sys [2010-11-22 81920]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264]
R2 ssfmonm;ssfmonm;C:\Windows\System32\drivers\ssfmonm.sys [2011-4-25 56920]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\Toshiba\TECO\TecoService.exe [2010-4-23 259440]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\Windows\System32\drivers\TVALZFL.sys [2009-6-19 14472]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-11-22 2320920]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe [2011-4-25 3997912]
R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2010-6-7 911872]
R2 WRConsumerService;Webroot Client Service;C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-9-10 3381184]
R3 bpenum;bpenum;C:\Windows\System32\drivers\bpenum.sys [2010-5-16 71168]
R3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\Windows\System32\drivers\bpmp.sys [2010-5-16 175104]
R3 bpusb;bpusb;C:\Windows\System32\drivers\bpusb.sys [2010-5-16 81920]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2010-11-22 295088]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-11-22 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-2-26 158976]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-2-3 271872]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETwNs64.sys [2010-10-18 8153088]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 PGEffect;Pangu effect driver;C:\Windows\System32\drivers\PGEffect.sys [2010-11-22 35008]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2010-9-14 760168]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2010-9-14 268648]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2010-9-14 25960]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2010-9-14 22376]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496]
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-11-22 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]
R3 TPCHSrv;TPCH Service;C:\Program Files\Toshiba\TPHM\TPCHSrv.exe [2010-5-10 836016]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2010-6-18 39832]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-29 136176]
S3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2011-5-25 245760]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-29 136176]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-10-19 340240]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-2-24 78336]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-2-24 181248]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-10-9 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-10 1255736]
.
=============== Created Last 30 ================
.
2012-01-18 20:39:11 69000 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{C7CA49D4-877B-40C4-909A-69F4AD35C167}\offreg.dll
2012-01-18 20:27:16 ——– d-s—w- C:\ComboFix
2012-01-18 19:59:49 98816 —-a-w- C:\windows\sed.exe
2012-01-18 19:59:49 518144 —-a-w- C:\windows\SWREG.exe
2012-01-18 19:59:49 256000 —-a-w- C:\windows\PEV.exe
2012-01-18 19:59:49 208896 —-a-w- C:\windows\MBR.exe
2012-01-17 22:28:16 8822856 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{C7CA49D4-877B-40C4-909A-69F4AD35C167}\mpengine.dll
2012-01-16 20:05:47 ——– d—–w- C:\Users\Bianca\AppData\Roaming\ooVoo Details
2012-01-16 20:05:19 ——– d—–w- C:\Program Files (x86)\ooVoo
2012-01-11 05:47:59 514560 —-a-w- C:\windows\SysWow64\qdvd.dll
2012-01-11 05:47:59 366592 —-a-w- C:\windows\System32\qdvd.dll
2012-01-11 05:47:59 1572864 —-a-w- C:\windows\System32\quartz.dll
2012-01-11 05:47:59 1328128 —-a-w- C:\windows\SysWow64\quartz.dll
2012-01-11 05:47:56 77312 —-a-w- C:\windows\System32\packager.dll
2012-01-11 05:47:56 67072 —-a-w- C:\windows\SysWow64\packager.dll
2012-01-11 05:47:56 1731920 —-a-w- C:\windows\System32\ntdll.dll
2012-01-11 05:47:56 1292080 —-a-w- C:\windows\SysWow64\ntdll.dll
2012-01-10 18:30:37 ——– d—–w- C:\Program Files (x86)\Conduit
2012-01-10 18:30:35 ——– d—–w- C:\Users\Bianca\AppData\Local\Conduit
2012-01-03 13:10:52 53656 —-a-w- C:\windows\System32\AdobePDF.dll
2012-01-03 13:10:48 24984 —-a-w- C:\windows\System32\AdobePDFUI.dll
2012-01-03 13:10:44 182672 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
.
==================== Find3M ====================
.
2011-11-24 04:52:09 3145216 —-a-w- C:\windows\System32\win32k.sys
2011-11-10 18:35:42 414368 —-a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-05 05:41:43 1188864 —-a-w- C:\windows\System32\wininet.dll
2011-11-05 05:32:50 2048 —-a-w- C:\windows\System32\tzres.dll
2011-11-05 04:35:00 981504 —-a-w- C:\windows\SysWow64\wininet.dll
2011-11-05 04:26:03 2048 —-a-w- C:\windows\SysWow64\tzres.dll
2011-11-05 03:32:47 1638912 —-a-w- C:\windows\System32\mshtml.tlb
2011-11-05 02:48:51 1638912 —-a-w- C:\windows\SysWow64\mshtml.tlb
2011-10-26 05:21:20 43520 —-a-w- C:\windows\System32\csrsrv.dll
2011-10-24 16:23:32 72080 —-a-w- C:\Users\Bianca\g2mdlhlpx.exe
.
============= FINISH: 13:13:48.47 ===============

Thank you!
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

First we need to make all files and folders VISIBLE:

  • Go to Start >> Control Panel >> Folder Options >> View
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with ok
———-


Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

Sorry about the delay in response but as you can see we are very busy here. In your next reply please post the log created by aswMBR. :)
Thanks for the response - I know you're very busy and definitely appreciate the help! Realize also that this isn't very urgent so understand if it's lower priority. I ran the aswMBR app twice - the first I forgot to run it from my desktop and it managed to load the blue screen of death with a memory dump. Impressive and scary. I pulled out the power and did a reboot and all seemed fine in safe mode (ran aswMBR then), so then I re-launched and ran aswMBR again, this time in full mode. Both scans are below, safe mode is first, full mode is second. aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-24 16:59:36 —————————– 16:59:36.205 OS Version: Windows x64 6.1.7601 Service Pack 1 16:59:36.205 Number of processors: 4 586 0x2505 16:59:36.205 ComputerName: BIANCA-PC UserName: Bianca 16:59:38.249 Initialize success 16:59:44.505 AVAST engine download error: 0 16:59:53.584 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 16:59:53.584 Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3 16:59:53.599 Disk 0 MBR read successfully 16:59:53.599 Disk 0 MBR scan 16:59:53.599 Disk 0 Windows VISTA default MBR code 16:59:53.631 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 16:59:53.662 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 465298 MB offset 3074048 16:59:53.693 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 10141 MB offset 956004352 16:59:53.709 Service scanning 16:59:55.471 Modules scanning 16:59:55.471 Disk 0 trace - called modules: 16:59:55.487 ntoskrnl.exe CLASSPNP.SYS disk.sys thpdrv.sys ACPI.sys iaStor.sys hal.dll 16:59:55.487 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800592e060] 16:59:55.503 3 CLASSPNP.SYS[fffff880017b843f] -> nt!IofCallDriver -> \Device\THPDRV1[0xfffffa800592d060] 16:59:55.503 5 thpdrv.sys[fffff88001b4dcc0] -> nt!IofCallDriver -> [0xfffffa80048f5670] 16:59:55.503 7 ACPI.sys[fffff88000f9c7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80048fa050] 16:59:55.518 Scan finished successfully 17:00:13.131 Disk 0 MBR has been saved successfully to "C:\Users\Bianca\Desktop\MBR.dat" 17:00:13.131 The log file has been saved successfully to "C:\Users\Bianca\Desktop\aswMBR.txt" ————————————————————————— aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-24 17:04:39 —————————– 17:04:39.532 OS Version: Windows x64 6.1.7601 Service Pack 1 17:04:39.532 Number of processors: 4 586 0x2505 17:04:39.532 ComputerName: BIANCA-PC UserName: Bianca 17:04:41.451 Initialize success 18:04:57.885 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 18:04:57.885 Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3 18:04:57.935 Disk 0 MBR read successfully 18:04:57.935 Disk 0 MBR scan 18:04:57.945 Disk 0 Windows VISTA default MBR code 18:04:57.955 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 18:04:57.975 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 465298 MB offset 3074048 18:04:58.045 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 10141 MB offset 956004352 18:04:58.045 Service scanning 18:05:00.055 Modules scanning 18:05:00.055 Disk 0 trace - called modules: 18:05:00.085 ntoskrnl.exe CLASSPNP.SYS disk.sys thpdrv.sys ACPI.sys iaStor.sys hal.dll 18:05:00.085 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800695f060] 18:05:00.085 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> \Device\THPDRV1[0xfffffa800695e060] 18:05:00.425 5 thpdrv.sys[fffff88001b92cc0] -> nt!IofCallDriver -> [0xfffffa80049385e0] 18:05:00.425 7 ACPI.sys[fffff88000d5e7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800493b050] 18:05:00.435 Scan finished successfully 18:05:11.518 Disk 0 MBR has been saved successfully to "C:\Users\Bianca\Desktop\MBR.dat" 18:05:11.518 The log file has been saved successfully to "C:\Users\Bianca\Desktop\aswMBR2.txt"
Hi BKL25,

so understand if it's lower priority.

B) In my opinion there is no "lower priority".
————

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Sorry for the delay, my Combofix has been running for about 12+ hours now. It was stuck on Completed Stage_48 for quite a while, now it's stuck at Completed Stage_50. I'll let it keep running until I hear otherwise. Thanks! Disregard earlier post. Just finally completed. Here is the Combofix.txt info: ComboFix 12-01-23.02 - Bianca 01/25/2012 14:15:25.6.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3824.1893 [GMT -8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E} SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Bianca\Documents\~WRL0003.tmp c:\users\Bianca\g2mdlhlpx.exe . . ((((((((((((((((((((((((( Files Created from 2011-12-27 to 2012-01-27 ))))))))))))))))))))))))))))))) . . 2012-01-27 05:50 . 2012-01-27 05:50 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-01-27 05:50 . 2012-01-27 05:50 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-01-27 05:50 . 2012-01-27 05:50 ——– d—–w- c:\users\Administrator\AppData\Local\temp 2012-01-26 01:55 . 2012-01-26 01:55 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A87B7364-A69B-4788-816D-4122780A6DC2}\offreg.dll 2012-01-24 22:08 . 2012-01-06 05:15 8602168 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A87B7364-A69B-4788-816D-4122780A6DC2}\mpengine.dll 2012-01-19 00:44 . 2012-01-19 00:44 ——– d—–w- c:\users\Bianca\AppData\Roaming\Adobe Mini Bridge CS5.1 2012-01-16 20:05 . 2012-01-16 20:05 ——– d—–w- c:\users\Bianca\AppData\Roaming\ooVoo Details 2012-01-16 20:05 . 2012-01-16 20:05 ——– d—–w- c:\program files (x86)\ooVoo 2012-01-11 05:47 . 2011-10-26 05:25 1572864 —-a-w- c:\windows\system32\quartz.dll 2012-01-11 05:47 . 2011-10-26 05:25 366592 —-a-w- c:\windows\system32\qdvd.dll 2012-01-11 05:47 . 2011-10-26 04:32 514560 —-a-w- c:\windows\SysWow64\qdvd.dll 2012-01-11 05:47 . 2011-10-26 04:32 1328128 —-a-w- c:\windows\SysWow64\quartz.dll 2012-01-11 05:47 . 2011-11-19 14:58 77312 —-a-w- c:\windows\system32\packager.dll 2012-01-11 05:47 . 2011-11-19 14:01 67072 —-a-w- c:\windows\SysWow64\packager.dll 2012-01-11 05:47 . 2011-11-17 06:41 1731920 —-a-w- c:\windows\system32\ntdll.dll 2012-01-11 05:47 . 2011-11-17 05:38 1292080 —-a-w- c:\windows\SysWow64\ntdll.dll 2012-01-10 18:30 . 2012-01-10 18:30 ——– d—–w- c:\program files (x86)\Conduit 2012-01-10 18:30 . 2012-01-10 19:05 ——– d—–w- c:\users\Bianca\AppData\Local\Conduit 2012-01-03 13:10 . 2012-01-03 13:10 53656 —-a-w- c:\windows\system32\AdobePDF.dll 2012-01-03 13:10 . 2012-01-03 13:10 24984 —-a-w- c:\windows\system32\AdobePDFUI.dll 2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-24 04:52 . 2011-12-15 06:59 3145216 —-a-w- c:\windows\system32\win32k.sys 2011-11-15 22:29 . 2011-03-09 04:38 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-11-10 18:35 . 2011-10-07 15:41 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-05 05:41 . 2011-12-15 07:00 1188864 —-a-w- c:\windows\system32\wininet.dll 2011-11-05 05:32 . 2011-12-15 06:59 2048 —-a-w- c:\windows\system32\tzres.dll 2011-11-05 04:35 . 2011-12-15 07:00 981504 —-a-w- c:\windows\SysWow64\wininet.dll 2011-11-05 04:26 . 2011-12-15 06:59 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2011-11-05 03:32 . 2011-12-15 06:59 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-11-05 02:48 . 2011-12-15 06:59 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-07-30 39408] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 19979400] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TOSDCR"="c:\program files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe" [2007-08-28 169296] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-05-02 2454840] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "WebrootTrayApp"="c:\program files (x86)\Webroot\Security\Current\Framework\WRTray.exe" [2011-09-10 1382984] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-01-03 36760] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-01-03 815512] . c:\users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-12-5 24242056] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-6-24 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 136176] R3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 136176] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-10-19 340240] R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x] R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-05-11 836016] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x] S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664] S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2010-06-07 408576] S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe64.sys [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264] S2 ssfmonm;ssfmonm;c:\windows\system32\DRIVERS\ssfmonm.sys [x] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-04-24 259440] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920] S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-06-07 911872] S2 WRConsumerService;Webroot Client Service;c:\program files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-09-10 3381184] S3 bpenum;bpenum;c:\windows\system32\DRIVERS\bpenum.sys [x] S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [x] S3 bpusb;bpusb;c:\windows\system32\Drivers\bpusb.sys [x] S3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 01:28] . 2012-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 01:28] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "IntelWirelessWiMAX"="c:\program files\Intel\WiMAX\Bin\WiMAXCU.exe" [2010-06-08 1441792] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-10-19 1931024] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-27 12681320] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-07-29 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-07-29 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-07-29 415256] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ uDefault_Search_URL = hxxp://www.google.com/ie mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file) Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe Wow6432Node-HKCU-Run-AdobeBridge - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-938898086-3655011318-2894540618-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-938898086-3655011318-2894540618-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe . ************************************************************************** . Completion time: 2012-01-26 22:20:57 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-27 06:20 . Pre-Run: 415,810,490,368 bytes free Post-Run: 415,466,483,712 bytes free . - - End Of File - - 7C476E91FAFDF0219CCA25A70201337B
Hi BKL25,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    uURLSearchHooks: H - No File
    BHO-X64: URLRedirectionBHO - No File
    TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    
    Folder::
    c:\program files (x86)\Conduit
    c:\users\Bianca\AppData\Local\Conduit
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hi Jeff, Sorry yes, still running combofix with the code you gave me. I started it Saturday night and it's been running since then. It gets interrupted occasionally when my computer hibernates and it's definitely still running but right now it's stuck at: Completed Stage_50. I'm going to let it run another half day or so - last time once I hit this stage, it finished pretty quickly. Thanks!
Hi Jeff, And it's completed! Thanks for all your patience and help. Here is the log: ComboFix 12-01-23.02 - Bianca 01/28/2012 21:21:16.7.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3824.1919 [GMT -8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Bianca\Desktop\CFScript.txt AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E} SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Conduit c:\program files (x86)\Conduit\Community Alerts\Alert.dll c:\users\Bianca\AppData\Local\Conduit . . ((((((((((((((((((((((((( Files Created from 2011-12-28 to 2012-01-30 ))))))))))))))))))))))))))))))) . . 2012-01-30 20:03 . 2012-01-30 20:03 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-01-30 20:03 . 2012-01-30 20:03 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-01-30 20:03 . 2012-01-30 20:03 ——– d—–w- c:\users\Administrator\AppData\Local\temp 2012-01-28 19:27 . 2012-01-06 05:15 8602168 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E2BEC011-2E23-4C5F-B68F-08A73B27138A}\mpengine.dll 2012-01-19 00:44 . 2012-01-19 00:44 ——– d—–w- c:\users\Bianca\AppData\Roaming\Adobe Mini Bridge CS5.1 2012-01-16 20:05 . 2012-01-16 20:05 ——– d—–w- c:\users\Bianca\AppData\Roaming\ooVoo Details 2012-01-16 20:05 . 2012-01-16 20:05 ——– d—–w- c:\program files (x86)\ooVoo 2012-01-11 05:47 . 2011-10-26 05:25 1572864 —-a-w- c:\windows\system32\quartz.dll 2012-01-11 05:47 . 2011-10-26 05:25 366592 —-a-w- c:\windows\system32\qdvd.dll 2012-01-11 05:47 . 2011-10-26 04:32 514560 —-a-w- c:\windows\SysWow64\qdvd.dll 2012-01-11 05:47 . 2011-10-26 04:32 1328128 —-a-w- c:\windows\SysWow64\quartz.dll 2012-01-11 05:47 . 2011-11-19 14:58 77312 —-a-w- c:\windows\system32\packager.dll 2012-01-11 05:47 . 2011-11-19 14:01 67072 —-a-w- c:\windows\SysWow64\packager.dll 2012-01-11 05:47 . 2011-11-17 06:41 1731920 —-a-w- c:\windows\system32\ntdll.dll 2012-01-11 05:47 . 2011-11-17 05:38 1292080 —-a-w- c:\windows\SysWow64\ntdll.dll 2012-01-03 13:10 . 2012-01-03 13:10 53656 —-a-w- c:\windows\system32\AdobePDF.dll 2012-01-03 13:10 . 2012-01-03 13:10 24984 —-a-w- c:\windows\system32\AdobePDFUI.dll 2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-07 18:39 . 2011-03-09 04:38 279096 ——w- c:\windows\system32\MpSigStub.exe 2011-11-24 04:52 . 2011-12-15 06:59 3145216 —-a-w- c:\windows\system32\win32k.sys 2011-11-10 18:35 . 2011-10-07 15:41 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-05 05:41 . 2011-12-15 07:00 1188864 —-a-w- c:\windows\system32\wininet.dll 2011-11-05 05:32 . 2011-12-15 06:59 2048 —-a-w- c:\windows\system32\tzres.dll 2011-11-05 04:35 . 2011-12-15 07:00 981504 —-a-w- c:\windows\SysWow64\wininet.dll 2011-11-05 04:26 . 2011-12-15 06:59 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2011-11-05 03:32 . 2011-12-15 06:59 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-11-05 02:48 . 2011-12-15 06:59 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb . . ((((((((((((((((((((((((((((( SnapShot@2012-01-27_06.14.51 ))))))))))))))))))))))))))))))))))))))))) . - 2012-01-27 06:08 . 2012-01-27 06:08 25106 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat + 2012-01-30 20:03 . 2012-01-30 20:03 25106 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat - 2009-07-14 04:54 . 2012-01-27 06:10 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-01-30 20:05 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-01-30 20:05 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-01-27 06:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-01-27 06:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-01-30 20:05 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-07-30 00:48 . 2012-01-29 03:03 54620 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-01-30 20:06 39206 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-03-09 04:25 . 2012-01-30 20:06 10576 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-938898086-3655011318-2894540618-1001_UserData.bin - 2010-11-22 20:19 . 2012-01-27 06:10 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-11-22 20:19 . 2012-01-30 20:05 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-11-22 20:19 . 2012-01-27 06:10 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2010-11-22 20:19 . 2012-01-30 20:05 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-01-30 20:05 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-01-27 06:10 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-03-09 19:30 . 2012-01-27 06:12 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-03-09 19:30 . 2012-01-29 03:04 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-03-09 19:30 . 2012-01-29 03:04 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-03-09 19:30 . 2012-01-27 06:12 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-03-09 19:30 . 2012-01-27 06:12 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-09 19:30 . 2012-01-29 03:04 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-09 04:27 . 2012-01-30 19:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-03-09 04:27 . 2012-01-27 06:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-03-09 04:27 . 2012-01-27 06:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-03-09 04:27 . 2012-01-30 19:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-01-28 19:26 . 2012-01-28 19:26 9560 c:\windows\system32\NetworkList\Icons\{068ABA06-AD4E-49A8-9B4C-E8927D5C94B8}_48.bin + 2012-01-28 19:26 . 2012-01-28 19:26 4280 c:\windows\system32\NetworkList\Icons\{068ABA06-AD4E-49A8-9B4C-E8927D5C94B8}_32.bin + 2012-01-28 19:26 . 2012-01-28 19:26 2456 c:\windows\system32\NetworkList\Icons\{068ABA06-AD4E-49A8-9B4C-E8927D5C94B8}_24.bin - 2012-01-27 06:09 . 2012-01-27 06:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-01-30 20:04 . 2012-01-30 20:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-01-27 06:09 . 2012-01-27 06:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-01-30 20:04 . 2012-01-30 20:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-03-10 20:10 . 2012-01-27 06:23 275908 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin - 2011-03-10 20:10 . 2012-01-27 05:23 275908 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin + 2011-03-09 23:32 . 2012-01-30 18:16 271318 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2011-03-09 23:32 . 2012-01-26 03:48 271318 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2009-07-14 05:01 . 2012-01-30 20:03 466556 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2012-01-27 06:08 466556 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-07-30 39408] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 19979400] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TOSDCR"="c:\program files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe" [2007-08-28 169296] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-05-02 2454840] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "WebrootTrayApp"="c:\program files (x86)\Webroot\Security\Current\Framework\WRTray.exe" [2011-09-10 1382984] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-01-03 36760] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-01-03 815512] . c:\users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-12-5 24242056] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-6-24 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 136176] R3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 136176] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-10-19 340240] R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x] R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-05-11 836016] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x] S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664] S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2010-06-07 408576] S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe64.sys [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264] S2 ssfmonm;ssfmonm;c:\windows\system32\DRIVERS\ssfmonm.sys [x] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-04-24 259440] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920] S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-06-07 911872] S2 WRConsumerService;Webroot Client Service;c:\program files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-09-10 3381184] S3 bpenum;bpenum;c:\windows\system32\DRIVERS\bpenum.sys [x] S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [x] S3 bpusb;bpusb;c:\windows\system32\Drivers\bpusb.sys [x] S3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 01:28] . 2012-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 01:28] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "IntelWirelessWiMAX"="c:\program files\Intel\WiMAX\Bin\WiMAXCU.exe" [2010-06-08 1441792] "TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU] "HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU] "SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU] "00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU] "SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU] "Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU] "TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-10-19 1931024] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-27 12681320] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-07-29 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-07-29 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-07-29 415256] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ uDefault_Search_URL = hxxp://www.google.com/ie mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-938898086-3655011318-2894540618-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-938898086-3655011318-2894540618-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe . ************************************************************************** . Completion time: 2012-01-30 12:11:58 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-30 20:11 ComboFix2.txt 2012-01-27 06:20 . Pre-Run: 415,498,072,064 bytes free Post-Run: 414,820,487,168 bytes free . - - End Of File - - C51D669D52894015CFE0F0F12FFFCF7B
Hi BKL25,

When you ran DDS there should have been another log that was created name Attach.txt. Could you post that into your next reply please? Thanks.
——-

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]
  • Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
———-

In your next reply please post the Attach.txt log created by DDS and the logs made by Malwarebytes and ESET online scanner. :)
Hi Jeff, Sorry about this but I can't find the original Attach.txt file - I re-ran it and attached here, for what it's worth. Here are the other two logs: MBAM: ========== Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Database version: v2012.01.31.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Bianca :: BIANCA-PC [administrator] 1/30/2012 7:38:49 PM mbam-log-2012-01-30 (19-38-49).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 203960 Time elapsed: 5 minute(s), 13 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ====================== ESET log - this one ran a little weird, so let me know if this doesn't look right: ====================== ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=0

Attachments:

Hi BKL25,

No that ESET scan has not run correctly. Let's try another online scan.

Do an online scan with BitDefender QuickScan.
Please be patient as scanning may take some time. If you have problem running the scan, you might want to disable any real time protection that you have.
  • Click here to go to BitDefender QuickScan page.
  • For Firefox users:
    • Click on Free Scan Now. You will be prompted to install a plug-in. Please Allow. In case you get stuck, please refresh the page to try again.
    • A Software Installation window will appear. Click Install Now and the plugin will be installed as an Add-on.
    • Restart Firefox when done. Go back to the BitDefender QuickScan page again and click on Free Scan Now and proceed accordingly.
  • For Internet Explorer users:
    • Click on Free Scan Now. You will be prompted to install an ActiveX control. Please install.
    • The page will refresh. Click on Free Scan Now again and proceed accordingly.
  • When scan has completed, click on View report and a Notepad log shall open.
  • If there are any infections found, you will get a warning and the link to the report will be displayed as the number of infections. Click on it.
  • Post back the contents of this report. It can also be found at C:\Documents and Settings\\Application Data\QuickScan, is the Windows log-in name.
———-
This one seemed to work but I had to refresh it, so let me know if this doesn't look right to you… sorry about the other one. ================================ QuickScan 32-bit v0.9.9.105 ————————— Scan date: Tue Jan 31 11:49:41 2012 Machine ID: DE46811F No infection found. ——————- Processes ——— AcroTray - Adobe Acrobat Distiller help 5904 C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe Dropbox 4916 C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe Google Chrome 116 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 1056 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 1144 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 1816 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 2500 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 3240 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 3624 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 3776 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 4620 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 5592 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 7608 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Chrome 8112 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Google Toolbar for Internet Explorer 1468 C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe Microsoft® Windows® Operating System 724 C:\Windows\SysWOW64\rundll32.exe Skype 4820 C:\Program Files (x86)\Skype\Phone\Skype.exe Webroot Security Tray Application 5196 C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe Windows® Internet Explorer 3528 C:\Program Files (x86)\Internet Explorer\iexplore.exe Windows® Internet Explorer 5784 C:\Program Files (x86)\Internet Explorer\iexplore.exe (verified) GoogleToolbarNotifier 4800 C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe Network activity —————- Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process chrome.exe (1816) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (3528) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (3528) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (3528) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (3528) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (3528) connected on port 80 (HTTP) –> [removed] Process Dropbox.exe (4916) connected on port 80 (HTTP) –> [removed] Process Dropbox.exe (4916) listens on ports: 17500 Autoruns and critical files ————————— AcroTray - Adobe Acrobat Distiller help C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe Adobe Acrobat C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe Adobe CS5.5 Service Manager C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe Adobe Reader and Acrobat Manager C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe Dropbox C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe Malwarebytes Anti-Malware C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe Microsoft® Windows® Operating System c:\windows\system32\userinit.exe SBSV 2010/02/19-11:02:07 C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe Skype C:\Program Files (x86)\Skype\Phone\Skype.exe TOSDCR.exe C:\Program Files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe TOSHIBA Service Station C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe TOSHIBA Web Camera Application C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe Webroot Security Tray Application C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe Windows® Internet Explorer c:\windows\syswow64\webcheck.dll (verified) GoogleToolbarNotifier C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe Browser plugins ————— AcroIEHelperShim Library c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll Adobe Acrobat C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll Adobe Acrobat C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll Adobe Acrobat C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll Adobe PDF Toolbar for IE c:\program files (x86)\common files\adobe\acrobat\activex\acroiefavclient.dll BitDefender QuickScan C:\Windows\Downloaded Program Files\qsax.dll Google Earth Plugin C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll Google Toolbar for Internet Explorer C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll Google Update C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll GoogleToolbarNotifier C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL Microsoft® CoReXT C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll Microsoft® CoReXT C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL Microsoft® CoReXT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL Microsoft® Windows® Operating System C:\windows\System32\mswsock.dll Microsoft® Windows® Operating System C:\windows\system32\NLAapi.dll nppdf32.DEU C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.DEU nppdf32.FRA C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.FRA NPSWF32.dll C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll Picasa C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll Silverlight Plug-In c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll TOSHIBA Media Controller Plug-in C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll Windows Live™ Photo Gallery C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll Windows® Internet Explorer C:\Windows\SysWOW64\ieframe.dll (verified) Java™ Platform SE 6 U20 c:\program files (x86)\java\jre6\bin\jp2ssv.dll (verified) Microsoft® Windows® Operating System C:\windows\system32\napinsp.dll (verified) Microsoft® Windows® Operating System C:\windows\system32\pnrpnsp.dll (verified) Microsoft® Windows® Operating System C:\windows\System32\winrnr.dll Scan —- MD5: 675768f27997468394aef7a785acd28c C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe MD5: 16aedbebd92d1ecba79bceb09ed90f32 C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe MD5: 4a3b1cad5511b37a2049b7bbb31e597e C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\adobe_caps.dll MD5: 8082f66dc9c8167ff1aa548736f58457 C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll MD5: d172236d0811c10ea8b2cdeb8bccbc3f C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\amtservices.dll MD5: eb8b5b2d37d7847f6074e046cbb5f938 C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\asneu.dll MD5: 8082f66dc9c8167ff1aa548736f58457 C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll MD5: ea7e57f87d6fee5fd6c5f813c04e8cd2 C:\Program Files (x86)\Browny02\BrYNSvc.exe MD5: edc07b6df34c39ec40df1904c7459b4f c:\program files (x86)\common files\adobe\acrobat\activex\acroiefavclient.dll MD5: 8a3ba48b5be893e1d81bfac17a3c1b1f c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll MD5: b8e421c0890356cd4a793d8a346d9096 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe MD5: 62b7936f9036dd6ed36e6a7efa805dc0 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe MD5: e1636f57581cab5d995fd54d2991ef57 C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe MD5: f577910a133a592234ebaad3f3afa258 C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe MD5: 344546d11d7e6d9f481e9d3abc6e76cb C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE MD5: 6bf01e200063d7274f3af06d226671f5 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll MD5: da579734b4375740efee86ffdfed57a7 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\wlidcli.DLL MD5: 9d4a1690af93f233e15380398bec7431 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL MD5: 97ae540b2853e7112be83a650110eb64 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\avcodec-53.dll MD5: 72af6085baf82343cb39b543a708686c C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\avformat-53.dll MD5: 5fb8b4f19907e64bb92254c6f08b0c09 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\avutil-51.dll MD5: 350f7cd349581497b1f31825c8decfa1 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\chrome.dll MD5: 1c9b45e87528b8bb8cfa884ea0099a85 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\d3dcompiler_43.dll MD5: 86e39e9161c3d930d93822f1563c280d C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\d3dx9_43.dll MD5: be0ff1633a2b280fb455ccd07c111050 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\gcswf32.dll MD5: 794f655caae44aae20139326a1d433c2 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\icudt.dll MD5: 848806e7a645fa8bc5324c9e2ef57249 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\libegl.dll MD5: fe5e9e99e940a5f9ef7b260c602e3199 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\libglesv2.dll MD5: 8cedb784eab4c35d2139adff4c8236e9 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\pdf.dll MD5: b6639ab91b1fcf1762efb395281decf9 C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll MD5: 697d3b09d8883f72265da274e0972042 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe MD5: 2437be68d5a37a75fad51c5f0e9a03ed C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll MD5: 64c1481b867cc7b45e10a74cc9eb46e4 C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_32_248D3CEB7C787E4E.dll MD5: 3a913a99c665a6c3610241c09439f281 C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_F5A70B61FC3A2BB0.dll MD5: 61980095ae5d02b1e9d2ed604a90c1bf C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll MD5: e168a426c2f711f39597292d878d5e50 C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe MD5: ab3668c159e1cfea184f72650bd66807 C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll MD5: 45d7f2fabdfd500e3c35dc068b552544 C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll MD5: 27626506e07795bb6357f7f2ef78a90b C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll MD5: 23de5b62b0445a6f874be633c95b483e C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe MD5: cc3775100aba633984f73dfae1f55cae C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe MD5: 00347a3d11d3c0863c953e48ff443d59 C:\Program Files (x86)\Internet Explorer\ieproxy.dll MD5: e0583d99d78277ccf78664708aec39b8 C:\Program Files (x86)\Internet Explorer\IEShims.dll MD5: c613e69c3b191bb02c7a191741a1d024 C:\Program Files (x86)\Internet Explorer\iexplore.exe MD5: 60d0647a2dc2d397b84d0afb0808f85d C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe MD5: 08d2b597cc4e26fde43be9f104476f65 C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe MD5: 0ec561d71a733814cff37712cdee2a74 C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe MD5: 47fc5a4a45e883a36aff884b3e6073b1 C:\Program Files (x86)\Microsoft Office\Office14\MSOHEV.DLL MD5: a5d08b86e8a437aa6deaf7a187bf6ca5 C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL MD5: ce6db25ffa35fd051c503f11db745862 c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll MD5: 7b18b2325b41196905fe71219aa2d154 C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.DEU MD5: 53fe2d34b143efdb80685281e751b91c C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll MD5: cc62f141b4b8bd5bafdb10079891556a C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.FRA MD5: c5af954556830ef71197024ea400b721 C:\Program Files (x86)\Skype\Phone\Skype.exe MD5: ce7648af53e26ceb484f54866f195328 C:\Program Files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe MD5: 816e03e300f49ae7882990da96ab0db7 C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll MD5: 28644b0523d64eff2fc7312a2ee74b0a C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe MD5: 541b822882607023e75ffec0c8f90faf C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe MD5: 80d632dc81bdf6e58630d8fa329fae54 C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe MD5: cd569bfef65e20768f7b142331b78700 C:\Program Files (x86)\Webroot\Security\Current\framework\frameworkresources.dll MD5: f5dd32df32f08917ccc63032be5f75aa C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe MD5: 6b22d50a2f22404f868967b18b46cd87 C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe MD5: bd1537fa5ea8e03d4b766d65c22d1073 C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe MD5: ac421a44de902f2627f1e63793ed89cd C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll MD5: 2528d733da7f5ac8d3d32c74ee4cff16 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe MD5: 28ad5e311996a34025cfb07e131058dd C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL MD5: 7e47c328fc4768cb8beafbcfafa70362 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE MD5: bdf87981c5fea94fd259f110fb8b1a72 C:\Program Files\Intel\WiFi\bin\EvtEng.exe MD5: 59aa4cff0c9eda2252bbf5b6c7c5aa21 C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe MD5: 8686e96e13f41ac9806a79ca8004feee C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe MD5: 61458c120cddfe7514e2db125568ca59 C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe MD5: bdbe7a21e1de76d92f566aa80546aa4c C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe MD5: 231153874d46a7fcb8f60b05dff7df69 C:\Program Files\TOSHIBA\TECO\TecoService.exe MD5: 74c2fa8c3765ee71a9c22182ec108457 C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe MD5: 1f7a27de3f0849a31ce8909e3b3b1e1c C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe MD5: a9f3bfc9345f49614d5859ec95b9e994 C:\Program Files\Windows Media Player\wmpnetwk.exe MD5: d774dbe55e186bb5b9b32e716a7c177a C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe MD5: 6d74290856347cf8682277a54b433d4b C:\Users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll MD5: 368b2bee3f88bfb883d2c74a258de6f6 C:\windows\AppPatch\AcLayers.DLL MD5: 6d7de520d8aa80a243347becd401eb54 C:\windows\AppPatch\AcWow64.DLL MD5: bb7fcdcd4de287340b5c1bb1949ad3c6 C:\Windows\Downloaded Program Files\qsax.dll MD5: c4002b6b41975f057d98c439030cea07 C:\windows\ehome\ehRecvr.exe MD5: 332feab1435662fc6c672e25beb37be3 C:\windows\Explorer.exe MD5: 5988fc40f8db5b0739cd1e3a5d0d78bd C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe MD5: a8b7f3818ab65695e3a0bb3279f6dce6 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe MD5: 773212b2aaa24c1e31f10246b15b276c C:\windows\servicing\TrustedInstaller.exe MD5: 37ce7a79d901235504f9add99a7ac177 C:\windows\system32\api-ms-win-core-console-l1-1-0.dll MD5: 7a044b0746d957bfd7aae18cfd8422c5 C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll MD5: 0a12d948b2cc7fbb01e28daa5e7c01ea C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll MD5: cb4863f2bd46aa02d954b86b56a149da C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll MD5: 2cae4ed96aa903578452b85e5383940c C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll MD5: e96170a923a69711b4d08e885f05d889 C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll MD5: 44ca750001f0db8c308d1ca4abd0f8e5 C:\windows\system32\api-ms-win-core-file-l1-1-0.dll MD5: 15df9eb8daba744e4d0e9b117f760f49 C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll MD5: a2385b02cb492131af6f79959a42a93f C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll MD5: 3ad0832e8e29fbe9bd722e3354dd4f57 C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll MD5: 88dc1714e38d4eb41a4378aab98e753b C:\windows\system32\api-ms-win-core-io-l1-1-0.dll MD5: a1d4deb5176c96b1a80715f6a1fdfb4f C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll MD5: b302a1630e5aea2d830b76bbcd761d72 C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll MD5: 22f767bb3b704f79363999bd4a49e68e C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll MD5: 00b83152f99e846fefb139c574cd4a96 C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll MD5: 50035c36acee069d0c209288208626d9 C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll MD5: cdf677ad479fa99f2e4d9766b83ef53c C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll MD5: 12c34c7325b74e8347e8db75279a8f3f C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll MD5: 96324ed3218133a13fff82055afac733 C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll MD5: a7bdf88a46bcc218b73e383e6547ba5f C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll MD5: 573c70d7076f2f101752a727db7c2280 C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll MD5: 29b01d02e9ff3d8a63f8747b50a5a1a3 C:\windows\system32\api-ms-win-core-string-l1-1-0.dll MD5: 0cc90316b34118e3b8af760d92c262a4 C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll MD5: 6f399c3e562c4e69df96039743a7aa26 C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll MD5: f3b94e04053c2483a6fecf953d6661d6 C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll MD5: c6942a18444bfffc3cceca69a7e1879c C:\windows\system32\api-ms-win-core-util-l1-1-0.dll MD5: f47e08b025ae376ef1342fc9ecfecdf1 C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll MD5: 8a13e14b68e00ac2cb67420396d8a1c5 C:\windows\system32\api-ms-win-security-base-l1-1-0.dll MD5: 863f793d15b4026b1a5fdeca873d4d84 C:\windows\system32\apphelp.dll MD5: 088cf5b6380fb9002f2a4246f812225d C:\windows\system32\asycfilt.dll MD5: c940f2f5c60b3727c5f18840735b229c C:\windows\system32\AUDIOSES.DLL MD5: 7a6986dd659b96398a11af5173892715 C:\windows\system32\Cabinet.dll MD5: ad7b9c14083b52bc532fba5948342b98 C:\windows\system32\cmd.exe MD5: 53831de9162c6c2378574b59eb786bf1 C:\windows\system32\corpol.dll MD5: 4e5fe39c1076d115ec8bfcfe14d75b80 C:\windows\system32\credssp.dll MD5: a585bebf7d054bd9618eda0922d5484a C:\windows\system32\cryptsvc.dll MD5: 28ca821606669bb9215ce010767720fa C:\windows\system32\cryptui.dll MD5: 465bea35f7ed4a4a57686dea7ea10f47 C:\windows\system32\cscapi.dll MD5: 6ef5f3f18413c367195f06e503ab86a6 C:\windows\system32\d3d9.dll MD5: 284b59d7b56fc76c80e622ab856b1fab C:\windows\System32\davclnt.dll MD5: 53223b673a3fa2f9a4d1c31c8d3f6cd8 C:\windows\system32\dbghelp.dll MD5: 162d247e995eaebf3ef4289069e1111c C:\windows\system32\DEVRTL.dll MD5: e9e01eb683c132f7fa27cd607b8a2b63 C:\windows\system32\dhcpcore.dll MD5: b40420876b9288e0a1c8cca8a84e5dc9 C:\windows\system32\DNSAPI.dll MD5: 1060d60cca69a8136a87dbe3c8f4a467 C:\windows\system32\EhStorAPI.dll MD5: 8b88ebbb05a0e56b7dcc708498c02b3e C:\windows\system32\Explorer.exe MD5: e2a17bcc08d92f42e08af6ba2f93aba7 C:\windows\system32\explorerframe.dll MD5: 03a03a453f1aaae0c73aaaf895321c7a C:\windows\System32\fwpuclnt.dll MD5: 28c8b1b6ab5d266226f3aba97b60dc6b C:\windows\system32\ieframe.DLL MD5: ff1e2482e9545ee40cb3160723f24588 C:\windows\system32\IEUI.dll MD5: 808538bbb53f34580765ddfb29b3fa58 C:\windows\system32\igdumd32.dll MD5: 0b149fe13eb1ea719e249d2e88d55fd2 C:\windows\system32\igdumdx32.dll MD5: 93117349047ddb7b3ff24eb006207606 C:\windows\system32\ImgUtil.dll MD5: a6f09e5669d9a19035f6d942caa15882 C:\windows\system32\IMM32.DLL MD5: a90dc9abd65db1a8902f361103029952 C:\windows\system32\IPHLPAPI.DLL MD5: 8ea53101ff2b15bdff934b62a8fb326d C:\windows\system32\LOGONCLI.DLL MD5: 8bc9db92c4b2f3be89185beab2afc1f6 C:\windows\system32\mapi32.dll MD5: fdba1dec4f9be4274a00b9b850c63484 C:\windows\system32\MF.dll MD5: 243974ec02f7ae49e4179c54624143ab C:\windows\system32\MMDevAPI.DLL MD5: 7f8678c59f188528d60104e697c2361e C:\windows\system32\mscms.dll MD5: 0ce4d3bd306da6d1f6f233c403f5b667 C:\windows\system32\msi.dll MD5: eee470f2a771fc0b543bdeef74fceca0 C:\windows\system32\msiexec.exe MD5: 8999b8631c7fd9f7f9ec3cafd953ba24 C:\windows\System32\mswsock.dll MD5: 4205ca4cd43e725db9ff02b0a588a8c6 C:\windows\System32\msxml3.dll MD5: 269d867585cda04d3972a39f3694e7df C:\windows\System32\msxml6.dll MD5: 8b57a1ad493653bb57f281fe75dd175b C:\windows\System32\NaturalLanguage6.dll MD5: 8ce1a6d16b9077e91e192499eb611c5f C:\windows\system32\NETAPI32.dll MD5: 20b3934db73eaba2b49b7177873cb81f C:\windows\system32\netutils.dll MD5: 3d57ffbad3ed16b63de3879bab0fb56f C:\windows\system32\NetworkExplorer.dll MD5: 104a1070e90f1c530328e69b49718841 C:\windows\system32\NLAapi.dll MD5: d7b7159bc8374e87d8c45a30377a3440 C:\windows\System32\ntlanman.dll MD5: eb77db354791a5932ca559b6f6374e95 C:\windows\system32\ntshrui.dll MD5: 8e01332cc4b68bc6b5b7effe374442aa C:\windows\system32\OLEACC.dll MD5: 703ffd301ab900b047337c5d40fd6f96 C:\windows\system32\olepro32.dll MD5: 487f44b08efeaf5ad087878357b9403d C:\windows\system32\pdh.dll MD5: 414bba67a3ded1d28437eb66aeb8a720 C:\windows\system32\pla.dll MD5: e98278865e8daba21cfe5fe4be34210a C:\windows\system32\PortableDeviceApi.dll MD5: 0fc7e6c8dfb1052f121638485a675761 C:\windows\system32\prntvpt.dll MD5: 12c45e3cb6d65f73209549e2d02eca7a C:\windows\system32\PROPSYS.dll MD5: dbc02d918fff1cad628acbe0c0eaa8e8 C:\windows\system32\provsvc.dll MD5: 63b282fb2550893724647a359ba2323f C:\windows\system32\query.dll MD5: 102cf6879887bbe846a00c459e6d4abc C:\windows\system32\RICHED20.dll MD5: 5997d769cdb108390dcfaebf442bf816 C:\windows\system32\RpcRtRemote.dll MD5: 0915c4db6dbc3bb9e11b7ecbbe4b7159 C:\windows\system32\rtutils.dll MD5: 68ecca523ed760aafc03c5d587569859 C:\windows\system32\samcli.dll MD5: 135f7ac9be35ab1df727faf2e60e92f8 C:\windows\system32\schannel.DLL MD5: 6581b52e133cc6d00661c58968c7e212 C:\windows\system32\SearchFolder.dll MD5: 236f286e103fd44bd85fdd93097fd5dd C:\windows\system32\SearchIndexer.exe MD5: a8ce0c7f1d37e0b8082608a148b6b976 C:\windows\system32\Secur32.dll MD5: 4ae380f39a0032eab7dd953030b26d28 C:\windows\system32\sessenv.dll MD5: be247ae996a9fde007a27b51413a6c79 C:\windows\System32\shdocvw.dll MD5: 414da952a35bf5d50192e28263b40577 C:\windows\System32\shsvcs.dll MD5: 5ccdcd40e732d54e0f7451ac66ac1c87 C:\windows\system32\srvcli.dll MD5: 6a1e8deb746912df47cf651e138401d7 C:\windows\System32\StructuredQuery.dll MD5: 919001d2bb17df06ca3f8ac16ad039f6 C:\windows\system32\SXS.DLL MD5: 613bf4820361543956909043a265c6ac C:\windows\System32\tapisrv.dll MD5: 465dbf63a5049e4db4bc5c12ffe781cb C:\windows\system32\tquery.dll MD5: d15618a0ff8dbc2c5bf3726bacc75a0b C:\windows\system32\USERENV.dll MD5: 61ac3efdfacfdd3f0f11dd4fd4044223 c:\windows\system32\userinit.exe MD5: cfc7d8289d2b5f3cf8d16e2db7f93d4a C:\windows\system32\wbem\fastprox.dll MD5: 704314fd398c81d5f342caa5df7b7f21 C:\windows\system32\wbemcomn.dll MD5: 34eee0dfaadb4f691d6d5308a51315dc C:\windows\System32\wcncsvc.dll MD5: d205c24a9d069049fe2df2a1b38726a7 C:\windows\system32\wdmaud.drv MD5: a9d880f97530d5b8fee278923349929d C:\windows\System32\webclnt.dll MD5: 02c61d8ad469417f5508225c75de3236 C:\windows\system32\webio.dll MD5: 1db71a41daee6b3f8cd0dda8209fa2d5 C:\windows\system32\WindowsCodecs.dll MD5: ca9f7888b524d8100b977c81f44c3234 C:\windows\system32\WINHTTP.dll MD5: d5aefad57c08349a4393d987df7c715d C:\windows\system32\WINMM.dll MD5: 9419abf3163b6f0e3ad3dd2b381c879f C:\windows\system32\WinSCard.dll MD5: 9e4b0e7472b4ceba9e17f440b8cb0ab8 C:\windows\system32\WINSPOOL.DRV MD5: 418e881201583a3039d81f43e39e6c78 C:\windows\System32\WINSTA.dll MD5: e5a4a1326a02f8e7b59e6c3270ce7202 C:\windows\system32\wkscli.dll MD5: 0f416e23dd2eb4debe70608020cfd283 C:\windows\system32\WMVCore.DLL MD5: 1b91cd34ea3a90ab6a4ef0550174f4cc C:\windows\system32\WsmSvc.dll MD5: 6a6b2ee4565a178035be2a4ff6f2c968 C:\windows\system32\WTSAPI32.dll MD5: edf2a5e96bec469da3f64e9bdd386111 C:\windows\system32\xmllite.dll MD5: d2958325c1ae1ae37a83334c6229e3bc C:\Windows\SysWOW64\actxprxy.dll MD5: 95e2376b3323f062eb562b8586d0f14a C:\windows\syswow64\ADVAPI32.dll MD5: 7a6986dd659b96398a11af5173892715 C:\windows\SysWOW64\Cabinet.dll MD5: f436e847fa799ecd75ad8c313673f450 C:\windows\syswow64\CFGMGR32.dll MD5: d1de1eafde97be41cf6585027ff3e732 C:\windows\syswow64\COMDLG32.dll MD5: 4e5fe39c1076d115ec8bfcfe14d75b80 C:\windows\SysWOW64\credssp.dll MD5: 454e292861a4ef1d72f43f42bbaf6917 C:\windows\syswow64\crypt32.dll MD5: 465bea35f7ed4a4a57686dea7ea10f47 C:\windows\SysWOW64\cscapi.dll MD5: 2eeff4502f5e13b1bed4a04ccad64c08 C:\windows\syswow64\DEVOBJ.dll MD5: 162d247e995eaebf3ef4289069e1111c C:\windows\SysWOW64\DEVRTL.dll MD5: b40420876b9288e0a1c8cca8a84e5dc9 C:\windows\SysWOW64\dnsapi.DLL MD5: 19bc13711ac403feb830522e4831701b C:\Windows\SysWOW64\gameux.dll MD5: d6d3ad7bf1d6f6ce9547613ed5e170a2 C:\windows\syswow64\GDI32.dll MD5: 28c8b1b6ab5d266226f3aba97b60dc6b C:\Windows\SysWOW64\ieframe.dll MD5: b54856b913ccbf23f456f87148f42920 C:\Windows\SysWOW64\iepeers.dll MD5: dfb136c4a799719347496bf22c84d4d2 C:\windows\syswow64\iertutil.dll MD5: b2fd31e20b423335fe3273b4bf95813c C:\windows\syswow64\imagehlp.dll MD5: a90dc9abd65db1a8902f361103029952 C:\windows\SysWOW64\iphlpapi.DLL MD5: 6ed9b473af5238e6c8edd4cd46f70e1f C:\Windows\SysWOW64\jscript.dll MD5: 99c3f8e9cc59d95666eb8d8a8b4c2beb C:\windows\syswow64\kernel32.dll MD5: 5c2d21c9b6b6175b89bc5d7e3cb979e1 C:\windows\syswow64\KERNELBASE.dll MD5: bd007d624e4cd905ab2e8df2c6de891c C:\windows\SysWOW64\Macromed\Flash\Flash11c.ocx MD5: de3745a51b7ac7fedc356a83f76c8023 C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll MD5: 938f39b50bafe13d6f58c7790682c010 C:\windows\syswow64\MSASN1.dll MD5: 61c09b5ad2932538659d133c875dbb0f C:\Windows\SysWOW64\mshtml.dll MD5: 20b3934db73eaba2b49b7177873cb81f C:\windows\SysWOW64\netutils.dll MD5: e73b0f1819602cb6ef176fb78d76a47b C:\windows\SysWOW64\ntdll.dll MD5: 928cf7268086631f54c3d8e17238c6dd C:\windows\syswow64\ole32.dll MD5: 6c765e82b57f2e66ce9c54ac238471d9 C:\windows\syswow64\OLEAUT32.dll MD5: c5ad8083cf94201f1f8084ecc696a8b7 C:\windows\syswow64\RPCRT4.dll MD5: 5997d769cdb108390dcfaebf442bf816 C:\windows\SysWOW64\RpcRtRemote.dll MD5: 0915c4db6dbc3bb9e11b7ecbbe4b7159 C:\windows\SysWOW64\rtutils.dll MD5: 135f7ac9be35ab1df727faf2e60e92f8 C:\windows\SysWOW64\schannel.dll MD5: 10fb16b50affda6d44588f3c445dc273 C:\windows\syswow64\SETUPAPI.dll MD5: be247ae996a9fde007a27b51413a6c79 C:\windows\SysWOW64\SHDOCVW.dll MD5: 16ab4bd2acc52109f43739bf0e89e18f C:\windows\syswow64\SHELL32.dll MD5: 8cc3c111d653e96f3ea1590891491d71 C:\windows\syswow64\SHLWAPI.dll MD5: 5ccdcd40e732d54e0f7451ac66ac1c87 C:\windows\SysWOW64\srvcli.dll MD5: 7224d964a6d657374c551c878eb2c386 C:\windows\syswow64\SspiCli.dll MD5: b20e9d20376028370a208828e9b03955 C:\windows\syswow64\urlmon.dll MD5: 5e0db2d8b2750543cd2ebb9ea8e6cdd3 C:\windows\syswow64\USER32.dll MD5: 804aaafebb3ad5f49334dd906bcb1de5 C:\windows\syswow64\USP10.dll MD5: a4ee3d80e31d5a3ca8ebe6a67a06cec0 c:\windows\syswow64\webcheck.dll MD5: 590d5c506044fe02ff7643e32ff9bdac C:\Windows\SysWOW64\wer.dll MD5: 1db71a41daee6b3f8cd0dda8209fa2d5 C:\windows\SysWOW64\WindowsCodecs.dll MD5: 19714fa7d7204d9bee1ee12791da9010 C:\windows\syswow64\WININET.dll MD5: 9e4b0e7472b4ceba9e17f440b8cb0ab8 C:\Windows\SysWOW64\WINSPOOL.DRV MD5: 2d0d2da87bea7144f2a17f19d0d17e4c C:\windows\syswow64\WINTRUST.dll MD5: e5a4a1326a02f8e7b59e6c3270ce7202 C:\windows\SysWOW64\wkscli.dll MD5: a8bb45f9ecad993461e0fef8e2a99152 C:\windows\syswow64\WLDAP32.dll MD5: 7ff15a4f092cd4a96055ba69f903e3e9 C:\windows\syswow64\WS2_32.dll MD5: edf2a5e96bec469da3f64e9bdd386111 C:\windows\SysWOW64\XmlLite.dll MD5: cdbe9690cf2b8409facad94fac9479c9 C:\windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb5 7\MSVCR90.dll MD5: bdac1aa64495d0f7e1ff810ebbf1f018 C:\windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32.dll MD5: 352b3dc62a0d259a82a052238425c872 C:\windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll MD5: 0029eba325f2fc9b6ba46bee33f32a09 C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a43 86696c80\gdiplus.dll No file uploaded. Scan finished - communication took 2 sec Total traffic - 0.01 MB sent, 0.91 KB recvd Scanned 400 files and modules - 45 seconds ==============================================================================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI