This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Traces of malware (and possible rootkit?) still present and causing is

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been wrestling with computer issues for the past couple weeks now caused by some sort of malicious programs. Some of the issues I've come across (a few of which are at least partially resolved) are: google search redirects, PING.EXE running constantly and hogging resources, unable to change windows firewall settings due to error "0x80070424", and other odds and ends. I ran malwarebyte's as well as a specific program to remove the PING.EXE issue and that seemed to take care of the redirects and the resource hog. The firewall issue has not been resolved as well as god knows what else that I haven't even noticed. Thank you so much for your time.

OTL logfile created on: 2/16/2012 12:29:02 PM - Run 1
OTL by OldTimer - Version 3.2.32.0 Folder = C:\Users\Marcos\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.17 Gb Available Physical Memory | 77.19% Memory free
16.00 Gb Paging File | 14.10 Gb Available in Paging File | 88.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 30.74 Gb Free Space | 22.00% Space Free | Partition Type: NTFS
Drive E: | 698.64 Gb Total Space | 337.39 Gb Free Space | 48.29% Space Free | Partition Type: NTFS

Computer Name: MARCOS-PC | User Name: Marcos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Marcos\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Users\Marcos\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Users\Marcos\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe ()
PRC - C:\Program Files (x86)\3d-io plugins\licensing_v2\ActiveLockServerV2.exe (3d-io GmbH)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\TechSmith\Jing\Jing.exe (TechSmith Corporation)
PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\c21fbb4bf27a7c8705e29f08827c9c7e\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\36b3b787a2942e629e87b1b96fa049d4\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\227927e469cb6b079e4cc7d81e38f8f5\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\1741fc5f7819af118d4de616016a8b2d\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\698b02e36bac06ac74077cc3ec6eced0\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\30740aecd686555cb6800b47cc80fae7\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\5c2eff65e7e457ea372f767c024c04f7\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b4e03b2b9835e9cb4e879c703880fe74\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\2d3806670b3c3e4163592b5aca62f8cc\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d4e8a005f4cdd6528f1c7295d833877f\mscorlib.ni.dll ()
MOD - C:\Users\Marcos\AppData\Local\Temp\c06086cf-47b1-4760-b263-4e4271d9922f\CliSecureRT.dll ()
MOD - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a0afd596da13c708d04b0a2dd1490036\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\0018b6bfd1d96454aa8fb698d0ea51a1\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\a9f6cfa4eb1436ff770995822f10e227\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\c8aa11ee6789d0f3f5542747aad7a2e4\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\173e012cca07a9b7151c574585a4ca9e\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\40404dbd013b0ca1e41ab7e57274308b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c68401de935c813374253d4fc2a18f6a\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\acbc57d41499fbc2b99194148786c677\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\338f3c91a0bea33a07a4611d324bf73a\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\16b68fcaff063835ae0ee348a1201f2a\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe ()
MOD - \\?\globalroot\systemroot\syswow64\mswsock.DLL ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - C:\Program Files (x86)\TechSmith\Jing\Recorder.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (ANTS Memory Profiler 7 Service) – C:\Program Files\Red Gate\ANTS Memory Profiler 7\RedGate.Memory.IISService.exe (Red Gate Software Ltd.)
SRV:64bit: - (ANTS Performance Profiler 6 Service) – C:\Program Files\Red Gate\ANTS Performance Profiler 6\RedGate.Profiler.IISService.exe (Red Gate Software Ltd.)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (TabletServiceWacom) – C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (AtiPcie) – C:\Windows\SysNative\3dkeybd.dll (Oak Technology Inc.)
SRV - (HiPatchService) – C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (3d-io License Server v2.0) – C:\Program Files (x86)\3d-io plugins\licensing_v2\ActiveLockServerV2.exe (3d-io GmbH)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (SCDEmu) – C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (YMIDUSBW) Yamaha USB-MIDI Driver (WDM) – C:\Windows\SysNative\drivers\ymidusbx64.sys (Yamaha Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (cpuz135) – C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (xnacc) – C:\Windows\SysNative\drivers\xnacc.sys (Microsoft Corporation)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (rt61x64) – C:\Windows\SysNative\drivers\netr6164.sys (Ralink Technology, Corp.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (dgderdrv) – C:\Windows\SysWOW64\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 64 2A 01 42 94 D5 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 56667
FF - prefs.js..network.proxy.type: 1

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.10: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Marcos\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Marcos\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Marcos\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\BYOND: C:\Program Files (x86)\BYOND\bin\npbyond.dll (BYOND)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/11/09 11:47:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2012/02/02 11:46:02 | 000,000,000 | —D | M]

[2011/07/04 15:08:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Marcos\AppData\Roaming\Mozilla\Extensions
[2012/01/12 00:24:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions
[2011/10/03 18:12:13 | 000,000,000 | —D | M] (FoxyTunes) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2011/11/11 22:26:16 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/08/21 00:21:47 | 000,000,000 | —D | M] (ActiveGS) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions\[removed]
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{0FA2149E-BB2C-4AC2-A8D3-479599819475}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{988DA70D-B78D-44A1-A9C7-ED11832A9E2E}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\0.80.0\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Roozz plugin (Enabled) = C:\Program Files (x86)\Roozz\nproozz.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Marcos\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Marcos\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus (Beta) = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: imgur = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehoopddfhgaehhmphfcooacjdpmbjlao\1.0.5_0\
CHR - Extension: AirMech = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdahlabpinmfcemhcbcfoijcpoalfgdn\7165_0\
CHR - Extension: AirMech = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdahlabpinmfcemhcbcfoijcpoalfgdn\7207_0\
CHR - Extension: Cloud9 = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbdmccoknlfggadpfkmcpnamfnbkmkcp\1.9.5_0\

Hosts file not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [TortoiseHgOverlayIconServer] C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe ()
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [ContourCameraFinder] C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe ()
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Marcos\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [Java X Run Class] %TEMP%\javax.exe File not found
O4 - HKCU..\Run: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - Startup: C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Marcos\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Thunderbird.lnk = C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
O4 - Startup: C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59DD3D3F-B7ED-404C-BA1F-84E544261B0D}: DhcpNameServer = 10.253.40.1 [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BA53C310-0C3C-4C99-B8B5-E2651CEBED41}: DhcpNameServer = 10.200.154.1 [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBFB7911-C70E-47D2-A6E5-84773522C303}: DhcpNameServer = 10.254.40.1 [removed] [removed] [removed]
O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~1\GO36F4~1.DLL) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/20 01:35:27 | 000,000,000 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{b7a1fd4e-3179-11e1-8e57-00044b15890c}\Shell - "" = AutoRun
O33 - MountPoints2\{b7a1fd4e-3179-11e1-8e57-00044b15890c}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AtiPcie - C:\Windows\SysNative\3dkeybd.dll (Oak Technology Inc.)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/16 11:46:48 | 000,013,800 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwhnt.sys
[2012/02/16 11:46:47 | 000,177,640 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdm.sys
[2012/02/16 11:46:47 | 000,157,672 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadbus.sys
[2012/02/16 11:46:47 | 000,016,872 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdfl.sys
[2012/02/16 11:46:47 | 000,013,288 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcmnt.sys
[2012/02/16 11:36:21 | 000,000,000 | —D | C] – C:\Windows\SysWow64\System32
[2012/02/16 11:34:34 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Local\Samsung
[2012/02/16 11:34:31 | 000,000,000 | —D | C] – C:\Users\Marcos\Documents\samsung
[2012/02/16 11:34:31 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\Samsung
[2012/02/16 11:33:01 | 000,013,800 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwh.sys
[2012/02/16 11:33:01 | 000,013,288 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcm.sys
[2012/02/16 11:31:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\MarkAny
[2012/02/13 18:05:48 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\NotTetris
[2012/02/13 01:50:43 | 000,005,632 | —- | C] ( ) – C:\Users\Marcos\Desktop\cssh.exe
[2012/02/10 02:47:16 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/02/09 09:12:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2012/02/09 09:12:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2012/02/08 14:46:06 | 000,000,000 | —D | C] – C:\TEMP
[2012/02/08 14:37:43 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012/02/08 14:37:43 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\IrfanView
[2012/02/08 14:37:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\IrfanView
[2012/02/08 14:35:07 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\DeskProbes
[2012/02/08 13:25:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\iamhrh
[2012/02/06 13:15:31 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2012/02/05 21:09:46 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2012/02/05 21:09:46 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2012/01/26 19:29:04 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Local\Akamai
[2012/01/25 13:38:13 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\vDub
[2012/01/25 13:30:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2012/01/25 13:30:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\ffdshow
[2012/01/20 12:32:40 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\Malwarebytes
[2012/01/20 12:32:15 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2012/01/20 12:32:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/20 12:32:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/01/20 12:32:12 | 000,023,152 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/01/20 12:32:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/01/20 12:20:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\RockScroll
[2012/01/20 01:37:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\7E39D
[2012/01/20 01:37:20 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\1837E
[2012/01/20 01:37:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\LP
[2012/01/20 01:37:05 | 000,000,000 | —D | C] – C:\Windows\system64
[2012/01/20 01:10:46 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\DustForce
[2012/01/19 11:44:12 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Local\TSVNCache
[2012/01/18 21:51:38 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\TortoiseSVN
[2012/01/18 21:50:32 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\Subversion
[2012/01/18 21:50:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TortoiseSVN
[2012/01/18 21:50:23 | 000,000,000 | —D | C] – C:\Program Files\TortoiseSVN
[2012/01/18 21:50:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\TortoiseOverlays
[2012/01/18 00:32:27 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overgrowth
[2012/01/18 00:21:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2012/01/18 00:21:43 | 000,000,000 | —D | C] – C:\ProgramData\Hi-Rez Studios
[2012/01/18 00:21:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Hi-Rez Studios
[2012/01/17 21:48:09 | 000,073,728 | —- | C] ( ) – C:\Windows\System\vdremote.dll
[2012/01/17 21:48:09 | 000,065,536 | —- | C] ( ) – C:\Windows\System\vdsvrlnk.dll
[2012/01/17 13:23:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/01/17 13:22:37 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/01/17 13:22:37 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/01/17 13:22:37 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/16 12:19:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000UA.job
[2012/02/16 11:41:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/02/16 11:41:03 | 2146,332,671 | -HS- | M] () – C:\hiberfil.sys
[2012/02/16 11:39:04 | 000,866,562 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/16 11:39:04 | 000,726,452 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/02/16 11:39:04 | 000,146,470 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/02/16 11:38:53 | 000,866,562 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/16 11:34:29 | 000,001,957 | —- | M] () – C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/02/16 11:05:03 | 000,000,000 | -HS- | M] () – C:\Windows\SysNative\dds_trash_log.cmd
[2012/02/15 18:46:21 | 000,276,221 | —- | M] () – C:\Users\Marcos\Desktop\skrillexPizza.jpg
[2012/02/15 17:19:01 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000Core.job
[2012/02/14 23:02:11 | 000,014,096 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/14 23:02:11 | 000,014,096 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/09 22:21:33 | 000,132,082 | —- | M] () – C:\Users\Marcos\Desktop\schoolID.jpg
[2012/02/09 22:04:52 | 001,498,485 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-09 22.04.53.jpg
[2012/02/09 19:06:32 | 000,001,178 | —- | M] () – C:\Users\Public\Desktop\Samsung Kies mini.lnk
[2012/02/09 17:53:08 | 000,040,152 | —- | M] () – C:\Users\Marcos\Desktop\orig.png
[2012/02/09 17:22:12 | 000,058,114 | —- | M] () – C:\Users\Marcos\Desktop\convo.png
[2012/02/09 17:22:11 | 000,000,132 | —- | M] () – C:\Users\Marcos\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/02/09 17:20:40 | 000,068,416 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-09_1720.png
[2012/02/08 14:37:43 | 000,001,894 | —- | M] () – C:\Users\Marcos\Desktop\IrfanView Thumbnails.lnk
[2012/02/08 14:37:43 | 000,001,002 | —- | M] () – C:\Users\Marcos\Desktop\IrfanView.lnk
[2012/02/08 13:28:33 | 000,135,258 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-08 13.21.09.jpg
[2012/02/07 23:41:55 | 000,000,003 | —- | M] () – C:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/02/05 21:09:57 | 000,014,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2012/02/05 21:09:56 | 001,008,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\user32.dll
[2012/02/05 21:09:56 | 000,419,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\systemcpl.dll
[2012/02/05 21:09:56 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2012/02/02 13:57:43 | 000,063,779 | —- | M] () – C:\Users\Marcos\Desktop\LIKEUTPA2.jpg
[2012/02/02 13:54:44 | 000,143,179 | —- | M] () – C:\Users\Marcos\Desktop\LIKEUTPA.jpg
[2012/02/02 13:51:22 | 000,158,215 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-02_1351.png
[2012/02/01 12:06:09 | 000,819,841 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-01 11.49.15.jpg
[2012/02/01 12:03:00 | 000,000,974 | —- | M] () – C:\Users\Public\Desktop\CPUID HWMonitor.lnk
[2012/01/25 13:27:24 | 008,126,464 | —- | M] () – C:\Users\Marcos\Desktop\VideoOut.avi
[2012/01/25 13:27:22 | 007,827,494 | —- | M] () – C:\Users\Marcos\Desktop\Do You Like Bears_.mp4
[2012/01/24 15:43:12 | 001,519,383 | —- | M] () – C:\Users\Marcos\Desktop\ContextMenu.gif
[2012/01/24 15:41:10 | 001,521,256 | —- | M] () – C:\Users\Marcos\Desktop\ContextMenu
[2012/01/24 15:09:42 | 000,049,420 | —- | M] () – C:\Users\Marcos\Desktop\2012-01-24_1509.png
[2012/01/22 23:34:35 | 000,921,602 | —- | M] () – C:\Users\Marcos\Desktop\MenuPreview.gif
[2012/01/22 13:30:32 | 000,009,644 | —- | M] () – C:\Users\Marcos\Desktop\unclerayshead.png
[2012/01/21 17:07:49 | 001,236,011 | —- | M] () – C:\Users\Marcos\Desktop\RTS 2012-01-21 17-05-32-64.gif
[2012/01/21 12:34:27 | 000,008,288 | —- | M] () – C:\Users\Marcos\Desktop\RegEditBackup.reg
[2012/01/20 12:33:02 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/19 23:16:49 | 000,134,522 | —- | M] () – C:\Users\Marcos\Desktop\Untitled-2.jpg
[2012/01/19 21:07:35 | 000,714,119 | —- | M] () – C:\Users\Marcos\Desktop\TileEngine 2012-01-19 21-04-52-65.gif
[2012/01/18 13:58:49 | 001,421,165 | —- | M] () – C:\Users\Marcos\Desktop\TileEngine 2012-01-18 13-55-59-90.gif
[2012/01/18 02:18:45 | 000,002,046 | —- | M] () – C:\Users\Marcos\Desktop\Tribes Ascend Closed Beta.lnk
[2012/01/18 00:21:44 | 000,002,037 | —- | M] () – C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
[2012/01/18 00:21:44 | 000,002,028 | —- | M] () – C:\Users\Public\Desktop\Tribes Ascend Closed Beta.lnk
[2012/01/17 21:49:47 | 001,381,704 | —- | M] () – C:\Users\Marcos\Desktop\TileEngine 2012-01-17 21-46-43-47.gif
[2012/01/17 13:13:00 | 000,887,998 | —- | M] () – C:\Users\Marcos\Desktop\AStarDemo.gif
[2012/01/17 13:13:00 | 000,887,998 | —- | M] () – C:\Users\Marcos\Desktop\AStarDemo - Copy.gif
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/16 11:34:29 | 000,001,957 | —- | C] () – C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/02/15 18:45:43 | 000,276,221 | —- | C] () – C:\Users\Marcos\Desktop\skrillexPizza.jpg
[2012/02/09 22:21:31 | 000,132,082 | —- | C] () – C:\Users\Marcos\Desktop\schoolID.jpg
[2012/02/09 22:06:29 | 001,498,485 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-09 22.04.53.jpg
[2012/02/09 19:06:32 | 000,001,178 | —- | C] () – C:\Users\Public\Desktop\Samsung Kies mini.lnk
[2012/02/09 17:53:08 | 000,040,152 | —- | C] () – C:\Users\Marcos\Desktop\orig.png
[2012/02/09 17:22:10 | 000,058,114 | —- | C] () – C:\Users\Marcos\Desktop\convo.png
[2012/02/09 17:20:40 | 000,068,416 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-09_1720.png
[2012/02/08 14:37:43 | 000,001,894 | —- | C] () – C:\Users\Marcos\Desktop\IrfanView Thumbnails.lnk
[2012/02/08 14:37:43 | 000,001,002 | —- | C] () – C:\Users\Marcos\Desktop\IrfanView.lnk
[2012/02/08 13:25:53 | 000,135,258 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-08 13.21.09.jpg
[2012/02/07 23:41:55 | 000,000,003 | —- | C] () – C:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/02/05 11:49:17 | 000,000,000 | -HS- | C] () – C:\Windows\SysNative\dds_trash_log.cmd
[2012/02/02 13:57:41 | 000,063,779 | —- | C] () – C:\Users\Marcos\Desktop\LIKEUTPA2.jpg
[2012/02/02 13:54:41 | 000,143,179 | —- | C] () – C:\Users\Marcos\Desktop\LIKEUTPA.jpg
[2012/02/02 13:51:22 | 000,158,215 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-02_1351.png
[2012/02/01 12:02:51 | 000,819,841 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-01 11.49.15.jpg
[2012/01/25 13:43:50 | 008,126,464 | —- | C] () – C:\Users\Marcos\Desktop\VideoOut.avi
[2012/01/25 13:30:12 | 000,079,360 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012/01/25 13:27:20 | 007,827,494 | —- | C] () – C:\Users\Marcos\Desktop\Do You Like Bears_.mp4
[2012/01/24 15:42:50 | 001,519,383 | —- | C] () – C:\Users\Marcos\Desktop\ContextMenu.gif
[2012/01/24 15:40:49 | 001,521,256 | —- | C] () – C:\Users\Marcos\Desktop\ContextMenu
[2012/01/24 15:09:42 | 000,049,420 | —- | C] () – C:\Users\Marcos\Desktop\2012-01-24_1509.png
[2012/01/22 23:34:23 | 000,921,602 | —- | C] () – C:\Users\Marcos\Desktop\MenuPreview.gif
[2012/01/22 13:30:30 | 000,009,644 | —- | C] () – C:\Users\Marcos\Desktop\unclerayshead.png
[2012/01/21 17:07:34 | 001,236,011 | —- | C] () – C:\Users\Marcos\Desktop\RTS 2012-01-21 17-05-32-64.gif
[2012/01/21 12:34:27 | 000,008,288 | —- | C] () – C:\Users\Marcos\Desktop\RegEditBackup.reg
[2012/01/20 12:33:02 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/19 23:16:47 | 000,134,522 | —- | C] () – C:\Users\Marcos\Desktop\Untitled-2.jpg
[2012/01/19 21:07:29 | 000,714,119 | —- | C] () – C:\Users\Marcos\Desktop\TileEngine 2012-01-19 21-04-52-65.gif
[2012/01/18 13:58:35 | 001,421,165 | —- | C] () – C:\Users\Marcos\Desktop\TileEngine 2012-01-18 13-55-59-90.gif
[2012/01/18 02:18:45 | 000,002,046 | —- | C] () – C:\Users\Marcos\Desktop\Tribes Ascend Closed Beta.lnk
[2012/01/18 00:21:44 | 000,002,037 | —- | C] () – C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
[2012/01/18 00:21:44 | 000,002,028 | —- | C] () – C:\Users\Public\Desktop\Tribes Ascend Closed Beta.lnk
[2012/01/17 21:49:28 | 001,381,704 | —- | C] () – C:\Users\Marcos\Desktop\TileEngine 2012-01-17 21-46-43-47.gif
[2012/01/17 13:14:38 | 000,887,998 | —- | C] () – C:\Users\Marcos\Desktop\AStarDemo - Copy.gif
[2012/01/17 13:11:17 | 000,887,998 | —- | C] () – C:\Users\Marcos\Desktop\AStarDemo.gif
[2011/12/24 17:00:21 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2011/12/12 16:47:16 | 000,001,456 | —- | C] () – C:\Users\Marcos\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/12/12 16:41:28 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011/11/29 16:38:18 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2011/11/29 16:38:12 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2011/11/29 16:38:12 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011/11/29 16:38:12 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011/11/29 16:38:12 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011/10/15 00:54:52 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/09/29 23:23:52 | 000,280,904 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/09/29 23:23:51 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/09/25 22:27:51 | 000,005,632 | —- | C] () – C:\Users\Marcos\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/08 21:04:25 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2011/07/24 16:03:55 | 000,007,605 | —- | C] () – C:\Users\Marcos\AppData\Local\Resmon.ResmonCfg
[2011/07/13 17:07:35 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/07/07 21:32:43 | 000,866,562 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/06 08:58:12 | 000,052,387 | —- | C] () – C:\Windows\MaxwellMayaPluginUninstall.exe
[2011/07/04 15:08:40 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/07/13 23:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/09/14 19:18:21 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\.minecraft
[2012/01/20 12:40:46 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\1837E
[2011/10/17 01:46:31 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Ableton
[2011/12/25 16:00:41 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Astroburn Lite
[2011/07/07 00:30:56 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\AtomZombieData
[2011/07/15 18:58:41 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Audacity
[2011/07/06 09:37:11 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Autodesk
[2011/07/12 11:50:45 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/30 01:38:18 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Crayon Physics Deluxe
[2011/11/11 22:33:38 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\digipen
[2012/02/16 11:42:20 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Dropbox
[2011/12/11 00:34:38 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\FileZilla
[2011/11/13 13:01:37 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\fotw
[2011/09/01 16:49:34 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Golly
[2011/10/17 18:45:27 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Image-Line
[2011/10/03 20:55:05 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\inkscape
[2012/02/08 14:37:43 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\IrfanView
[2011/09/27 22:47:44 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\JetBrains
[2011/09/21 00:37:52 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\JustDecompile
[2011/07/30 01:23:14 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Lazy 8 Studios
[2012/02/13 18:06:00 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\LOVE
[2011/11/13 04:15:49 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Nicalis
[2011/07/04 16:32:16 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Notepad++
[2011/10/04 21:18:17 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\NuGet
[2011/07/04 16:46:09 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\OpenOffice.org
[2011/11/01 02:23:35 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Polynomial
[2011/07/15 18:51:59 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Propellerhead Software
[2011/07/27 17:03:40 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\REAPER
[2012/02/16 11:34:31 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Samsung
[2012/01/26 00:40:27 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Scoregasm
[2011/09/19 18:48:35 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/01/18 21:50:32 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Subversion
[2011/12/06 01:01:11 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\superhudeditor
[2011/08/28 10:11:19 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Thunderbird
[2011/11/29 00:19:39 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\UDP Software
[2011/07/24 16:43:38 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Unity
[2012/02/02 02:40:52 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\uTorrent
[2011/09/29 22:28:36 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\VertexDispenser
[2011/11/01 12:29:15 | 000,000,000 | —D | M] – C:\Users\Marcos\AppData\Roaming\Voxatron
[2012/02/16 11:37:14 | 000,032,594 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/11/20 06:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/07/04 15:09:34 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/02/16 11:41:03 | 2146,332,671 | -HS- | M] () – C:\hiberfil.sys
[2012/02/16 11:41:10 | 4293,435,391 | -HS- | M] () – C:\pagefile.sys
[2011/09/30 15:35:17 | 000,015,104 | —- | M] () – C:\shared.log
[2012/02/10 02:47:35 | 000,160,884 | —- | M] () – C:\TDSSKiller.2.7.11.0_10.02.2012_02.45.25_log.txt

< %systemroot%\Fonts\*.com >
[2009/07/13 23:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 14:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/04 12:52:46 | 000,000,221 | -HS- | M] () – C:\Users\Marcos\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2006/12/19 15:20:48 | 000,005,632 | —- | M] ( ) – C:\Users\Marcos\Desktop\cssh.exe
[2012/01/04 18:50:02 | 000,329,216 | —- | M] (Seancode) – C:\Users\Marcos\Desktop\Terrafirma.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\system64] -> \systemroot\system32 -> Mount Point

< End of report >

OTL Extras logfile created on: 2/16/2012 12:29:02 PM - Run 1
OTL by OldTimer - Version 3.2.32.0 Folder = C:\Users\Marcos\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.17 Gb Available Physical Memory | 77.19% Memory free
16.00 Gb Paging File | 14.10 Gb Available in Paging File | 88.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 30.74 Gb Free Space | 22.00% Space Free | Partition Type: NTFS
Drive E: | 698.64 Gb Total Space | 337.39 Gb Free Space | 48.29% Space Free | Partition Type: NTFS

Computer Name: MARCOS-PC | User Name: Marcos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{034106B5-54B7-467F-B477-5B7DBB492624}" = Microsoft Sync Framework Services v1.0 SP1 (x64)
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{1AB7EDC5-D891-34C5-9FF1-BE6A85ACC44B}" = Microsoft Team Foundation Server 2010 Object Model - ENU
"{1B1D83BE-BAB8-4220-A850-036C67590C73}" = TortoiseSVN 1.7.4.22459 (64 bit)
"{1CB6C387-65A7-327F-B4A5-7DDC75A291AF}" = Microsoft Visual Studio 2010 Office Developer Tools (x64)
"{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x64)
"{1D5CE83C-BFDD-4668-8BCB-E8614334A657}" = Adobe Photoshop Lightroom 3.4 64-bit
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{4529F749-C362-4119-AFA0-0A3F1CA924AB}" = Autodesk MatchMover 2012 64-bit
"{4554DBB6-40D0-43BB-ADB8-75399FF11284}" = ANTS Memory Profiler 7
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{491DF203-7B61-4F0E-BDCB-A1218C4DAFE9}" = Native Instruments Massive
"{4A8CE6D7-4D52-43B9-970B-03FC75FAD667}" = Microsoft SQL Server System CLR Types (x64)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{502EAA3C-5887-4B62-83BC-7FCE593A8A89}" = ANTS Performance Profiler 6
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{5D068141-189F-39E2-A052-E40D4B561256}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{662014D2-0450-37ED-ABAE-157C88127BEB}" = Visual Studio 2010 Prerequisites - English
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7608CF6F-EB13-4E89-A4F0-8732FB6EAF98}" = Maxwell Shell Extension (x64)
"{7A780DF7-359E-42F6-A258-A1AA602024F4}" = .NET Reflector 7
"{7ACE202B-1B01-4B43-B6AE-03D66D621CDE}" = Microsoft SQL Server 2008 RsFx Driver
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8438EC02-B8A9-462D-AC72-1B521349C001}" = Microsoft Sync Framework Runtime v1.0 SP1 (x64)
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{918473BA-67C9-498B-BE7A-BC3A3CBC3338}" = TortoiseHg 2.1.3 (x64)
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{94D70749-4281-39AC-AD90-B56A0E0A402E}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9E6BB4E4-0B20-4922-AA37-260FA5ACFBA5}" = Autodesk Maya 2012 64-bit
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B40EE88B-400A-4266-A17B-E3DE64E94431}" = Microsoft SQL Server 2008 Setup Support Files
"{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}" = Microsoft SQL Server 2008 Native Client
"{BCA26999-EC22-3007-BB79-638913079C9A}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU
"{BCF07271-A853-4D3A-B668-4B752174CAA8}" = iTunes
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{C9A5048A-26A6-440B-A059-9DF9956C4D44}" = Yamaha USB-MIDI Driver
"{CC7C5BA5-0010-1033-B966-42899C00BD23}" = Autodesk Mudbox 2012 64-bit - English
"{CC7C5BA5-09B5-428E-B966-42899C00BD23}" = Autodesk Mudbox 2012 64-bit - English
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{DA67488A-2689-4F10-B90F-D2F6977509D6}" = Microsoft SQL Server 2008 R2 Management Objects (x64)
"{DE0248C8-0701-4132-95A5-9130D22B3A24}" = ANTS Profiler Visual Studio Add-in 1
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{F5079164-1DB9-3BDA-853B-F78AF67CE071}" = Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FC4AD39F-9DCE-4BD0-B7D0-7C81CEB9F04B}" = NVIDIA PhysX Plug-in for Autodesk Maya 2012 64 bit
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"Autodesk Maya 2012 64-bit" = Autodesk Maya 2012 64-bit
"Autodesk Mudbox 2012 64-bit - English" = Autodesk Mudbox 2012 64-bit - English
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.58
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.18
"Mari 1.3v1_is1" = Mari 1.3v1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"Microsoft Team Foundation Server 2010 Object Model - ENU" = Microsoft Team Foundation Server 2010 Object Model - ENU
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"Nuke 6.2v2_is1" = Nuke 6.2v2
"V-Ray for Maya 2012 for x64" = V-Ray for Maya 2012 for x64
"Wacom Tablet Driver" = Wacom Tablet
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.44-1 (x64)
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01C79EF3-DE84-4B56-B638-8BEA0D507506}" = Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{0666E46E-A860-4353-BE6D-13AA72FABB57}" = Microsoft XNA Game Studio Platform Tools
"{08C84CC6-E7FD-4B2D-BBF9-B02CC90EE031}" = Microsoft XNA Game Studio 4.0 (Shared Components)
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0DDCEC37-369C-484B-B16D-B4413FD42FB9}" = Microsoft SQL Server 2008 R2 Data-Tier Application Framework
"{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}" = Microsoft Sync Framework SDK v1.0 SP1
"{0FDCF6BC-AB79-4CEF-9A7D-01FD838A6C61}" = JetBrains ReSharper 6.0
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{21AF2C88-A2D7-436D-A261-017865640E84}" = Imgur Uploader
"{265E2F1D-0025-45DF-B83B-8320466108A8}" = Python 3.2 pygame-1.9.2a0
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 30
"{2A2F3AE8-246A-4252-BB26-1BEB45627074}" = Microsoft SQL Server System CLR Types
"{2AD738DC-FC24-4342-A2DA-BB6DCCF6B048}" = Jing
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}" = Microsoft Games for Windows - LIVE
"{2D9FEBEE-F1B7-344F-BFDF-760E18332D96}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{34b2530c-6349-4292-9dc3-60bda4aed93c}" = Python 3.2.1
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF010}" = Tribes Ascend Closed Beta
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3F4EB5FE-B5BE-4069-A5A8-6D9262E1B379}" = Microsoft XNA Game Studio 4.0 Documentation
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{41B31ABE-5A6E-498A-8F28-3BA3B8779A41}" = Dotfuscator Software Services - Community Edition
"{45C8D17D-B5E0-4e93-8370-4329AB16D2A0}" = Battlefield 3™ Open Beta
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59F24743-2EA1-3A45-B8C2-6E0E1E078FA8}" = Microsoft Visual C# 2010 Express - ENU
"{5AFD94F5-CB9F-4CEF-B271-2A636C895451}_is1" = Window On Top version 1.2
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{68BD57D3-D606-411E-A7E0-3EB6EA5660F6}" = Microsoft XNA Game Studio 4.0 (Redists)
"{6A86554B-8928-30E4-A53C-D7337689134D}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{729A3000-BC8A-3B74-BA5D-5068FE12D70C}" = Microsoft Visual F# 2.0 Runtime
"{73BE04D9-BA0E-4BAF-9C9D-677278BDB3DC}" = Microsoft XNA Game Studio 4.0 (ARP entry)
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{78C3657E-742C-40B1-9F53-E5A921D40F17}" = Microsoft SQL Server 2008 R2 Transact-SQL Language Service
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C496FBF-DB4A-468D-A3A1-15E127382218}" = Microsoft XNA Game Studio 4.0 (Visual Studio)
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-00AF-0409-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B55759D-424F-4CB1-B84E-AAE83CC1D20A}_is1" = Nitronic Rush (2011-11-11) version 20111111.0
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{C0E8FE43-C35B-451D-B35F-D4BD056D70E7}" = Camtasia Studio 7
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C91A289F-A5F1-4D98-A0AA-453F0FBAE6F4}_is1" = Deity
"{C95443CF-EE78-4CB5-A25E-6CF71C0127C5}" = Telerik JustDecompile Beta
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D179B513-AD43-4013-AC50-C16107A0A02D}" = LogMeIn Hamachi
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.8 Game
"{D6B15AE6-B052-363E-B6BB-C4714CBA6509}" = Microsoft Visual Studio 2010 Professional - ENU
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E14F0598-ACB9-4953-90E0-458B880852CB}" = RockScroll
"{E5AE9031-79A5-4627-9641-BEFA82819B08}" = Microsoft SQL Server 2008 R2 Data-Tier Application Project
"{E82097B9-A3B8-404A-9A92-AC16A8AC9576}" = Adobe After Effects CS5.5
"{EE43894E-FDCF-4A8C-BCD6-3AAA9A48B486}" = Kies mini
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{FAB1F336-1B7C-4057-A7BC-2922CD82A781}" = Ralink RT6x Wireless LAN Card
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ASIO4ALL" = ASIO4ALL
"Astroburn Lite" = Astroburn Lite
"Audacity_is1" = Audacity 1.2.6
"Build Your Own Net Dream" = Build Your Own Net Dream (remove only)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"Contour Storyteller 3.0.8" = Contour Storyteller
"Diablo III Beta" = Diablo III Beta
"dRasterNEX_is1" = NEX [removed]
"ESN Sonar-0.70.0" = ESN Sonar
"ffdshow_is1" = ffdshow v1.1.4257 [2012-01-15]
"FileZilla Client" = FileZilla Client 3.5.0
"FL Studio 10" = FL Studio 10
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"Fraps" = Fraps (remove only)
"Google Desktop" = Google Desktop
"IL Download Manager" = IL Download Manager
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{EE43894E-FDCF-4A8C-BCD6-3AAA9A48B486}" = Kies mini
"IrfanView" = IrfanView (remove only)
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"Live 8.2.6" = Live 8.2.6
"LogMeIn Hamachi" = LogMeIn Hamachi
"LOVE" = LOVE (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Maxwell 2" = Maxwell 2
"MaxwellMaya" = Maxwell Plugin for Maya
"Microsoft Visual C# 2010 Express - ENU" = Microsoft Visual C# 2010 Express - ENU
"Microsoft Visual Studio 2010 Professional - ENU" = Microsoft Visual Studio 2010 Professional - ENU
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Mozilla Thunderbird 9.0.1 (x86 en-US)" = Mozilla Thunderbird 9.0.1 (x86 en-US)
"Native Instruments Massive" = Native Instruments Massive
"Notepad++" = Notepad++
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"Orcs Must Die!_is1" = Orcs Must Die!
"OVERGROWTH" = Overgrowth (remove only)
"PowerISO" = PowerISO
"Proun" = Proun
"PunkBusterSvc" = PunkBuster Services
"RealFlow 5" = RealFlow 5
"REAPER" = REAPER
"ReCycle_is1" = ReCycle 2.1.2
"Rigs of Rods 0.38.67" = Rigs of Rods 0.38.67
"Steam App 105600" = Terraria
"Steam App 107100" = Bastion
"Steam App 113200" = The Binding Of Isaac
"Steam App 12210" = Grand Theft Auto IV
"Steam App 202410" = Scoregasm
"Steam App 22000" = World of Goo
"Steam App 22350" = Brink
"Steam App 24420" = Aquaria
"Steam App 25010" = Lugaru HD
"Steam App 26500" = Cogs
"Steam App 26800" = Braid
"Steam App 26900" = Crayon Physics Deluxe
"Steam App 29180" = Osmos
"Steam App 37400" = Time Gentlemen, Please!
"Steam App 37420" = Ben There, Dan That!
"Steam App 40700" = Machinarium
"Steam App 40720" = Samorost 2
"Steam App 41100" = Hammerfight
"Steam App 44320" = DiRT 3
"Steam App 50000" = Nimbus
"Steam App 55040" = Atom Zombie Smasher
"Steam App 70300" = VVVVVV
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 91600" = Sanctum
"Steam App 93200" = Revenge of the Titans
"Steam App 94200" = Jamestown
"Steam App 9500" = Gish
"Steam App 96200" = Steel Storm: Burning Retribution
"Steam App 98200" = Frozen Synapse
"Steam App 99700" = NightSky
"Unwrella_Maya" = Unwrella_Maya 2.13
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.10
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"XNA Game Studio 4.0" = Microsoft XNA Game Studio 4.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"0ab833f7f99039b3" = RoadWare
"Akamai" = Akamai NetSession Interface
"b14223fc30a0843d" = RTS
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/14/2012 9:12:59 PM | Computer Name = Marcos-PC | Source = Software Protection Platform Service | ID = 8193
Description = License Activation Scheduler (sppuinotify.dll) failed with the following
error code: 0x80070005

Error - 2/14/2012 10:12:59 PM | Computer Name = Marcos-PC | Source = Software Protection Platform Service | ID = 8193
Description = License Activation Scheduler (sppuinotify.dll) failed with the following
error code: 0x80070005

Error - 2/14/2012 11:12:59 PM | Computer Name = Marcos-PC | Source = Software Protection Platform Service | ID = 8193
Description = License Activation Scheduler (sppuinotify.dll) failed with the following
error code: 0x80070005

Error - 2/15/2012 12:12:59 AM | Computer Name = Marcos-PC | Source = Software Protection Platform Service | ID = 8193
Description = License Activation Scheduler (sppuinotify.dll) failed with the following
error code: 0x80070005

Error - 2/15/2012 2:51:15 AM | Computer Name = Marcos-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.

Error - 2/15/2012 6:28:25 PM | Computer Name = Marcos-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.

Error - 2/16/2012 1:04:08 PM | Computer Name = Marcos-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.

Error - 2/16/2012 1:31:31 PM | Computer Name = Marcos-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 16.0.912.77 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 990 Start
Time: 01cceccd13616ac0 Termination Time: 6 Application Path: C:\Users\Marcos\AppData\Local\Google\Chrome\Application\chrome.exe

Report
Id: 0cb513bd-58c4-11e1-80c2-00044b15890c

Error - 2/16/2012 1:37:10 PM | Computer Name = Marcos-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_Schedule, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc00000fd Fault offset: 0x0000000000371312 Faulting process
id: 0x288 Faulting application start time: 0x01ccecccfe116c60 Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: unknown Report Id: da53796c-58c4-11e1-80c2-00044b15890c

Error - 2/16/2012 1:41:16 PM | Computer Name = Marcos-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.

[ System Events ]
Error - 12/22/2011 2:37:44 PM | Computer Name = Marcos-PC | Source = PNRPSvc | ID = 102
Description =

Error - 12/22/2011 2:37:44 PM | Computer Name = Marcos-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 12/22/2011 2:37:44 PM | Computer Name = Marcos-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 12/22/2011 2:37:44 PM | Computer Name = Marcos-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 12/22/2011 2:37:44 PM | Computer Name = Marcos-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 12/22/2011 2:39:49 PM | Computer Name = Marcos-PC | Source = DCOM | ID = 10001
Description =

Error - 12/22/2011 3:25:03 PM | Computer Name = Marcos-PC | Source = DCOM | ID = 10001
Description =

Error - 12/22/2011 4:23:23 PM | Computer Name = Marcos-PC | Source = PNRPSvc | ID = 102
Description =

Error - 12/22/2011 4:23:23 PM | Computer Name = Marcos-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 12/22/2011 4:23:23 PM | Computer Name = Marcos-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535


< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Right-click and Run as Administrator CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-
Thank you Jeff. CKScanner - Additional Security Risks - These are not necessarily bad c:\program files\autodesk\maya2012\brushes\fun\cracks.mel c:\program files\autodesk\maya2012\brushes\fun\cracks.mel.icon c:\program files\autodesk\maya2012\presets\nparticles\examples\crackegg.ma c:\program files\autodesk\maya2012\presets\nparticles\examples\.mayaswatches\crackegg.ma.swatch c:\program files\autodesk\maya2012\resources\l10n\ja_jp\scripts\crackshatter.res.mel c:\program files\autodesk\maya2012\scripts\others\crackshatter.mel c:\program files\autodesk\maya2012\scripts\others\crackshatter.res.mel c:\program files (x86)\common files\native instruments\shared content\sounds\massive\crackle carl.ksd c:\program files (x86)\common files\native instruments\shared content\sounds\massive\digitoy crackle.ksd c:\program files (x86)\data realms\cortex command\base.rte\activities\unused\coalition crackdown.lua c:\program files (x86)\digipen\nitronic rush\effects\tvscreen_cracked.fx c:\program files (x86)\digipen\nitronic rush\effects\tvscreen_cracked.fxo c:\program files (x86)\digipen\nitronic rush\textures\cracked_diff.tga c:\program files (x86)\digipen\nitronic rush\textures\cracked_norm.tga c:\program files (x86)\digipen\nitronic rush\textures\road_crack_diff.tga c:\program files (x86)\digipen\nitronic rush\textures\road_crack_emit.tga c:\program files (x86)\image-line\fl studio 10\plugins\fruity\effects\hardcore\presets\i cracked my tube!.hdprg c:\program files (x86)\image-line\fl studio 10\plugins\fruity\generators\drumaxx\drum patches\sound fx\crack.dmpatch c:\program files (x86)\image-line\fl studio 10\plugins\fruity\generators\drumpad\drum patches\sound fx\crack.dmpatch c:\program files (x86)\wolfire\overgrowth\data\objects\sounds\icecrack.xml c:\program files (x86)\wolfire\overgrowth\data\sounds\ambient\amb_ice_crack.xml c:\program files (x86)\wolfire\overgrowth\data\textures\terrain\detailtextures\cracked_ground.tga_converted.dds c:\program files (x86)\wolfire\overgrowth\data\textures\terrain\detailtextures\cracked_ground_normal.tga_converted.dds c:\users\marcos\documents\ableton\library\presets\audio effects\vinyl distortion\crack.adv scanner sequence 3.ZZ.11.NBABXQ —– EOF —–
Hi Socram484,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Okay ran ComboFix. I figured it is worth mentioning that the first time it ran my computer locked up on an all black screen that I could only see the mouse cursor on. Couldn't move it or anything, so I was forced to manually restart after waiting for a while. After running it a second time everything worked fine. ComboFix 12-02-16.02 - Marcos 02/16/2012 19:50:59.2.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8191.6334 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Marcos\AppData\Local\Temp\c06086cf-47b1-4760-b263-4e4271d9922f\CliSecureRT.dll c:\windows\assembly\temp\@ c:\windows\assembly\temp\cfg.ini . —- Previous Run ——- . c:\program files (x86)\LP\90C1\1831.tmp c:\program files (x86)\LP\90C1\255A.tmp c:\program files (x86)\LP\90C1\9E91.tmp c:\programdata\Propellerhead Software\ReCycle\ReCycle212.dat c:\users\Marcos\AppData\Local\Temp\c06086cf-47b1-4760-b263-4e4271d9922f\CliSecureRT.dll c:\users\Marcos\AppData\Roaming\Love\not_tetris_2\highscoresA.txt c:\users\Marcos\AppData\Roaming\Love\not_tetris_2\options.txt c:\users\Marcos\AppData\Roaming\Love\Wildfire\autosave.lua c:\users\Marcos\AppData\Roaming\Love\WriteTests\faggots.lua c:\users\Marcos\AppData\Roaming\Propellerhead Software\ReCycle\ReCycle Preferences File.prf c:\windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\GAC_64\Desktop.ini c:\windows\system32\consrv.dll c:\windows\SysWow64\muzapp.exe c:\windows\SysWow64\system32\3DAudio.ax c:\windows\SysWow64\system32\avrt.dll c:\windows\SysWow64\system32\cis-2.4.dll c:\windows\SysWow64\system32\issacapi_bs-2.3.dll c:\windows\SysWow64\system32\issacapi_pe-2.3.dll c:\windows\SysWow64\system32\issacapi_se-2.3.dll c:\windows\SysWow64\system32\MACXMLProto.dll c:\windows\SysWow64\system32\MaDRM.dll c:\windows\SysWow64\system32\MaJGUILib.dll c:\windows\SysWow64\system32\MAMACExtract.dll c:\windows\SysWow64\system32\MASetupCleaner.exe c:\windows\SysWow64\system32\MaXMLProto.dll c:\windows\SysWow64\system32\mfplat.dll c:\windows\SysWow64\system32\MK_Lyric.dll c:\windows\SysWow64\system32\MSCLib.dll c:\windows\SysWow64\system32\MSFLib.dll c:\windows\SysWow64\system32\MSLUR71.dll c:\windows\SysWow64\system32\msvcp60.dll c:\windows\SysWow64\system32\MTTELECHIP.dll c:\windows\SysWow64\system32\MTXSYNCICON.dll c:\windows\SysWow64\system32\muzaf1.dll c:\windows\SysWow64\system32\muzapp.dll c:\windows\SysWow64\system32\muzapp.exe c:\windows\SysWow64\system32\muzdecode.ax c:\windows\SysWow64\system32\muzeffect.ax c:\windows\SysWow64\system32\muzmp4sp.ax c:\windows\SysWow64\system32\muzmpgsp.ax c:\windows\SysWow64\system32\muzoggsp.ax c:\windows\SysWow64\system32\muzwmts.dll c:\windows\SysWow64\system32\psapi.dll E:\install.exe . . ((((((((((((((((((((((((( Files Created from 2012-01-17 to 2012-02-17 ))))))))))))))))))))))))))))))) . . 2012-02-17 01:55 . 2012-02-17 01:55 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-02-16 17:46 . 2011-12-08 04:22 13800 —-a-w- c:\windows\system32\drivers\ssadwhnt.sys 2012-02-16 17:46 . 2011-12-08 04:22 177640 —-a-w- c:\windows\system32\drivers\ssadmdm.sys 2012-02-16 17:46 . 2011-12-08 04:22 16872 —-a-w- c:\windows\system32\drivers\ssadmdfl.sys 2012-02-16 17:46 . 2011-12-08 04:22 157672 —-a-w- c:\windows\system32\drivers\ssadbus.sys 2012-02-16 17:46 . 2011-12-08 04:22 13288 —-a-w- c:\windows\system32\drivers\ssadcmnt.sys 2012-02-16 17:34 . 2012-02-17 01:47 ——– d—–w- c:\users\Marcos\AppData\Local\Samsung 2012-02-16 17:34 . 2012-02-16 17:34 ——– d—–w- c:\users\Marcos\AppData\Roaming\Samsung 2012-02-16 17:33 . 2011-10-27 01:25 13800 —-a-w- c:\windows\system32\drivers\ssadwh.sys 2012-02-16 17:33 . 2011-10-27 01:25 13288 —-a-w- c:\windows\system32\drivers\ssadcm.sys 2012-02-16 17:31 . 2012-02-16 17:31 ——– d—–w- c:\program files (x86)\MarkAny 2012-02-10 08:47 . 2012-02-10 08:47 ——– d—–w- C:\TDSSKiller_Quarantine 2012-02-09 15:12 . 2012-02-09 15:12 ——– d—–w- c:\program files (x86)\LogMeIn Hamachi 2012-02-08 20:46 . 2012-02-08 20:46 ——– d—–w- C:\TEMP 2012-02-08 20:37 . 2012-02-08 20:37 ——– d—–w- c:\users\Marcos\AppData\Roaming\IrfanView 2012-02-08 20:37 . 2012-02-08 20:37 ——– d—–w- c:\program files (x86)\IrfanView 2012-02-08 19:25 . 2012-02-08 19:25 ——– d—–w- c:\program files (x86)\iamhrh 2012-02-06 19:15 . 2009-03-18 22:35 33856 —ha-w- c:\windows\system32\hamachi.sys 2012-02-06 03:09 . 2012-02-06 03:09 ——– d—–w- c:\windows\SysWow64\Wat 2012-02-06 03:09 . 2012-02-06 03:09 ——– d—–w- c:\windows\system32\Wat 2012-02-05 17:49 . 2012-02-17 01:57 0 –sha-w- c:\windows\system32\dds_trash_log.cmd 2012-01-27 01:29 . 2012-02-09 00:54 ——– d—–w- c:\users\Marcos\AppData\Local\Akamai 2012-01-25 19:30 . 2012-01-25 19:33 ——– d—–w- c:\program files (x86)\ffdshow 2012-01-25 19:30 . 2011-12-21 00:50 79360 —-a-w- c:\windows\SysWow64\ff_vfw.dll 2012-01-20 18:32 . 2012-01-20 18:32 ——– d—–w- c:\users\Marcos\AppData\Roaming\Malwarebytes 2012-01-20 18:32 . 2012-01-20 18:32 ——– d—–w- c:\programdata\Malwarebytes 2012-01-20 18:32 . 2011-05-29 15:11 39984 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2012-01-20 18:32 . 2012-02-01 01:08 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-01-20 18:32 . 2011-12-10 21:24 23152 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-01-20 18:20 . 2012-01-20 18:20 ——– d—–w- c:\program files (x86)\RockScroll 2012-01-20 07:37 . 2012-01-20 18:40 ——– d—–w- c:\program files (x86)\7E39D 2012-01-20 07:37 . 2012-01-20 18:40 ——– d—–w- c:\users\Marcos\AppData\Roaming\1837E 2012-01-19 17:44 . 2012-02-17 01:56 ——– d—–w- c:\users\Marcos\AppData\Local\TSVNCache 2012-01-19 03:51 . 2012-01-19 03:51 ——– d—–w- c:\users\Marcos\AppData\Roaming\TortoiseSVN 2012-01-19 03:50 . 2012-01-19 03:50 ——– d—–w- c:\users\Marcos\AppData\Roaming\Subversion 2012-01-19 03:50 . 2012-01-19 03:50 ——– d—–w- c:\program files\TortoiseSVN 2012-01-19 03:50 . 2012-01-19 03:50 ——– d—–w- c:\program files (x86)\Common Files\TortoiseOverlays 2012-01-18 06:21 . 2012-01-18 07:30 ——– d—–w- c:\programdata\Hi-Rez Studios 2012-01-18 06:21 . 2012-02-08 05:41 ——– d—–w- c:\program files (x86)\Hi-Rez Studios 2012-01-18 03:48 . 2010-12-24 19:18 73728 —-a-w- c:\windows\system\vdremote.dll 2012-01-18 03:48 . 2010-12-24 19:17 65536 —-a-w- c:\windows\system\vdsvrlnk.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-06 03:09 . 2011-07-25 04:32 14848 —-a-w- c:\windows\system32\slwga.dll 2012-02-06 03:09 . 2011-07-25 04:33 1008640 —-a-w- c:\windows\system32\user32.dll 2012-02-06 03:09 . 2011-07-25 04:32 833024 —-a-w- c:\windows\SysWow64\user32.dll 2012-02-06 03:09 . 2011-07-25 04:32 419840 —-a-w- c:\windows\system32\systemcpl.dll 2012-02-06 03:09 . 2011-07-25 04:31 13824 —-a-w- c:\windows\SysWow64\slwga.dll 2012-01-08 19:45 . 2011-07-04 21:29 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-29 22:39 . 2011-08-27 18:51 4659712 —-a-w- c:\windows\SysWow64\Redemption.dll 2011-11-29 22:38 . 2011-11-29 22:38 90112 —-a-w- c:\windows\MAMCityDownload.ocx 2011-11-29 22:38 . 2011-11-29 22:38 325552 —-a-w- c:\windows\MASetupCaller.dll 2011-11-29 22:38 . 2011-11-29 22:38 30568 —-a-w- c:\windows\MusiccityDownload.exe 2011-11-29 22:38 . 2011-11-29 22:38 974848 —-a-w- c:\windows\SysWow64\cis-2.4.dll 2011-11-29 22:38 . 2011-11-29 22:38 81920 —-a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll 2011-11-29 22:38 . 2011-11-29 22:38 65536 —-a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll 2011-11-29 22:38 . 2011-11-29 22:38 57344 —-a-w- c:\windows\SysWow64\MTXSYNCICON.dll 2011-11-29 22:38 . 2011-11-29 22:38 57344 —-a-w- c:\windows\SysWow64\MK_Lyric.dll 2011-11-29 22:38 . 2011-11-29 22:38 57344 —-a-w- c:\windows\SysWow64\issacapi_se-2.3.dll 2011-11-29 22:38 . 2011-11-29 22:38 569344 —-a-w- c:\windows\SysWow64\muzdecode.ax 2011-11-29 22:38 . 2011-11-29 22:38 491520 —-a-w- c:\windows\SysWow64\muzapp.dll 2011-11-29 22:38 . 2011-11-29 22:38 49152 —-a-w- c:\windows\SysWow64\MaJGUILib.dll 2011-11-29 22:38 . 2011-11-29 22:38 45056 —-a-w- c:\windows\SysWow64\MaXMLProto.dll 2011-11-29 22:38 . 2011-11-29 22:38 45056 —-a-w- c:\windows\SysWow64\MACXMLProto.dll 2011-11-29 22:38 . 2011-11-29 22:38 40960 —-a-w- c:\windows\SysWow64\MTTELECHIP.dll 2011-11-29 22:38 . 2011-11-29 22:38 40960 —-a-w- c:\windows\SysWow64\MAMACExtract.dll 2011-11-29 22:38 . 2011-11-29 22:38 352256 —-a-w- c:\windows\SysWow64\MSLUR71.dll 2011-11-29 22:38 . 2011-11-29 22:38 258048 —-a-w- c:\windows\SysWow64\muzoggsp.ax 2011-11-29 22:38 . 2011-11-29 22:38 245760 —-a-w- c:\windows\SysWow64\MSCLib.dll 2011-11-29 22:38 . 2011-11-29 22:38 24576 —-a-w- c:\windows\SysWow64\MASetupCleaner.exe 2011-11-29 22:38 . 2011-11-29 22:38 200704 —-a-w- c:\windows\SysWow64\muzwmts.dll 2011-11-29 22:38 . 2011-11-29 22:38 155648 —-a-w- c:\windows\SysWow64\MSFLib.dll 2011-11-29 22:38 . 2011-11-29 22:38 143360 —-a-w- c:\windows\SysWow64\3DAudio.ax 2011-11-29 22:38 . 2011-11-29 22:38 135168 —-a-w- c:\windows\SysWow64\muzaf1.dll 2011-11-29 22:38 . 2011-11-29 22:38 131072 —-a-w- c:\windows\SysWow64\muzmpgsp.ax 2011-11-29 22:38 . 2011-11-29 22:38 122880 —-a-w- c:\windows\SysWow64\muzeffect.ax 2011-11-29 22:38 . 2011-11-29 22:38 118784 —-a-w- c:\windows\SysWow64\MaDRM.dll 2011-11-29 22:38 . 2011-11-29 22:38 110592 —-a-w- c:\windows\SysWow64\muzmp4sp.ax 2011-11-29 22:38 . 2011-05-09 01:29 821824 —-a-w- c:\windows\SysWow64\dgderapi.dll . . ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll [-] 2012-02-06 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll . [-] 2012-02-06 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll [7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Jing"="c:\program files (x86)\TechSmith\Jing\Jing.exe" [2010-08-19 3069192] "Akamai NetSession Interface"="c:\users\Marcos\AppData\Local\Akamai\netsession_win.exe" [2012-02-02 3329824] "KiesHelper"="c:\program files (x86)\Samsung\Kies\KiesHelper.exe" [2012-02-03 943504] "KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-02-16 21416] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 421160] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "ContourCameraFinder"="c:\program files (x86)\ContourStoryteller\ContourAutoplay.exe" [2011-05-11 75000] "Google Desktop Search"="c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" [2011-07-14 30192] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-07 1987976] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-02-03 3508624] . c:\users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Marcos\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-8-22 24182896] Mozilla Thunderbird.lnk - c:\program files (x86)\Mozilla Thunderbird\thunderbird.exe [2011-8-28 399512] OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "HideSCAHealth"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\Google\GOOGLE~1\GoogleDesktopNetwork3.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 TabletServiceWacom;TabletServiceWacom;c:\program files\Tablet\Wacom\Wacom_Tablet.exe [2010-11-15 5716848] R3 ANTS Memory Profiler 7 Service;ANTS Memory Profiler 7 Service;c:\program files\Red Gate\ANTS Memory Profiler 7\RedGate.Memory.IISService.exe [2012-01-16 164792] R3 ANTS Performance Profiler 6 Service;ANTS Performance Profiler 6 Service;c:\program files\Red Gate\ANTS Performance Profiler 6\RedGate.Profiler.IISService.exe [2012-01-16 145408] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-07-04 1431888] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2011-07-14 30192] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 YMIDUSBW;Yamaha USB-MIDI Driver (WDM);c:\windows\system32\drivers\ymidusbx64.sys [x] R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x] R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 3d-io License Server v2.0;3d-io License Server v2.0;c:\program files (x86)\3d-io plugins\licensing_v2\ActiveLockServerV2.exe [2011-03-31 34816] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-07 2343816] S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-02-07 8704] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 rt61x64;RT61 Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr6164.sys [x] S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-02-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000Core.job - c:\users\Marcos\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-29 18:04] . 2012-02-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000UA.job - c:\users\Marcos\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-29 18:04] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-07-07 12558440] "TortoiseHgOverlayIconServer"="c:\program files\TortoiseHg\TortoiseHgOverlayServer.exe" [2011-08-28 52688] "combofix"="c:\combofix\CF3242.3XE" [2010-11-20 345088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs AtiPcie . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421 LSP: mswsock.dll . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-Java X Run Class - c:\users\Marcos\AppData\Local\Temp\javax.exe AddRemove-ESN Sonar-0.70.0 - c:\program files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe AddRemove-FoxyTunesForFirefox - c:\program files (x86)\Mozilla Firefox\firefox.exe AddRemove-PunkBusterSvc - c:\program files (x86)\Origin Games\Battlefield 3 Beta\pbsvc.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1943473726-2824459890-2441723098-1000\Software\SecuROM\License information*] "datasecu"=hex:38,ad,f0,58,26,74,64,d8,f7,b7,21,68,28,12,54,0f,7a,97,a9,a5,48, 11,c0,bb,eb,f1,7f,80,1a,d2,c3,53,2b,1b,2a,7a,e4,c7,e7,e9,33,66,b5,7f,27,31,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\OpenOffice.org 3\program\soffice.exe c:\program files (x86)\OpenOffice.org 3\program\soffice.bin c:\windows\SysWOW64\PnkBstrA.exe . ************************************************************************** . Completion time: 2012-02-16 20:03:09 - machine was rebooted ComboFix-quarantined-files.txt 2012-02-17 02:03 . Pre-Run: 36,846,571,520 bytes free Post-Run: 36,588,015,616 bytes free . - - End Of File - - D29EE274B11567CF889DF43ADD96424C
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    File::
    C:\Windows\SysNative\3dkeybd.dll
    
    DDS::
    uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421
    
    Netsvc::
    AtiPcie 
    
    Driver::
    AtiPcie
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Oh dear that sounds serious… Let's hope I haven't been compromised. I know there's no way for you to know for sure, and I also understand that I take your advice with no guarantee of accuracy and completely at my own risk, but do you know what the chances of information being stolen from me is? I have purchased things online in the past month. ComboFix 12-02-16.02 - Marcos 02/17/2012 22:03:27.3.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8191.6041 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Marcos\Desktop\CFScript.txt SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\windows\system32\3dkeybd.dll" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Marcos\AppData\Local\Temp\c06086cf-47b1-4760-b263-4e4271d9922f\CliSecureRT.dll c:\windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\GAC_64\Desktop.ini c:\windows\assembly\temp\cfg.ini c:\windows\system32\3dkeybd.dll c:\windows\system32\consrv.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_AtiPcie . . ((((((((((((((((((((((((( Files Created from 2012-01-18 to 2012-02-18 ))))))))))))))))))))))))))))))) . . 2012-02-18 04:08 . 2012-02-18 04:08 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-02-16 17:46 . 2011-12-08 04:22 13800 —-a-w- c:\windows\system32\drivers\ssadwhnt.sys 2012-02-16 17:46 . 2011-12-08 04:22 177640 —-a-w- c:\windows\system32\drivers\ssadmdm.sys 2012-02-16 17:46 . 2011-12-08 04:22 16872 —-a-w- c:\windows\system32\drivers\ssadmdfl.sys 2012-02-16 17:46 . 2011-12-08 04:22 157672 —-a-w- c:\windows\system32\drivers\ssadbus.sys 2012-02-16 17:46 . 2011-12-08 04:22 13288 —-a-w- c:\windows\system32\drivers\ssadcmnt.sys 2012-02-16 17:34 . 2012-02-17 01:47 ——– d—–w- c:\users\Marcos\AppData\Local\Samsung 2012-02-16 17:34 . 2012-02-16 17:34 ——– d—–w- c:\users\Marcos\AppData\Roaming\Samsung 2012-02-16 17:33 . 2011-10-27 01:25 13800 —-a-w- c:\windows\system32\drivers\ssadwh.sys 2012-02-16 17:33 . 2011-10-27 01:25 13288 —-a-w- c:\windows\system32\drivers\ssadcm.sys 2012-02-16 17:31 . 2012-02-16 17:31 ——– d—–w- c:\program files (x86)\MarkAny 2012-02-10 08:47 . 2012-02-10 08:47 ——– d—–w- C:\TDSSKiller_Quarantine 2012-02-09 15:12 . 2012-02-09 15:12 ——– d—–w- c:\program files (x86)\LogMeIn Hamachi 2012-02-08 20:46 . 2012-02-08 20:46 ——– d—–w- C:\TEMP 2012-02-08 20:37 . 2012-02-08 20:37 ——– d—–w- c:\users\Marcos\AppData\Roaming\IrfanView 2012-02-08 20:37 . 2012-02-08 20:37 ——– d—–w- c:\program files (x86)\IrfanView 2012-02-08 19:25 . 2012-02-08 19:25 ——– d—–w- c:\program files (x86)\iamhrh 2012-02-06 19:15 . 2009-03-18 22:35 33856 —ha-w- c:\windows\system32\hamachi.sys 2012-02-06 03:09 . 2012-02-06 03:09 ——– d—–w- c:\windows\system32\Wat 2012-02-05 17:49 . 2012-02-17 01:57 0 –sha-w- c:\windows\system32\dds_trash_log.cmd 2012-01-27 01:29 . 2012-02-09 00:54 ——– d—–w- c:\users\Marcos\AppData\Local\Akamai 2012-01-25 19:30 . 2012-01-25 19:33 ——– d—–w- c:\program files (x86)\ffdshow 2012-01-25 19:30 . 2011-12-21 00:50 79360 —-a-w- c:\windows\SysWow64\ff_vfw.dll 2012-01-20 18:32 . 2012-01-20 18:32 ——– d—–w- c:\users\Marcos\AppData\Roaming\Malwarebytes 2012-01-20 18:32 . 2012-01-20 18:32 ——– d—–w- c:\programdata\Malwarebytes 2012-01-20 18:32 . 2011-05-29 15:11 39984 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2012-01-20 18:32 . 2012-02-01 01:08 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-01-20 18:32 . 2011-12-10 21:24 23152 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-01-20 18:20 . 2012-01-20 18:20 ——– d—–w- c:\program files (x86)\RockScroll 2012-01-20 07:37 . 2012-01-20 18:40 ——– d—–w- c:\program files (x86)\7E39D 2012-01-20 07:37 . 2012-01-20 18:40 ——– d—–w- c:\users\Marcos\AppData\Roaming\1837E 2012-01-19 17:44 . 2012-02-18 04:11 ——– d—–w- c:\users\Marcos\AppData\Local\TSVNCache . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-06 03:09 . 2011-07-25 04:32 14848 —-a-w- c:\windows\system32\slwga.dll 2012-02-06 03:09 . 2011-07-25 04:33 1008640 —-a-w- c:\windows\system32\user32.dll 2012-02-06 03:09 . 2011-07-25 04:32 833024 —-a-w- c:\windows\SysWow64\user32.dll 2012-02-06 03:09 . 2011-07-25 04:32 419840 —-a-w- c:\windows\system32\systemcpl.dll 2012-02-06 03:09 . 2011-07-25 04:31 13824 —-a-w- c:\windows\SysWow64\slwga.dll 2012-01-08 19:45 . 2011-07-04 21:29 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-29 22:39 . 2011-08-27 18:51 4659712 —-a-w- c:\windows\SysWow64\Redemption.dll 2011-11-29 22:38 . 2011-11-29 22:38 90112 —-a-w- c:\windows\MAMCityDownload.ocx 2011-11-29 22:38 . 2011-11-29 22:38 325552 —-a-w- c:\windows\MASetupCaller.dll 2011-11-29 22:38 . 2011-11-29 22:38 30568 —-a-w- c:\windows\MusiccityDownload.exe 2011-11-29 22:38 . 2011-11-29 22:38 974848 —-a-w- c:\windows\SysWow64\cis-2.4.dll 2011-11-29 22:38 . 2011-11-29 22:38 81920 —-a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll 2011-11-29 22:38 . 2011-11-29 22:38 65536 —-a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll 2011-11-29 22:38 . 2011-11-29 22:38 57344 —-a-w- c:\windows\SysWow64\MTXSYNCICON.dll 2011-11-29 22:38 . 2011-11-29 22:38 57344 —-a-w- c:\windows\SysWow64\MK_Lyric.dll 2011-11-29 22:38 . 2011-11-29 22:38 57344 —-a-w- c:\windows\SysWow64\issacapi_se-2.3.dll 2011-11-29 22:38 . 2011-11-29 22:38 569344 —-a-w- c:\windows\SysWow64\muzdecode.ax 2011-11-29 22:38 . 2011-11-29 22:38 491520 —-a-w- c:\windows\SysWow64\muzapp.dll 2011-11-29 22:38 . 2011-11-29 22:38 49152 —-a-w- c:\windows\SysWow64\MaJGUILib.dll 2011-11-29 22:38 . 2011-11-29 22:38 45056 —-a-w- c:\windows\SysWow64\MaXMLProto.dll 2011-11-29 22:38 . 2011-11-29 22:38 45056 —-a-w- c:\windows\SysWow64\MACXMLProto.dll 2011-11-29 22:38 . 2011-11-29 22:38 40960 —-a-w- c:\windows\SysWow64\MTTELECHIP.dll 2011-11-29 22:38 . 2011-11-29 22:38 40960 —-a-w- c:\windows\SysWow64\MAMACExtract.dll 2011-11-29 22:38 . 2011-11-29 22:38 352256 —-a-w- c:\windows\SysWow64\MSLUR71.dll 2011-11-29 22:38 . 2011-11-29 22:38 258048 —-a-w- c:\windows\SysWow64\muzoggsp.ax 2011-11-29 22:38 . 2011-11-29 22:38 245760 —-a-w- c:\windows\SysWow64\MSCLib.dll 2011-11-29 22:38 . 2011-11-29 22:38 24576 —-a-w- c:\windows\SysWow64\MASetupCleaner.exe 2011-11-29 22:38 . 2011-11-29 22:38 200704 —-a-w- c:\windows\SysWow64\muzwmts.dll 2011-11-29 22:38 . 2011-11-29 22:38 155648 —-a-w- c:\windows\SysWow64\MSFLib.dll 2011-11-29 22:38 . 2011-11-29 22:38 143360 —-a-w- c:\windows\SysWow64\3DAudio.ax 2011-11-29 22:38 . 2011-11-29 22:38 135168 —-a-w- c:\windows\SysWow64\muzaf1.dll 2011-11-29 22:38 . 2011-11-29 22:38 131072 —-a-w- c:\windows\SysWow64\muzmpgsp.ax 2011-11-29 22:38 . 2011-11-29 22:38 122880 —-a-w- c:\windows\SysWow64\muzeffect.ax 2011-11-29 22:38 . 2011-11-29 22:38 118784 —-a-w- c:\windows\SysWow64\MaDRM.dll 2011-11-29 22:38 . 2011-11-29 22:38 110592 —-a-w- c:\windows\SysWow64\muzmp4sp.ax 2011-11-29 22:38 . 2011-05-09 01:29 821824 —-a-w- c:\windows\SysWow64\dgderapi.dll . . ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll [-] 2012-02-06 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll . [-] 2012-02-06 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll [7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll . ((((((((((((((((((((((((((((( SnapShot@2012-02-17_01.57.33 ))))))))))))))))))))))))))))))))))))))))) . + 2011-07-04 20:48 . 2012-02-18 03:58 48526 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-02-18 03:58 28228 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-07-04 19:57 . 2012-02-18 03:58 17650 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1943473726-2824459890-2441723098-1000_UserData.bin - 2011-07-04 20:37 . 2012-02-17 01:57 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-07-04 20:37 . 2012-02-18 04:10 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-07-04 20:37 . 2012-02-18 04:10 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-07-04 20:37 . 2012-02-17 01:57 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-02-17 01:57 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-02-18 04:10 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-07-04 21:08 . 2012-02-17 01:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-07-04 21:08 . 2012-02-18 03:58 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-07-04 21:08 . 2012-02-17 01:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-07-04 21:08 . 2012-02-18 03:58 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-07-04 21:08 . 2012-02-17 01:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-07-04 21:08 . 2012-02-18 03:58 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-07-04 21:08 . 2012-02-17 01:46 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-07-04 21:08 . 2012-02-18 04:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-07-04 21:08 . 2012-02-17 01:46 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-07-04 21:08 . 2012-02-18 04:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-07-05 08:51 . 2012-02-17 06:45 3662 c:\windows\system32\wdi\ERCQueuedResolutions.dat - 2011-07-05 08:51 . 2012-02-16 04:05 3662 c:\windows\system32\wdi\ERCQueuedResolutions.dat + 2012-02-18 04:10 . 2012-02-18 04:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-02-17 01:57 . 2012-02-17 01:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-02-18 04:10 . 2012-02-18 04:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-02-17 01:57 . 2012-02-17 01:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-07-14 05:01 . 2012-02-17 01:56 381756 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-02-18 04:09 381756 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 04:54 . 2012-02-18 04:06 1081344 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-02-16 17:14 1081344 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-02-18 04:06 8028160 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-02-16 17:14 8028160 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-07-04 22:55 . 2012-02-18 04:09 2271832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat - 2011-07-04 22:55 . 2012-02-16 17:40 2271832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat - 2009-07-14 04:54 . 2012-02-16 17:14 11190272 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-02-18 04:06 11190272 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-07-04 20:40 . 2012-02-17 01:56 42273244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1943473726-2824459890-2441723098-1000-12288.dat + 2011-07-04 20:40 . 2012-02-18 04:09 42273244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1943473726-2824459890-2441723098-1000-12288.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Jing"="c:\program files (x86)\TechSmith\Jing\Jing.exe" [2010-08-19 3069192] "Akamai NetSession Interface"="c:\users\Marcos\AppData\Local\Akamai\netsession_win.exe" [2012-02-02 3329824] "KiesHelper"="c:\program files (x86)\Samsung\Kies\KiesHelper.exe" [2012-02-03 943504] "KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-02-16 21416] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 421160] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "ContourCameraFinder"="c:\program files (x86)\ContourStoryteller\ContourAutoplay.exe" [2011-05-11 75000] "Google Desktop Search"="c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" [2011-07-14 30192] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-07 1987976] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-02-03 3508624] . c:\users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Marcos\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-8-22 24182896] Mozilla Thunderbird.lnk - c:\program files (x86)\Mozilla Thunderbird\thunderbird.exe [2011-8-28 399512] OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "HideSCAHealth"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\progra~2\Google\GOOGLE~1\GoogleDesktopNetwork3.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-02-07 8704] R3 ANTS Memory Profiler 7 Service;ANTS Memory Profiler 7 Service;c:\program files\Red Gate\ANTS Memory Profiler 7\RedGate.Memory.IISService.exe [2012-01-16 164792] R3 ANTS Performance Profiler 6 Service;ANTS Performance Profiler 6 Service;c:\program files\Red Gate\ANTS Performance Profiler 6\RedGate.Profiler.IISService.exe [2012-01-16 145408] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-07-04 1431888] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2011-07-14 30192] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 YMIDUSBW;Yamaha USB-MIDI Driver (WDM);c:\windows\system32\drivers\ymidusbx64.sys [x] R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x] R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 3d-io License Server v2.0;3d-io License Server v2.0;c:\program files (x86)\3d-io plugins\licensing_v2\ActiveLockServerV2.exe [2011-03-31 34816] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-07 2343816] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] S2 TabletServiceWacom;TabletServiceWacom;c:\program files\Tablet\Wacom\Wacom_Tablet.exe [2010-11-15 5716848] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 rt61x64;RT61 Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr6164.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-02-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000Core.job - c:\users\Marcos\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-29 18:04] . 2012-02-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000UA.job - c:\users\Marcos\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-29 18:04] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-07-07 12558440] "TortoiseHgOverlayIconServer"="c:\program files\TortoiseHg\TortoiseHgOverlayServer.exe" [2011-08-28 52688] "combofix"="c:\combofix\CF16352.3XE" [2010-11-20 345088] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs AtiPcie . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1943473726-2824459890-2441723098-1000\Software\SecuROM\License information*] "datasecu"=hex:38,ad,f0,58,26,74,64,d8,f7,b7,21,68,28,12,54,0f,7a,97,a9,a5,48, 11,c0,bb,eb,f1,7f,80,1a,d2,c3,53,2b,1b,2a,7a,e4,c7,e7,e9,33,66,b5,7f,27,31,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\OpenOffice.org 3\program\soffice.exe c:\program files (x86)\OpenOffice.org 3\program\soffice.bin . ************************************************************************** . Completion time: 2012-02-17 22:17:00 - machine was rebooted ComboFix-quarantined-files.txt 2012-02-18 04:17 ComboFix2.txt 2012-02-17 02:03 . Pre-Run: 35,393,015,808 bytes free Post-Run: 35,299,377,152 bytes free . - - End Of File - - 10C32E475D687C956BCB7A22D22D422D
ComboFix 12-02-16.02 - Marcos 02/19/2012 23:36:17.4.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8191.6364 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Marcos\Desktop\CFScript.txt SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\windows\system32\3dkeybd.dll" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Marcos\AppData\Local\Temp\c06086cf-47b1-4760-b263-4e4271d9922f\CliSecureRT.dll c:\windows\system32\3dkeybd.dll . . ((((((((((((((((((((((((( Files Created from 2012-01-20 to 2012-02-20 ))))))))))))))))))))))))))))))) . . 2012-02-20 05:43 . 2012-02-20 05:43 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-02-16 17:46 . 2011-12-08 04:22 13800 —-a-w- c:\windows\system32\drivers\ssadwhnt.sys 2012-02-16 17:46 . 2011-12-08 04:22 177640 —-a-w- c:\windows\system32\drivers\ssadmdm.sys 2012-02-16 17:46 . 2011-12-08 04:22 16872 —-a-w- c:\windows\system32\drivers\ssadmdfl.sys 2012-02-16 17:46 . 2011-12-08 04:22 157672 —-a-w- c:\windows\system32\drivers\ssadbus.sys 2012-02-16 17:46 . 2011-12-08 04:22 13288 —-a-w- c:\windows\system32\drivers\ssadcmnt.sys 2012-02-16 17:34 . 2012-02-17 01:47 ——– d—–w- c:\users\Marcos\AppData\Local\Samsung 2012-02-16 17:34 . 2012-02-16 17:34 ——– d—–w- c:\users\Marcos\AppData\Roaming\Samsung 2012-02-16 17:33 . 2011-10-27 01:25 13800 —-a-w- c:\windows\system32\drivers\ssadwh.sys 2012-02-16 17:33 . 2011-10-27 01:25 13288 —-a-w- c:\windows\system32\drivers\ssadcm.sys 2012-02-16 17:31 . 2012-02-16 17:31 ——– d—–w- c:\program files (x86)\MarkAny 2012-02-10 08:47 . 2012-02-10 08:47 ——– d—–w- C:\TDSSKiller_Quarantine 2012-02-09 15:12 . 2012-02-09 15:12 ——– d—–w- c:\program files (x86)\LogMeIn Hamachi 2012-02-08 20:46 . 2012-02-08 20:46 ——– d—–w- C:\TEMP 2012-02-08 20:37 . 2012-02-08 20:37 ——– d—–w- c:\users\Marcos\AppData\Roaming\IrfanView 2012-02-08 20:37 . 2012-02-08 20:37 ——– d—–w- c:\program files (x86)\IrfanView 2012-02-08 19:25 . 2012-02-08 19:25 ——– d—–w- c:\program files (x86)\iamhrh 2012-02-06 19:15 . 2009-03-18 22:35 33856 —ha-w- c:\windows\system32\hamachi.sys 2012-02-06 03:09 . 2012-02-06 03:09 ——– d—–w- c:\windows\SysWow64\Wat 2012-02-06 03:09 . 2012-02-06 03:09 ——– d—–w- c:\windows\system32\Wat 2012-02-05 17:49 . 2012-02-17 01:57 0 –sha-w- c:\windows\system32\dds_trash_log.cmd 2012-01-27 01:29 . 2012-02-09 00:54 ——– d—–w- c:\users\Marcos\AppData\Local\Akamai 2012-01-25 19:30 . 2012-01-25 19:33 ——– d—–w- c:\program files (x86)\ffdshow 2012-01-25 19:30 . 2011-12-21 00:50 79360 —-a-w- c:\windows\SysWow64\ff_vfw.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-06 03:09 . 2011-07-25 04:32 14848 —-a-w- c:\windows\system32\slwga.dll 2012-02-06 03:09 . 2011-07-25 04:33 1008640 —-a-w- c:\windows\system32\user32.dll 2012-02-06 03:09 . 2011-07-25 04:32 833024 —-a-w- c:\windows\SysWow64\user32.dll 2012-02-06 03:09 . 2011-07-25 04:32 419840 —-a-w- c:\windows\system32\systemcpl.dll 2012-02-06 03:09 . 2011-07-25 04:31 13824 —-a-w- c:\windows\SysWow64\slwga.dll 2012-01-08 19:45 . 2011-07-04 21:29 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-12-10 21:24 . 2012-01-20 18:32 23152 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-29 22:39 . 2011-08-27 18:51 4659712 —-a-w- c:\windows\SysWow64\Redemption.dll 2011-11-29 22:38 . 2011-11-29 22:38 90112 —-a-w- c:\windows\MAMCityDownload.ocx 2011-11-29 22:38 . 2011-11-29 22:38 325552 —-a-w- c:\windows\MASetupCaller.dll 2011-11-29 22:38 . 2011-11-29 22:38 30568 —-a-w- c:\windows\MusiccityDownload.exe 2011-11-29 22:38 . 2011-11-29 22:38 974848 —-a-w- c:\windows\SysWow64\cis-2.4.dll 2011-11-29 22:38 . 2011-11-29 22:38 81920 —-a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll 2011-11-29 22:38 . 2011-11-29 22:38 65536 —-a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll 2011-11-29 22:38 . 2011-11-29 22:38 57344 —-a-w- c:\windows\SysWow64\MTXSYNCICON.dll 2011-11-29 22:38 . 2011-11-29 22:38 57344 —-a-w- c:\windows\SysWow64\MK_Lyric.dll 2011-11-29 22:38 . 2011-11-29 22:38 57344 —-a-w- c:\windows\SysWow64\issacapi_se-2.3.dll 2011-11-29 22:38 . 2011-11-29 22:38 569344 —-a-w- c:\windows\SysWow64\muzdecode.ax 2011-11-29 22:38 . 2011-11-29 22:38 491520 —-a-w- c:\windows\SysWow64\muzapp.dll 2011-11-29 22:38 . 2011-11-29 22:38 49152 —-a-w- c:\windows\SysWow64\MaJGUILib.dll 2011-11-29 22:38 . 2011-11-29 22:38 45056 —-a-w- c:\windows\SysWow64\MaXMLProto.dll 2011-11-29 22:38 . 2011-11-29 22:38 45056 —-a-w- c:\windows\SysWow64\MACXMLProto.dll 2011-11-29 22:38 . 2011-11-29 22:38 40960 —-a-w- c:\windows\SysWow64\MTTELECHIP.dll 2011-11-29 22:38 . 2011-11-29 22:38 40960 —-a-w- c:\windows\SysWow64\MAMACExtract.dll 2011-11-29 22:38 . 2011-11-29 22:38 352256 —-a-w- c:\windows\SysWow64\MSLUR71.dll 2011-11-29 22:38 . 2011-11-29 22:38 258048 —-a-w- c:\windows\SysWow64\muzoggsp.ax 2011-11-29 22:38 . 2011-11-29 22:38 245760 —-a-w- c:\windows\SysWow64\MSCLib.dll 2011-11-29 22:38 . 2011-11-29 22:38 24576 —-a-w- c:\windows\SysWow64\MASetupCleaner.exe 2011-11-29 22:38 . 2011-11-29 22:38 200704 —-a-w- c:\windows\SysWow64\muzwmts.dll 2011-11-29 22:38 . 2011-11-29 22:38 155648 —-a-w- c:\windows\SysWow64\MSFLib.dll 2011-11-29 22:38 . 2011-11-29 22:38 143360 —-a-w- c:\windows\SysWow64\3DAudio.ax 2011-11-29 22:38 . 2011-11-29 22:38 135168 —-a-w- c:\windows\SysWow64\muzaf1.dll 2011-11-29 22:38 . 2011-11-29 22:38 131072 —-a-w- c:\windows\SysWow64\muzmpgsp.ax 2011-11-29 22:38 . 2011-11-29 22:38 122880 —-a-w- c:\windows\SysWow64\muzeffect.ax 2011-11-29 22:38 . 2011-11-29 22:38 118784 —-a-w- c:\windows\SysWow64\MaDRM.dll 2011-11-29 22:38 . 2011-11-29 22:38 110592 —-a-w- c:\windows\SysWow64\muzmp4sp.ax 2011-11-29 22:38 . 2011-05-09 01:29 821824 —-a-w- c:\windows\SysWow64\dgderapi.dll . . ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll [-] 2012-02-06 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll . [-] 2012-02-06 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll [7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll . ((((((((((((((((((((((((((((( SnapShot@2012-02-17_01.57.33 ))))))))))))))))))))))))))))))))))))))))) . + 2011-07-04 20:48 . 2012-02-20 05:34 48670 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-02-20 05:34 28260 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-07-04 19:57 . 2012-02-20 05:34 17774 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1943473726-2824459890-2441723098-1000_UserData.bin - 2011-07-04 20:37 . 2012-02-17 01:57 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-07-04 20:37 . 2012-02-20 05:44 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-07-04 20:37 . 2012-02-20 05:44 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-07-04 20:37 . 2012-02-17 01:57 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-02-17 01:57 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-02-20 05:44 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-07-04 21:08 . 2012-02-17 01:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-07-04 21:08 . 2012-02-20 05:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-07-04 21:08 . 2012-02-17 01:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-07-04 21:08 . 2012-02-20 05:35 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-07-04 21:08 . 2012-02-17 01:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-07-04 21:08 . 2012-02-20 05:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-07-04 21:08 . 2012-02-17 01:46 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-07-04 21:08 . 2012-02-20 05:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-07-04 21:08 . 2012-02-17 01:46 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-07-04 21:08 . 2012-02-20 05:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-07-05 08:51 . 2012-02-18 05:12 3662 c:\windows\system32\wdi\ERCQueuedResolutions.dat - 2011-07-05 08:51 . 2012-02-16 04:05 3662 c:\windows\system32\wdi\ERCQueuedResolutions.dat + 2012-02-20 05:44 . 2012-02-20 05:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-02-17 01:57 . 2012-02-17 01:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-02-20 05:44 . 2012-02-20 05:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-02-17 01:57 . 2012-02-17 01:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-07-14 05:01 . 2012-02-17 01:56 381756 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-02-20 05:43 381756 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 04:54 . 2012-02-18 04:06 1081344 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-02-16 17:14 1081344 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-02-18 04:06 8028160 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-02-16 17:14 8028160 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-07-04 22:55 . 2012-02-20 05:43 2271832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat - 2011-07-04 22:55 . 2012-02-16 17:40 2271832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat - 2009-07-14 04:54 . 2012-02-16 17:14 11190272 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-02-18 04:06 11190272 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-07-04 20:40 . 2012-02-17 01:56 42273244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1943473726-2824459890-2441723098-1000-12288.dat + 2011-07-04 20:40 . 2012-02-20 05:43 42273244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1943473726-2824459890-2441723098-1000-12288.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 64792 —-a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Jing"="c:\program files (x86)\TechSmith\Jing\Jing.exe" [2010-08-19 3069192] "Akamai NetSession Interface"="c:\users\Marcos\AppData\Local\Akamai\netsession_win.exe" [2012-02-02 3329824] "KiesHelper"="c:\program files (x86)\Samsung\Kies\KiesHelper.exe" [2012-02-03 943504] "KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-02-16 21416] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 421160] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "ContourCameraFinder"="c:\program files (x86)\ContourStoryteller\ContourAutoplay.exe" [2011-05-11 75000] "Google Desktop Search"="c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" [2011-07-14 30192] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-07 1987976] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-02-03 3508624] . c:\users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Marcos\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-8-22 24182896] Mozilla Thunderbird.lnk - c:\program files (x86)\Mozilla Thunderbird\thunderbird.exe [2011-8-28 399512] OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "HideSCAHealth"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\progra~2\Google\GOOGLE~1\GoogleDesktopNetwork3.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 ANTS Memory Profiler 7 Service;ANTS Memory Profiler 7 Service;c:\program files\Red Gate\ANTS Memory Profiler 7\RedGate.Memory.IISService.exe [2012-01-16 164792] R3 ANTS Performance Profiler 6 Service;ANTS Performance Profiler 6 Service;c:\program files\Red Gate\ANTS Performance Profiler 6\RedGate.Profiler.IISService.exe [2012-01-16 145408] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-07-04 1431888] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2011-07-14 30192] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 YMIDUSBW;Yamaha USB-MIDI Driver (WDM);c:\windows\system32\drivers\ymidusbx64.sys [x] R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x] R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 3d-io License Server v2.0;3d-io License Server v2.0;c:\program files (x86)\3d-io plugins\licensing_v2\ActiveLockServerV2.exe [2011-03-31 34816] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-07 2343816] S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-02-07 8704] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] S2 TabletServiceWacom;TabletServiceWacom;c:\program files\Tablet\Wacom\Wacom_Tablet.exe [2010-11-15 5716848] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 rt61x64;RT61 Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr6164.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-02-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000Core.job - c:\users\Marcos\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-29 18:04] . 2012-02-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000UA.job - c:\users\Marcos\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-29 18:04] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 16:20 75544 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Marcos\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-07-07 12558440] "TortoiseHgOverlayIconServer"="c:\program files\TortoiseHg\TortoiseHgOverlayServer.exe" [2011-08-28 52688] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs AtiPcie . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1943473726-2824459890-2441723098-1000\Software\SecuROM\License information*] "datasecu"=hex:38,ad,f0,58,26,74,64,d8,f7,b7,21,68,28,12,54,0f,7a,97,a9,a5,48, 11,c0,bb,eb,f1,7f,80,1a,d2,c3,53,2b,1b,2a,7a,e4,c7,e7,e9,33,66,b5,7f,27,31,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\OpenOffice.org 3\program\soffice.exe c:\program files (x86)\OpenOffice.org 3\program\soffice.bin c:\windows\SysWOW64\PnkBstrA.exe . ************************************************************************** . Completion time: 2012-02-19 23:50:29 - machine was rebooted ComboFix-quarantined-files.txt 2012-02-20 05:50 ComboFix2.txt 2012-02-18 04:17 ComboFix3.txt 2012-02-17 02:03 . Pre-Run: 35,326,443,520 bytes free Post-Run: 35,102,736,384 bytes free . - - End Of File - - CE0B3C8DBE7F9216F1B4D9730E237525
Hi,

Please run a new scan with OTL.
Be sure to include in the Custom Scan section the following bolded information below:

netsvcs
/MD5START
consrv.dll
3dkeybd.dll
/MD5STOP


Once the scan is complete please post the newly created log.
OTL logfile created on: 2/20/2012 9:00:03 AM - Run 2
OTL by OldTimer - Version 3.2.32.0 Folder = C:\Users\Marcos\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.02 Gb Available Physical Memory | 75.21% Memory free
16.00 Gb Paging File | 13.78 Gb Available in Paging File | 86.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 32.66 Gb Free Space | 23.38% Space Free | Partition Type: NTFS
Drive E: | 698.64 Gb Total Space | 341.35 Gb Free Space | 48.86% Space Free | Partition Type: NTFS

Computer Name: MARCOS-PC | User Name: Marcos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Marcos\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Users\Marcos\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Users\Marcos\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe ()
PRC - C:\Program Files (x86)\3d-io plugins\licensing_v2\ActiveLockServerV2.exe (3d-io GmbH)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\TechSmith\Jing\Jing.exe (TechSmith Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\Marcos\AppData\Local\Temp\c06086cf-47b1-4760-b263-4e4271d9922f\CliSecureRT.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\a8bd6b91bf16c6727723481b42ea3293\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\16498c46d223310bc8811e193bcf1205\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\5f29a2d3dc6bdadb9751faaa0f230911\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\c21fbb4bf27a7c8705e29f08827c9c7e\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\36b3b787a2942e629e87b1b96fa049d4\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\227927e469cb6b079e4cc7d81e38f8f5\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\1741fc5f7819af118d4de616016a8b2d\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\698b02e36bac06ac74077cc3ec6eced0\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\30740aecd686555cb6800b47cc80fae7\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\5c2eff65e7e457ea372f767c024c04f7\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b4e03b2b9835e9cb4e879c703880fe74\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\2d3806670b3c3e4163592b5aca62f8cc\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d4e8a005f4cdd6528f1c7295d833877f\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\avutil-51.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\avformat-53.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\avcodec-53.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll ()
MOD - C:\Program Files\TortoiseSVN\bin\libsasl32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a0afd596da13c708d04b0a2dd1490036\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\0018b6bfd1d96454aa8fb698d0ea51a1\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\a9f6cfa4eb1436ff770995822f10e227\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\c8aa11ee6789d0f3f5542747aad7a2e4\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\173e012cca07a9b7151c574585a4ca9e\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\40404dbd013b0ca1e41ab7e57274308b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c68401de935c813374253d4fc2a18f6a\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\acbc57d41499fbc2b99194148786c677\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\338f3c91a0bea33a07a4611d324bf73a\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\16b68fcaff063835ae0ee348a1201f2a\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe ()
MOD - C:\Program Files (x86)\TechSmith\Jing\Recorder.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (ANTS Memory Profiler 7 Service) – C:\Program Files\Red Gate\ANTS Memory Profiler 7\RedGate.Memory.IISService.exe (Red Gate Software Ltd.)
SRV:64bit: - (ANTS Performance Profiler 6 Service) – C:\Program Files\Red Gate\ANTS Performance Profiler 6\RedGate.Profiler.IISService.exe (Red Gate Software Ltd.)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (TabletServiceWacom) – C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (HiPatchService) – C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (3d-io License Server v2.0) – C:\Program Files (x86)\3d-io plugins\licensing_v2\ActiveLockServerV2.exe (3d-io GmbH)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (SCDEmu) – C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (YMIDUSBW) Yamaha USB-MIDI Driver (WDM) – C:\Windows\SysNative\drivers\ymidusbx64.sys (Yamaha Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (cpuz135) – C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (xnacc) – C:\Windows\SysNative\drivers\xnacc.sys (Microsoft Corporation)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (rt61x64) – C:\Windows\SysNative\drivers\netr6164.sys (Ralink Technology, Corp.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (dgderdrv) – C:\Windows\SysWOW64\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 64 2A 01 42 94 D5 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 56667
FF - prefs.js..network.proxy.type: 1

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.10: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Marcos\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Marcos\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Marcos\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\BYOND: C:\Program Files (x86)\BYOND\bin\npbyond.dll (BYOND)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/11/09 11:47:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2012/02/02 11:46:02 | 000,000,000 | —D | M]

[2011/07/04 15:08:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Marcos\AppData\Roaming\Mozilla\Extensions
[2012/01/12 00:24:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions
[2011/10/03 18:12:13 | 000,000,000 | —D | M] (FoxyTunes) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2011/11/11 22:26:16 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/08/21 00:21:47 | 000,000,000 | —D | M] (ActiveGS) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions\[removed]
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{0FA2149E-BB2C-4AC2-A8D3-479599819475}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{988DA70D-B78D-44A1-A9C7-ED11832A9E2E}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: BYOND stub plugin for Mozilla (Enabled) = C:\Program Files (x86)\BYOND\bin\npbyond.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Marcos\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Marcos\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus (Beta) = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: imgur = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehoopddfhgaehhmphfcooacjdpmbjlao\1.0.5_0\
CHR - Extension: AirMech = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdahlabpinmfcemhcbcfoijcpoalfgdn\7207_0\
CHR - Extension: Cloud9 = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbdmccoknlfggadpfkmcpnamfnbkmkcp\1.9.5_0\

O1 HOSTS File: ([2012/02/19 23:44:40 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [TortoiseHgOverlayIconServer] C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe ()
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [ContourCameraFinder] C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe ()
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Marcos\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - Startup: C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Marcos\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Thunderbird.lnk = C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
O4 - Startup: C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.254.40.1 [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59DD3D3F-B7ED-404C-BA1F-84E544261B0D}: DhcpNameServer = 10.253.40.1 [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BA53C310-0C3C-4C99-B8B5-E2651CEBED41}: DhcpNameServer = 10.200.154.1 [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBFB7911-C70E-47D2-A6E5-84773522C303}: DhcpNameServer = 10.254.40.1 [removed] [removed] [removed]
O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/20 01:35:27 | 000,000,000 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

========== Files/Folders - Created Within 30 Days ==========

[2012/02/20 08:56:51 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/02/19 23:50:30 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/02/16 19:23:00 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/02/16 19:23:00 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/02/16 19:23:00 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/02/16 19:22:55 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/02/16 19:22:52 | 000,000,000 | —D | C] – C:\Qoobox
[2012/02/16 19:21:57 | 004,406,022 | R— | C] (Swearware) – C:\Users\Marcos\Desktop\ComboFix.exe
[2012/02/16 12:26:39 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Marcos\Desktop\OTL.exe
[2012/02/16 11:46:48 | 000,013,800 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwhnt.sys
[2012/02/16 11:46:47 | 000,177,640 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdm.sys
[2012/02/16 11:46:47 | 000,157,672 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadbus.sys
[2012/02/16 11:46:47 | 000,016,872 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdfl.sys
[2012/02/16 11:46:47 | 000,013,288 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcmnt.sys
[2012/02/16 11:34:34 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Local\Samsung
[2012/02/16 11:34:31 | 000,000,000 | —D | C] – C:\Users\Marcos\Documents\samsung
[2012/02/16 11:34:31 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\Samsung
[2012/02/16 11:33:01 | 000,013,800 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwh.sys
[2012/02/16 11:33:01 | 000,013,288 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcm.sys
[2012/02/16 11:31:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\MarkAny
[2012/02/13 18:05:48 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\NotTetris
[2012/02/13 01:50:43 | 000,005,632 | —- | C] ( ) – C:\Users\Marcos\Desktop\cssh.exe
[2012/02/10 02:47:16 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/02/09 09:12:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2012/02/09 09:12:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2012/02/08 14:46:06 | 000,000,000 | —D | C] – C:\TEMP
[2012/02/08 14:37:43 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012/02/08 14:37:43 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\IrfanView
[2012/02/08 14:37:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\IrfanView
[2012/02/08 14:35:07 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\DeskProbes
[2012/02/08 13:25:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\iamhrh
[2012/02/06 13:15:31 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2012/02/05 21:09:46 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2012/02/05 21:09:46 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2012/01/26 19:29:04 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Local\Akamai
[2012/01/25 13:38:13 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\vDub
[2012/01/25 13:30:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2012/01/25 13:30:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\ffdshow
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/20 08:56:44 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/02/20 08:56:34 | 2146,332,671 | -HS- | M] () – C:\hiberfil.sys
[2012/02/20 02:19:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000UA.job
[2012/02/20 00:31:46 | 000,019,894 | —- | M] () – C:\Users\Marcos\Desktop\archer_archer.gif
[2012/02/20 00:18:43 | 000,168,805 | —- | M] () – C:\Users\Marcos\Desktop\body ref.jpg
[2012/02/19 23:44:40 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/02/16 19:57:26 | 000,000,000 | -HS- | M] () – C:\Windows\SysNative\dds_trash_log.cmd
[2012/02/16 19:22:08 | 004,406,022 | R— | M] (Swearware) – C:\Users\Marcos\Desktop\ComboFix.exe
[2012/02/16 17:19:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000Core.job
[2012/02/16 12:26:39 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Marcos\Desktop\OTL.exe
[2012/02/16 11:39:04 | 000,866,562 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/16 11:39:04 | 000,726,452 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/02/16 11:39:04 | 000,146,470 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/02/16 11:38:53 | 000,866,562 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/16 11:34:29 | 000,001,957 | —- | M] () – C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/02/15 18:46:21 | 000,276,221 | —- | M] () – C:\Users\Marcos\Desktop\skrillexPizza.jpg
[2012/02/14 23:02:11 | 000,014,096 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/14 23:02:11 | 000,014,096 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/09 22:21:33 | 000,132,082 | —- | M] () – C:\Users\Marcos\Desktop\schoolID.jpg
[2012/02/09 22:04:52 | 001,498,485 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-09 22.04.53.jpg
[2012/02/09 19:06:32 | 000,001,178 | —- | M] () – C:\Users\Public\Desktop\Samsung Kies mini.lnk
[2012/02/09 17:53:08 | 000,040,152 | —- | M] () – C:\Users\Marcos\Desktop\orig.png
[2012/02/09 17:22:12 | 000,058,114 | —- | M] () – C:\Users\Marcos\Desktop\convo.png
[2012/02/09 17:22:11 | 000,000,132 | —- | M] () – C:\Users\Marcos\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/02/09 17:20:40 | 000,068,416 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-09_1720.png
[2012/02/08 14:37:43 | 000,001,894 | —- | M] () – C:\Users\Marcos\Desktop\IrfanView Thumbnails.lnk
[2012/02/08 14:37:43 | 000,001,002 | —- | M] () – C:\Users\Marcos\Desktop\IrfanView.lnk
[2012/02/08 13:28:33 | 000,135,258 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-08 13.21.09.jpg
[2012/02/07 23:41:55 | 000,000,003 | —- | M] () – C:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/02/05 21:09:57 | 000,014,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2012/02/05 21:09:56 | 001,008,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\user32.dll
[2012/02/05 21:09:56 | 000,419,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\systemcpl.dll
[2012/02/05 21:09:56 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2012/02/02 13:57:43 | 000,063,779 | —- | M] () – C:\Users\Marcos\Desktop\LIKEUTPA2.jpg
[2012/02/02 13:54:44 | 000,143,179 | —- | M] () – C:\Users\Marcos\Desktop\LIKEUTPA.jpg
[2012/02/02 13:51:22 | 000,158,215 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-02_1351.png
[2012/02/01 12:06:09 | 000,819,841 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-01 11.49.15.jpg
[2012/02/01 12:03:00 | 000,000,974 | —- | M] () – C:\Users\Public\Desktop\CPUID HWMonitor.lnk
[2012/01/25 13:27:24 | 008,126,464 | —- | M] () – C:\Users\Marcos\Desktop\VideoOut.avi
[2012/01/25 13:27:22 | 007,827,494 | —- | M] () – C:\Users\Marcos\Desktop\Do You Like Bears_.mp4
[2012/01/24 15:43:12 | 001,519,383 | —- | M] () – C:\Users\Marcos\Desktop\ContextMenu.gif
[2012/01/24 15:41:10 | 001,521,256 | —- | M] () – C:\Users\Marcos\Desktop\ContextMenu
[2012/01/24 15:09:42 | 000,049,420 | —- | M] () – C:\Users\Marcos\Desktop\2012-01-24_1509.png
[2012/01/22 23:34:35 | 000,921,602 | —- | M] () – C:\Users\Marcos\Desktop\MenuPreview.gif
[2012/01/22 13:30:32 | 000,009,644 | —- | M] () – C:\Users\Marcos\Desktop\unclerayshead.png
[2012/01/21 17:07:49 | 001,236,011 | —- | M] () – C:\Users\Marcos\Desktop\RTS 2012-01-21 17-05-32-64.gif
[2012/01/21 12:34:27 | 000,008,288 | —- | M] () – C:\Users\Marcos\Desktop\RegEditBackup.reg
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/20 00:31:48 | 000,019,894 | —- | C] () – C:\Users\Marcos\Desktop\archer_archer.gif
[2012/02/20 00:19:06 | 000,168,805 | —- | C] () – C:\Users\Marcos\Desktop\body ref.jpg
[2012/02/16 19:23:00 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/02/16 19:23:00 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/02/16 19:23:00 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/02/16 19:23:00 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/02/16 19:23:00 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/02/16 11:34:29 | 000,001,957 | —- | C] () – C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/02/15 18:45:43 | 000,276,221 | —- | C] () – C:\Users\Marcos\Desktop\skrillexPizza.jpg
[2012/02/09 22:21:31 | 000,132,082 | —- | C] () – C:\Users\Marcos\Desktop\schoolID.jpg
[2012/02/09 22:06:29 | 001,498,485 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-09 22.04.53.jpg
[2012/02/09 19:06:32 | 000,001,178 | —- | C] () – C:\Users\Public\Desktop\Samsung Kies mini.lnk
[2012/02/09 17:53:08 | 000,040,152 | —- | C] () – C:\Users\Marcos\Desktop\orig.png
[2012/02/09 17:22:10 | 000,058,114 | —- | C] () – C:\Users\Marcos\Desktop\convo.png
[2012/02/09 17:20:40 | 000,068,416 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-09_1720.png
[2012/02/08 14:37:43 | 000,001,894 | —- | C] () – C:\Users\Marcos\Desktop\IrfanView Thumbnails.lnk
[2012/02/08 14:37:43 | 000,001,002 | —- | C] () – C:\Users\Marcos\Desktop\IrfanView.lnk
[2012/02/08 13:25:53 | 000,135,258 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-08 13.21.09.jpg
[2012/02/07 23:41:55 | 000,000,003 | —- | C] () – C:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/02/05 11:49:17 | 000,000,000 | -HS- | C] () – C:\Windows\SysNative\dds_trash_log.cmd
[2012/02/02 13:57:41 | 000,063,779 | —- | C] () – C:\Users\Marcos\Desktop\LIKEUTPA2.jpg
[2012/02/02 13:54:41 | 000,143,179 | —- | C] () – C:\Users\Marcos\Desktop\LIKEUTPA.jpg
[2012/02/02 13:51:22 | 000,158,215 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-02_1351.png
[2012/02/01 12:02:51 | 000,819,841 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-01 11.49.15.jpg
[2012/01/25 13:43:50 | 008,126,464 | —- | C] () – C:\Users\Marcos\Desktop\VideoOut.avi
[2012/01/25 13:30:12 | 000,079,360 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012/01/25 13:27:20 | 007,827,494 | —- | C] () – C:\Users\Marcos\Desktop\Do You Like Bears_.mp4
[2012/01/24 15:42:50 | 001,519,383 | —- | C] () – C:\Users\Marcos\Desktop\ContextMenu.gif
[2012/01/24 15:40:49 | 001,521,256 | —- | C] () – C:\Users\Marcos\Desktop\ContextMenu
[2012/01/24 15:09:42 | 000,049,420 | —- | C] () – C:\Users\Marcos\Desktop\2012-01-24_1509.png
[2012/01/22 23:34:23 | 000,921,602 | —- | C] () – C:\Users\Marcos\Desktop\MenuPreview.gif
[2012/01/22 13:30:30 | 000,009,644 | —- | C] () – C:\Users\Marcos\Desktop\unclerayshead.png
[2012/01/21 17:07:34 | 001,236,011 | —- | C] () – C:\Users\Marcos\Desktop\RTS 2012-01-21 17-05-32-64.gif
[2012/01/21 12:34:27 | 000,008,288 | —- | C] () – C:\Users\Marcos\Desktop\RegEditBackup.reg
[2011/12/24 17:00:21 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2011/12/12 16:47:16 | 000,001,456 | —- | C] () – C:\Users\Marcos\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/12/12 16:41:28 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011/11/29 16:38:18 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2011/11/29 16:38:12 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2011/11/29 16:38:12 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011/11/29 16:38:12 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011/11/29 16:38:12 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011/10/15 00:54:52 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/09/29 23:23:52 | 000,280,904 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/09/29 23:23:51 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/09/25 22:27:51 | 000,005,632 | —- | C] () – C:\Users\Marcos\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/08 21:04:25 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2011/07/24 16:03:55 | 000,007,605 | —- | C] () – C:\Users\Marcos\AppData\Local\Resmon.ResmonCfg
[2011/07/13 17:07:35 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/07/07 21:32:43 | 000,866,562 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/06 08:58:12 | 000,052,387 | —- | C] () – C:\Windows\MaxwellMayaPluginUninstall.exe
[2011/07/04 15:08:40 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/07/13 23:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== Custom Scans ==========



< MD5 for: 3DKEYBD.DLL >
[2009/07/13 19:39:46 | 000,006,656 | —- | M] (Oak Technology Inc.) MD5=5F22132C9153639762708909F156B33D – C:\Windows\SysNative\3dkeybd.dll

< End of report >
Hi socram484,

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - prefs.js..network.proxy.http: "127.0.0.1"
    FF - prefs.js..network.proxy.http_port: 56667
    FF - prefs.js..network.proxy.type: 1
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    [2012/02/16 19:57:26 | 000,000,000 | -HS- | M] () – C:\Windows\SysNative\dds_trash_log.cmd
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [2011/09/25 22:27:51 | 000,005,632 | —- | C] () – C:\Users\Marcos\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009/07/13 19:39:46 | 000,006,656 | —- | M] (Oak Technology Inc.) MD5=5F22132C9153639762708909F156B33D – C:\Windows\SysNative\3dkeybd.dll
    
    :Files
    dir "C:\Program Files (x86)\iamhrh" /s /c
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
OTL logfile created on: 2/20/2012 2:14:05 PM - Run 3
OTL by OldTimer - Version 3.2.32.0 Folder = C:\Users\Marcos\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.05 Gb Available Physical Memory | 75.62% Memory free
16.00 Gb Paging File | 13.80 Gb Available in Paging File | 86.27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 32.86 Gb Free Space | 23.51% Space Free | Partition Type: NTFS
Drive E: | 698.64 Gb Total Space | 341.35 Gb Free Space | 48.86% Space Free | Partition Type: NTFS

Computer Name: MARCOS-PC | User Name: Marcos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Marcos\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Users\Marcos\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Users\Marcos\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe ()
PRC - C:\Program Files (x86)\3d-io plugins\licensing_v2\ActiveLockServerV2.exe (3d-io GmbH)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\TechSmith\Jing\Jing.exe (TechSmith Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\Marcos\AppData\Local\Temp\c06086cf-47b1-4760-b263-4e4271d9922f\CliSecureRT.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\a8bd6b91bf16c6727723481b42ea3293\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\16498c46d223310bc8811e193bcf1205\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\5f29a2d3dc6bdadb9751faaa0f230911\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\c21fbb4bf27a7c8705e29f08827c9c7e\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\36b3b787a2942e629e87b1b96fa049d4\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\227927e469cb6b079e4cc7d81e38f8f5\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\1741fc5f7819af118d4de616016a8b2d\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\698b02e36bac06ac74077cc3ec6eced0\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\30740aecd686555cb6800b47cc80fae7\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\5c2eff65e7e457ea372f767c024c04f7\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b4e03b2b9835e9cb4e879c703880fe74\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\2d3806670b3c3e4163592b5aca62f8cc\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d4e8a005f4cdd6528f1c7295d833877f\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\avutil-51.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\avformat-53.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\avcodec-53.dll ()
MOD - C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldap32v60.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldappr32v60.dll ()
MOD - C:\Program Files\TortoiseSVN\bin\libsasl32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a0afd596da13c708d04b0a2dd1490036\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\0018b6bfd1d96454aa8fb698d0ea51a1\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\a9f6cfa4eb1436ff770995822f10e227\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\c8aa11ee6789d0f3f5542747aad7a2e4\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\173e012cca07a9b7151c574585a4ca9e\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\40404dbd013b0ca1e41ab7e57274308b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c68401de935c813374253d4fc2a18f6a\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\acbc57d41499fbc2b99194148786c677\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\338f3c91a0bea33a07a4611d324bf73a\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\16b68fcaff063835ae0ee348a1201f2a\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe ()
MOD - C:\Program Files (x86)\TechSmith\Jing\Recorder.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (ANTS Memory Profiler 7 Service) – C:\Program Files\Red Gate\ANTS Memory Profiler 7\RedGate.Memory.IISService.exe (Red Gate Software Ltd.)
SRV:64bit: - (ANTS Performance Profiler 6 Service) – C:\Program Files\Red Gate\ANTS Performance Profiler 6\RedGate.Profiler.IISService.exe (Red Gate Software Ltd.)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (TabletServiceWacom) – C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (HiPatchService) – C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (3d-io License Server v2.0) – C:\Program Files (x86)\3d-io plugins\licensing_v2\ActiveLockServerV2.exe (3d-io GmbH)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (SCDEmu) – C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (YMIDUSBW) Yamaha USB-MIDI Driver (WDM) – C:\Windows\SysNative\drivers\ymidusbx64.sys (Yamaha Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (cpuz135) – C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (xnacc) – C:\Windows\SysNative\drivers\xnacc.sys (Microsoft Corporation)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (rt61x64) – C:\Windows\SysNative\drivers\netr6164.sys (Ralink Technology, Corp.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (dgderdrv) – C:\Windows\SysWOW64\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 64 2A 01 42 94 D5 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.http: ""
FF - prefs.js..network.proxy.http_port: ""
FF - prefs.js..network.proxy.type: ""

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.10: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Marcos\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Marcos\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Marcos\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\BYOND: C:\Program Files (x86)\BYOND\bin\npbyond.dll (BYOND)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/11/09 11:47:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2012/02/02 11:46:02 | 000,000,000 | —D | M]

[2011/07/04 15:08:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Marcos\AppData\Roaming\Mozilla\Extensions
[2012/01/12 00:24:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions
[2011/10/03 18:12:13 | 000,000,000 | —D | M] (FoxyTunes) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2011/11/11 22:26:16 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/08/21 00:21:47 | 000,000,000 | —D | M] (ActiveGS) – C:\Users\Marcos\AppData\Roaming\Mozilla\Firefox\Profiles\81uu70zs.default\extensions\[removed]
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{0FA2149E-BB2C-4AC2-A8D3-479599819475}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{988DA70D-B78D-44A1-A9C7-ED11832A9E2E}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\MARCOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\81UU70ZS.DEFAULT\EXTENSIONS\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Marcos\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: BYOND stub plugin for Mozilla (Enabled) = C:\Program Files (x86)\BYOND\bin\npbyond.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Marcos\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Marcos\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus (Beta) = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: imgur = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehoopddfhgaehhmphfcooacjdpmbjlao\1.0.5_0\
CHR - Extension: AirMech = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdahlabpinmfcemhcbcfoijcpoalfgdn\7207_0\
CHR - Extension: Cloud9 = C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbdmccoknlfggadpfkmcpnamfnbkmkcp\1.9.5_0\

O1 HOSTS File: ([2012/02/19 23:44:40 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [TortoiseHgOverlayIconServer] C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe ()
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [ContourCameraFinder] C:\Program Files (x86)\ContourStoryteller\ContourAutoplay.exe ()
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Marcos\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - Startup: C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Marcos\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Thunderbird.lnk = C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
O4 - Startup: C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59DD3D3F-B7ED-404C-BA1F-84E544261B0D}: DhcpNameServer = 10.253.40.1 [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BA53C310-0C3C-4C99-B8B5-E2651CEBED41}: DhcpNameServer = 10.200.154.1 [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBFB7911-C70E-47D2-A6E5-84773522C303}: DhcpNameServer = 10.254.40.1 [removed] [removed] [removed]
O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/20 01:35:27 | 000,000,000 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/02/20 14:10:55 | 000,000,000 | —D | C] – C:\_OTL
[2012/02/20 14:08:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/02/20 14:08:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2012/02/20 08:56:51 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/02/19 23:50:30 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/02/16 19:23:00 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/02/16 19:23:00 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/02/16 19:23:00 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/02/16 19:22:55 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/02/16 19:22:52 | 000,000,000 | —D | C] – C:\Qoobox
[2012/02/16 19:21:57 | 004,406,022 | R— | C] (Swearware) – C:\Users\Marcos\Desktop\ComboFix.exe
[2012/02/16 12:26:39 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Marcos\Desktop\OTL.exe
[2012/02/16 11:46:48 | 000,013,800 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwhnt.sys
[2012/02/16 11:46:47 | 000,177,640 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdm.sys
[2012/02/16 11:46:47 | 000,157,672 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadbus.sys
[2012/02/16 11:46:47 | 000,016,872 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdfl.sys
[2012/02/16 11:46:47 | 000,013,288 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcmnt.sys
[2012/02/16 11:34:34 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Local\Samsung
[2012/02/16 11:34:31 | 000,000,000 | —D | C] – C:\Users\Marcos\Documents\samsung
[2012/02/16 11:34:31 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\Samsung
[2012/02/16 11:33:01 | 000,013,800 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwh.sys
[2012/02/16 11:33:01 | 000,013,288 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcm.sys
[2012/02/16 11:31:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\MarkAny
[2012/02/13 18:05:48 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\NotTetris
[2012/02/13 01:50:43 | 000,005,632 | —- | C] ( ) – C:\Users\Marcos\Desktop\cssh.exe
[2012/02/10 02:47:16 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/02/09 09:12:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2012/02/09 09:12:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2012/02/08 14:46:06 | 000,000,000 | —D | C] – C:\TEMP
[2012/02/08 14:37:43 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012/02/08 14:37:43 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Roaming\IrfanView
[2012/02/08 14:37:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\IrfanView
[2012/02/08 14:35:07 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\DeskProbes
[2012/02/08 13:25:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\iamhrh
[2012/02/06 13:15:31 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2012/02/05 21:09:46 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2012/02/05 21:09:46 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2012/01/26 19:29:04 | 000,000,000 | —D | C] – C:\Users\Marcos\AppData\Local\Akamai
[2012/01/25 13:38:13 | 000,000,000 | —D | C] – C:\Users\Marcos\Desktop\vDub
[2012/01/25 13:30:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2012/01/25 13:30:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\ffdshow

========== Files - Modified Within 30 Days ==========

[2012/02/20 14:12:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/02/20 14:12:04 | 2146,332,671 | -HS- | M] () – C:\hiberfil.sys
[2012/02/20 14:08:39 | 000,000,928 | —- | M] () – C:\Users\Marcos\Desktop\NTREGOPT.lnk
[2012/02/20 14:08:39 | 000,000,909 | —- | M] () – C:\Users\Marcos\Desktop\ERUNT.lnk
[2012/02/20 02:19:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000UA.job
[2012/02/20 00:31:46 | 000,019,894 | —- | M] () – C:\Users\Marcos\Desktop\archer_archer.gif
[2012/02/20 00:18:43 | 000,168,805 | —- | M] () – C:\Users\Marcos\Desktop\body ref.jpg
[2012/02/19 23:44:40 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/02/16 19:22:08 | 004,406,022 | R— | M] (Swearware) – C:\Users\Marcos\Desktop\ComboFix.exe
[2012/02/16 17:19:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1943473726-2824459890-2441723098-1000Core.job
[2012/02/16 12:26:39 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Marcos\Desktop\OTL.exe
[2012/02/16 11:39:04 | 000,866,562 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/16 11:39:04 | 000,726,452 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/02/16 11:39:04 | 000,146,470 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/02/16 11:38:53 | 000,866,562 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/16 11:34:29 | 000,001,957 | —- | M] () – C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/02/15 18:46:21 | 000,276,221 | —- | M] () – C:\Users\Marcos\Desktop\skrillexPizza.jpg
[2012/02/14 23:02:11 | 000,014,096 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/14 23:02:11 | 000,014,096 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/09 22:21:33 | 000,132,082 | —- | M] () – C:\Users\Marcos\Desktop\schoolID.jpg
[2012/02/09 22:04:52 | 001,498,485 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-09 22.04.53.jpg
[2012/02/09 19:06:32 | 000,001,178 | —- | M] () – C:\Users\Public\Desktop\Samsung Kies mini.lnk
[2012/02/09 17:53:08 | 000,040,152 | —- | M] () – C:\Users\Marcos\Desktop\orig.png
[2012/02/09 17:22:12 | 000,058,114 | —- | M] () – C:\Users\Marcos\Desktop\convo.png
[2012/02/09 17:22:11 | 000,000,132 | —- | M] () – C:\Users\Marcos\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/02/09 17:20:40 | 000,068,416 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-09_1720.png
[2012/02/08 14:37:43 | 000,001,894 | —- | M] () – C:\Users\Marcos\Desktop\IrfanView Thumbnails.lnk
[2012/02/08 14:37:43 | 000,001,002 | —- | M] () – C:\Users\Marcos\Desktop\IrfanView.lnk
[2012/02/08 13:28:33 | 000,135,258 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-08 13.21.09.jpg
[2012/02/07 23:41:55 | 000,000,003 | —- | M] () – C:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/02/05 21:09:57 | 000,014,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2012/02/05 21:09:56 | 001,008,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\user32.dll
[2012/02/05 21:09:56 | 000,419,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\systemcpl.dll
[2012/02/05 21:09:56 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2012/02/02 13:57:43 | 000,063,779 | —- | M] () – C:\Users\Marcos\Desktop\LIKEUTPA2.jpg
[2012/02/02 13:54:44 | 000,143,179 | —- | M] () – C:\Users\Marcos\Desktop\LIKEUTPA.jpg
[2012/02/02 13:51:22 | 000,158,215 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-02_1351.png
[2012/02/01 12:06:09 | 000,819,841 | —- | M] () – C:\Users\Marcos\Desktop\2012-02-01 11.49.15.jpg
[2012/02/01 12:03:00 | 000,000,974 | —- | M] () – C:\Users\Public\Desktop\CPUID HWMonitor.lnk
[2012/01/25 13:27:24 | 008,126,464 | —- | M] () – C:\Users\Marcos\Desktop\VideoOut.avi
[2012/01/25 13:27:22 | 007,827,494 | —- | M] () – C:\Users\Marcos\Desktop\Do You Like Bears_.mp4
[2012/01/24 15:43:12 | 001,519,383 | —- | M] () – C:\Users\Marcos\Desktop\ContextMenu.gif
[2012/01/24 15:41:10 | 001,521,256 | —- | M] () – C:\Users\Marcos\Desktop\ContextMenu
[2012/01/24 15:09:42 | 000,049,420 | —- | M] () – C:\Users\Marcos\Desktop\2012-01-24_1509.png
[2012/01/22 23:34:35 | 000,921,602 | —- | M] () – C:\Users\Marcos\Desktop\MenuPreview.gif
[2012/01/22 13:30:32 | 000,009,644 | —- | M] () – C:\Users\Marcos\Desktop\unclerayshead.png
[2012/01/21 17:07:49 | 001,236,011 | —- | M] () – C:\Users\Marcos\Desktop\RTS 2012-01-21 17-05-32-64.gif

========== Files Created - No Company Name ==========

[2012/02/20 14:08:39 | 000,000,928 | —- | C] () – C:\Users\Marcos\Desktop\NTREGOPT.lnk
[2012/02/20 14:08:39 | 000,000,909 | —- | C] () – C:\Users\Marcos\Desktop\ERUNT.lnk
[2012/02/20 00:31:48 | 000,019,894 | —- | C] () – C:\Users\Marcos\Desktop\archer_archer.gif
[2012/02/20 00:19:06 | 000,168,805 | —- | C] () – C:\Users\Marcos\Desktop\body ref.jpg
[2012/02/16 19:23:00 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/02/16 19:23:00 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/02/16 19:23:00 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/02/16 19:23:00 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/02/16 19:23:00 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/02/16 11:34:29 | 000,001,957 | —- | C] () – C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/02/15 18:45:43 | 000,276,221 | —- | C] () – C:\Users\Marcos\Desktop\skrillexPizza.jpg
[2012/02/09 22:21:31 | 000,132,082 | —- | C] () – C:\Users\Marcos\Desktop\schoolID.jpg
[2012/02/09 22:06:29 | 001,498,485 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-09 22.04.53.jpg
[2012/02/09 19:06:32 | 000,001,178 | —- | C] () – C:\Users\Public\Desktop\Samsung Kies mini.lnk
[2012/02/09 17:53:08 | 000,040,152 | —- | C] () – C:\Users\Marcos\Desktop\orig.png
[2012/02/09 17:22:10 | 000,058,114 | —- | C] () – C:\Users\Marcos\Desktop\convo.png
[2012/02/09 17:20:40 | 000,068,416 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-09_1720.png
[2012/02/08 14:37:43 | 000,001,894 | —- | C] () – C:\Users\Marcos\Desktop\IrfanView Thumbnails.lnk
[2012/02/08 14:37:43 | 000,001,002 | —- | C] () – C:\Users\Marcos\Desktop\IrfanView.lnk
[2012/02/08 13:25:53 | 000,135,258 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-08 13.21.09.jpg
[2012/02/07 23:41:55 | 000,000,003 | —- | C] () – C:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/02/02 13:57:41 | 000,063,779 | —- | C] () – C:\Users\Marcos\Desktop\LIKEUTPA2.jpg
[2012/02/02 13:54:41 | 000,143,179 | —- | C] () – C:\Users\Marcos\Desktop\LIKEUTPA.jpg
[2012/02/02 13:51:22 | 000,158,215 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-02_1351.png
[2012/02/01 12:02:51 | 000,819,841 | —- | C] () – C:\Users\Marcos\Desktop\2012-02-01 11.49.15.jpg
[2012/01/25 13:43:50 | 008,126,464 | —- | C] () – C:\Users\Marcos\Desktop\VideoOut.avi
[2012/01/25 13:30:12 | 000,079,360 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012/01/25 13:27:20 | 007,827,494 | —- | C] () – C:\Users\Marcos\Desktop\Do You Like Bears_.mp4
[2012/01/24 15:42:50 | 001,519,383 | —- | C] () – C:\Users\Marcos\Desktop\ContextMenu.gif
[2012/01/24 15:40:49 | 001,521,256 | —- | C] () – C:\Users\Marcos\Desktop\ContextMenu
[2012/01/24 15:09:42 | 000,049,420 | —- | C] () – C:\Users\Marcos\Desktop\2012-01-24_1509.png
[2012/01/22 23:34:23 | 000,921,602 | —- | C] () – C:\Users\Marcos\Desktop\MenuPreview.gif
[2012/01/22 13:30:30 | 000,009,644 | —- | C] () – C:\Users\Marcos\Desktop\unclerayshead.png
[2012/01/21 17:07:34 | 001,236,011 | —- | C] () – C:\Users\Marcos\Desktop\RTS 2012-01-21 17-05-32-64.gif
[2011/12/24 17:00:21 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2011/12/12 16:47:16 | 000,001,456 | —- | C] () – C:\Users\Marcos\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/12/12 16:41:28 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011/11/29 16:38:18 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2011/11/29 16:38:12 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2011/11/29 16:38:12 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011/11/29 16:38:12 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011/11/29 16:38:12 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011/10/15 00:54:52 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/09/29 23:23:52 | 000,280,904 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/09/29 23:23:51 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/09/08 21:04:25 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2011/07/24 16:03:55 | 000,007,605 | —- | C] () – C:\Users\Marcos\AppData\Local\Resmon.ResmonCfg
[2011/07/13 17:07:35 | 000,000,132 | —- | C] () – C:\Users\Marcos\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/07/07 21:32:43 | 000,866,562 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/06 08:58:12 | 000,052,387 | —- | C] () – C:\Windows\MaxwellMayaPluginUninstall.exe
[2011/07/04 15:08:40 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/07/13 23:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI