This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer is extremely slow [Solved]

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi i am need of some assistance with fixing my laptop. I lent my laptop to a friend for bout a year and i just got it back after quite some time. When i got it back, i noticed the computer was extremely slow and bogged down to the point of where i had to use safe mode in some cases to be able to operate the laptop successfully. I have certainly witnessed worse case situations then this but its pretty bad and i am fixing to use the laptop to start working on my next term of college so its absolutly essential that i fix the laptop and get it ready for school. So knowing that, i can't really format the computer because i have alot of important school data on here. In any case, the firewalls that i use normally are AVG 2011 free edition and MSI. Right now i have them both turned off because im going to be posting my DDS log file.

Some symptoms include non responsive programs, internet crashing, both browsers like firefox and Google chrome, Missing plugins for video playback, operating system lock ups and the opening, installing programs is extremely slow. The desktop is cluttered as well with a bunch of software. I am not sure which is safe and which isn't. I would not be surprised if their was a maga ton load of viruses and male ware on this machine, the user i sent it to doesn't exactly know how to use a computer that well to keep it protected so i have no idea what hes been doing. In any case i would definitely like to get this fixed as soon as you can, that is all, thank you kindly.

DDS log



.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 12:52:02.76 on Fri 03/30/2012
Internet Explorer: 8.0.7601.17514
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.1983.529 [GMT -7:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG2012\avgfws.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Airlink101\Airlink101 WLAN Monitor\RtlService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system\HsMgr.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Dennis\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Dennis\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com
mDefault_Page_URL = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\mif5ba~1\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.2.0.3\AVG Secure Search_toolbar.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mif5ba~1\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.2.0.3\AVG Secure Search_toolbar.dll
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Mal Updater 2] c:\program files\mal updater 2\MalUpdater.exe
uRun: [uTorrent] "c:\users\dennis\desktop\utorrent.exe" /MINIMIZED
uRun: [Google Update] "c:\users\dennis\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRunOnce: [Application Restart #2] c:\users\dennis\appdata\local\google\chrome\application\chrome.exe –flag-switches-begin –enable-print-preview –flag-switches-end –restore-last-session –flag-switches-begin –enable-print-preview –flag-switches-end –flag-switches-begin –enable-print-preview –flag-switches-end
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
mRun: [Cm112Sound] RunDll32 cm112.cpl,CMICtrlWnd
mRun: [Cm112GX] c:\windows\system\HsMgr.exe Envoke
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\mif5ba~1\office14\ONBttnIE.dll/105
IE: {725E77D3-B919-4eef-8EEE-D09DE618B6C1} - c:\microgaming\poker\doylesroommpp\MPPoker.exe
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\10.2.0\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\mif5ba~1\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\dennis\appdata\roaming\mozilla\firefox\profiles\xxrwuihz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Ba31b2d43-8fa5-4bf8-8b61-3993e127cdee%7D&mid=e1768720aaed47d18cebd15262d43ebe-555bad6521ae01bbd8150207adddc7da0a809f2f&ds=AVG&v=10.2.0.3&lang=en&pr=pr&d=2011-09-29%2020%3A11%3A48&sap=ku&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff10.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff4.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff5.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff6.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff7.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff8.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff9.dll
FF - plugin: c:\progra~1\mif5ba~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\mif5ba~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\npjpi160_31.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\dennis\appdata\local\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: DivX Plus Web Player HTML5 : {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\divx\divx plus web player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\divx\divx plus web player\firefox\wpa
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg2012\Firefox4
FF - Ext: AVG Security Toolbar: avg@toolbar - c:\programdata\avg secure search\10.0.0.7
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 avgfws;AVG Firewall;c:\program files\avg\avg2012\avgfws.exe [2011-8-19 2399560]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2011-4-18 20328]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-5-24 366152]
R2 NAUpdate;Nero Update;c:\program files\nero\update\NASvc.exe [2010-3-25 490280]
R2 Realtek11nCU;Realtek11nCU;c:\program files\airlink101\airlink101 wlan monitor\RtlService.exe [2012-3-15 36864]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-10-14 1153368]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134736]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-5-24 22216]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\rtl8192cu.sys [2012-3-15 630304]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 ASUSU1;ASUS Xonar U3 Audio Interface;c:\windows\system32\drivers\cm112.sys [2012-2-1 1518592]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-4-18 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2011-5-13 1492840]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2009-6-10 657408]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-9-8 15872]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-9-8 52224]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
.
=============== Created Last 30 ================
.
2012-03-30 19:45:08 6582328 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{7297b862-9406-4585-bc27-db6600bc667c}\mpengine.dll
2012-03-30 19:25:29 ——– d—–w- c:\users\dennis\appdata\local\{74100644-9AE4-49A4-97CC-CB6D11B6BCDF}
2012-03-30 04:58:43 ——– d—–w- c:\users\dennis\appdata\local\{5F4D5A1F-E992-4545-AB8B-F3358B6BEA59}
2012-03-29 11:10:03 ——– d—–w- c:\users\dennis\appdata\local\{5D1EA4B3-A141-46EB-9902-E9EB73A6D7A1}
2012-03-28 20:10:32 ——– d—–w- c:\users\dennis\appdata\local\{9877209D-836E-4E84-A940-11216D5DB26D}
2012-03-28 20:09:18 ——– d—–w- c:\users\dennis\appdata\local\{3830DD9D-8837-47EF-AFBA-2AB2876A69FD}
2012-03-27 23:33:22 ——– d—–w- c:\users\dennis\appdata\local\{C934D716-DC13-4699-9E05-951D34B90960}
2012-03-27 23:31:29 ——– d—–w- c:\users\dennis\appdata\local\{C8D49D48-3F9F-4EC9-94EB-007EF27C93EB}
2012-03-27 10:42:49 ——– d—–w- c:\users\dennis\appdata\local\{C1E3F9E0-3D5B-4E9D-B5CE-01C1E4A4BFBC}
2012-03-26 21:44:50 ——– d—–w- c:\users\dennis\appdata\local\{CE3E69E5-90C2-4555-979F-DD8E105B0343}
2012-03-26 21:43:07 ——– d—–w- c:\users\dennis\appdata\local\{AF51E302-D165-4B5E-85EE-78A0F1763E3D}
2012-03-26 06:34:53 ——– d—–w- c:\users\dennis\appdata\local\{222F52AB-0A59-4F34-A05D-AA036146FC36}
2012-03-26 06:33:06 ——– d—–w- c:\users\dennis\appdata\local\{DF4855B5-D009-4645-B27F-EE42A403ED7A}
2012-03-25 17:38:01 ——– d—–w- c:\users\dennis\appdata\local\{1CB484C7-B0DF-41B2-8CDD-7E9B2AD48F75}
2012-03-25 17:35:51 ——– d—–w- c:\users\dennis\appdata\local\{B3E4D63A-9043-4889-85DF-A3A203FA6CBD}
2012-03-25 05:23:47 ——– d—–w- c:\users\dennis\appdata\local\{BA9C0A7D-F650-4137-B740-C3C313FBEBE1}
2012-03-25 05:23:12 ——– d—–w- c:\users\dennis\appdata\local\{993BE580-89C3-4E41-8972-F3CEA4A15A19}
2012-03-24 17:22:49 ——– d—–w- c:\users\dennis\appdata\local\{C5D1D1A1-96F8-4E25-A13B-1688659669F3}
2012-03-24 17:22:17 ——– d—–w- c:\users\dennis\appdata\local\{885F0C99-163D-40E6-8E61-5D43FAB91321}
2012-03-24 05:21:57 ——– d—–w- c:\users\dennis\appdata\local\{BDC0C9BE-2248-4162-B428-4D8C7B87D539}
2012-03-24 05:21:11 ——– d—–w- c:\users\dennis\appdata\local\{93F42560-B863-43CA-AD28-A1E2D9A3F888}
2012-03-23 15:55:51 ——– d—–w- c:\users\dennis\appdata\local\{914717D4-AA16-4DD4-8596-6330F18BAAFE}
2012-03-23 02:13:18 ——– d—–w- c:\users\dennis\appdata\local\{B0960A0F-D8B3-4A41-9F73-EC4A79719D6D}
2012-03-23 02:12:01 ——– d—–w- c:\users\dennis\appdata\local\{8546323F-8385-4F4C-B549-926D133DAF7D}
2012-03-22 14:02:54 ——– d—–w- c:\users\dennis\appdata\local\{70AAC818-02CA-4634-8F06-D5554996ACB7}
2012-03-21 22:32:21 ——– d—–w- c:\users\dennis\appdata\local\{A4D65001-F5FA-43DA-BBF5-21DF9366C948}
2012-03-21 22:30:31 ——– d—–w- c:\users\dennis\appdata\local\{440A06E0-C762-4889-A552-10E21FEDFA5A}
2012-03-21 08:37:06 ——– d—–w- c:\users\dennis\appdata\local\{0D274200-4D65-4F5E-9008-BB563E952075}
2012-03-20 19:41:53 ——– d—–w- c:\program files\common files\Steam
2012-03-20 19:41:41 ——– d—–w- c:\program files\Steam
2012-03-20 19:34:39 ——– d—–w- c:\users\dennis\appdata\local\{7165A823-0A20-43CA-90F5-5E2E537BD0EE}
2012-03-20 19:33:26 ——– d—–w- c:\users\dennis\appdata\local\{B4A6BDA9-FDEF-442D-B730-6DC3414CF7A8}
2012-03-20 04:26:29 ——– d—–w- c:\users\dennis\appdata\local\{8D2C3663-1AC0-40ED-9B75-7D020EA17553}
2012-03-20 04:26:16 ——– d—–w- c:\users\dennis\appdata\local\{7AABB238-03B2-4857-8F3D-B711712D620C}
2012-03-19 16:25:32 ——– d—–w- c:\users\dennis\appdata\local\{AAEEA108-BF8A-4142-AE1F-0874D62D591A}
2012-03-19 16:24:27 ——– d—–w- c:\users\dennis\appdata\local\{09F60F2C-495E-4EAB-B018-D6BBE021B750}
2012-03-18 21:06:27 ——– d—–w- c:\users\dennis\appdata\local\{C2903B1C-31D3-4B48-A28C-967225587555}
2012-03-18 21:06:13 ——– d—–w- c:\users\dennis\appdata\local\{3C12D491-988A-49AC-BA75-D3CF1D9EF222}
2012-03-18 09:05:54 ——– d—–w- c:\users\dennis\appdata\local\{373E1277-B42F-4492-97AF-D97CBB40D3AE}
2012-03-18 09:04:53 ——– d—–w- c:\users\dennis\appdata\local\{15BD8C76-6674-4F2B-993B-09DDEDA2866D}
2012-03-17 17:41:26 ——– d—–w- c:\users\dennis\appdata\local\{F8D9ECA3-01D8-47CC-BA2B-B231EC1E77F3}
2012-03-17 17:41:01 ——– d—–w- c:\users\dennis\appdata\local\{2A14878D-D301-4738-8F91-4DCA781886FE}
2012-03-17 05:24:29 ——– d—–w- c:\users\dennis\appdata\local\{7EDEF8D8-C3AF-4110-817A-26E7CB206ACD}
2012-03-17 05:22:51 ——– d—–w- c:\users\dennis\appdata\local\{5637D58B-F965-47CD-87C4-746850B8DA17}
2012-03-16 15:01:08 ——– d—–w- c:\users\dennis\appdata\local\{E5DD5FE9-DBD4-4445-A525-4013AF79769C}
2012-03-16 00:32:11 ——– d—–w- c:\users\dennis\appdata\local\{C2B00891-4FAC-40C6-B510-C4FB98E8A71F}
2012-03-16 00:25:28 ——– d—–w- c:\program files\Cisco
2012-03-16 00:24:07 630304 —-a-r- c:\windows\system32\drivers\rtl8192cu.sys
2012-03-16 00:23:57 380928 —-a-w- c:\windows\RtlUI2.exe
2012-03-16 00:23:56 614400 —-a-w- c:\windows\system32\Rtlihvs.dll
2012-03-16 00:23:55 188416 —-a-w- c:\windows\system32\RTLExtUI.dll
2012-03-16 00:23:53 451072 —-a-w- c:\windows\system32\ISSRemoveSP.exe
2012-03-16 00:23:53 ——– d—–w- c:\program files\Airlink101
2012-03-15 13:36:33 ——– d—–w- c:\users\dennis\appdata\local\{454C3A89-90B4-47F9-B9EF-17E143B722E0}
2012-03-15 00:05:44 ——– d—–w- c:\users\dennis\appdata\local\{26932F12-D6F2-47AC-8F59-E5F31E1DF9ED}
2012-03-14 11:55:05 ——– d—–w- c:\users\dennis\appdata\local\{768A59EA-A6C1-4EE1-B0D1-42746DAD63B0}
2012-03-13 21:24:14 ——– d—–w- c:\users\dennis\appdata\local\{5A1519B6-4A3F-4756-9876-26A2AAC05165}
2012-03-13 21:23:42 ——– d—–w- c:\users\dennis\appdata\local\{C67C6E99-39F0-43DC-AB4B-ECB940F5DFEB}
2012-03-13 19:07:50 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-13 19:07:50 3913584 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-03-13 19:06:43 2343424 —-a-w- c:\windows\system32\win32k.sys
2012-03-13 19:06:41 1077248 —-a-w- c:\windows\system32\DWrite.dll
2012-03-13 19:04:33 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-13 19:04:32 58880 —-a-w- c:\windows\system32\rdpwsx.dll
2012-03-13 19:04:32 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-13 19:04:27 919040 —-a-w- c:\windows\system32\rdpcorets.dll
2012-03-13 19:04:26 826880 —-a-w- c:\windows\system32\rdpcore.dll
2012-03-13 19:04:25 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-13 19:04:25 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-13 15:10:08 ——– d—–w- c:\users\dennis\appdata\local\{3BA62051-44D3-4AA6-A942-E7F07D34E536}
2012-03-12 22:25:35 ——– d—–w- c:\users\dennis\appdata\local\{294BBBC5-68DF-4B27-91C4-3BB7ACF0A5AC}
2012-03-12 10:18:24 ——– d—–w- c:\users\dennis\appdata\local\{18A0B555-0212-4BF1-B077-604382581006}
2012-03-11 16:37:59 ——– d—–w- c:\users\dennis\appdata\local\{43ECC7B9-E8B7-42B5-B59C-951047DE45C9}
2012-03-11 16:37:07 ——– d—–w- c:\users\dennis\appdata\local\{CE863B3A-41D8-42F6-8A0A-0381A4BDA9EB}
2012-03-11 04:08:48 ——– d—–w- c:\users\dennis\appdata\local\{41912061-C5D5-4E17-A5A2-AED242394F70}
2012-03-11 04:08:35 ——– d—–w- c:\users\dennis\appdata\local\{6ECBD009-35B9-44F8-9FC9-03D0B5132219}
2012-03-10 16:08:41 ——– d—–w- c:\users\dennis\appdata\local\{BF3CB7CB-2933-4D4A-A7BA-27E1CCF85761}
2012-03-10 02:40:02 ——– d—–w- c:\users\dennis\appdata\local\Yahoo
2012-03-09 22:13:36 ——– d—–w- c:\users\dennis\appdata\local\{28561BDA-56B4-422E-9AF7-36F61BBFA0E5}
2012-03-09 22:13:17 ——– d—–w- c:\users\dennis\appdata\local\{100263A7-D7AA-4A76-A03C-AF8A2DADF38B}
2012-03-09 07:54:18 ——– d—–w- c:\users\dennis\appdata\local\{3F43CB28-B863-4749-A4DA-AE8E589B6511}
2012-03-09 07:53:59 ——– d—–w- c:\users\dennis\appdata\local\{37E5229A-20CA-484F-BF2A-769FD0D750BD}
2012-03-08 19:53:40 ——– d—–w- c:\users\dennis\appdata\local\{5507FD06-3D48-42CE-A936-3F182681D992}
2012-03-08 19:53:27 ——– d—–w- c:\users\dennis\appdata\local\{9B47611B-65C7-459B-8151-5BED98BCE6E1}
2012-03-08 07:53:07 ——– d—–w- c:\users\dennis\appdata\local\{241061C4-D480-4D00-943D-96FE357487BA}
2012-03-08 07:52:34 ——– d—–w- c:\users\dennis\appdata\local\{2C05215C-8379-414D-90E6-26C57B09019B}
2012-03-07 19:26:30 ——– d—–w- c:\users\dennis\appdata\local\{EB75A4E1-A102-497D-BB33-0FF4463F396C}
2012-03-07 19:25:35 ——– d—–w- c:\users\dennis\appdata\local\{7E3BA6A1-6006-40B4-8DE4-BE2DE1A11D40}
2012-03-07 07:23:24 ——– d—–w- c:\users\dennis\appdata\local\{C0BC4E8D-22E7-45DF-B54F-6E618651FBE7}
2012-03-07 07:22:57 ——– d—–w- c:\users\dennis\appdata\local\{AC44CD63-5468-4DB7-A4E4-E096753E99FF}
2012-03-06 19:22:33 ——– d—–w- c:\users\dennis\appdata\local\{8452B954-8D6E-459E-81F7-375E6DDED053}
2012-03-06 19:21:12 ——– d—–w- c:\users\dennis\appdata\local\{1F2B39E6-F961-498F-BD8F-E938A2E0BC87}
2012-03-06 00:45:16 ——– d—–w- c:\users\dennis\appdata\local\{F53273F9-596B-494F-893C-B5E2CBFA3BCA}
2012-03-06 00:44:51 ——– d—–w- c:\users\dennis\appdata\local\{387928B6-870D-4112-A8F0-602E087C161B}
2012-03-04 21:59:29 ——– d—–w- c:\users\dennis\appdata\local\{87C8C5D4-6E4B-4BF3-A502-052FB3B811EA}
2012-03-04 21:59:02 ——– d—–w- c:\users\dennis\appdata\local\{E45ADCFC-A4BD-4A6E-88BA-5F289A779087}
2012-03-04 04:18:18 ——– d—–w- c:\users\dennis\appdata\local\{57AC5DF6-FEF2-4CB9-A371-7282D3AB5721}
2012-03-04 04:18:05 ——– d—–w- c:\users\dennis\appdata\local\{DE70BBC9-9146-442B-856D-085EE4192AF3}
2012-03-03 16:18:14 ——– d—–w- c:\users\dennis\appdata\local\{BABF228D-04B3-426A-9A8D-472488CD71D1}
2012-03-02 23:55:31 ——– d—–w- c:\users\dennis\appdata\local\{88D4ADE8-CFD0-4E8B-BF7A-E6AFB20313F0}
2012-03-02 23:54:58 ——– d—–w- c:\users\dennis\appdata\local\{88C74DAF-F3EA-4375-8A05-53E1A40C0DA7}
2012-03-02 07:30:38 ——– d—–w- c:\users\dennis\appdata\local\{5C654109-87E2-4337-BE74-9CA63C485F77}
2012-03-02 07:29:43 ——– d—–w- c:\users\dennis\appdata\local\{9F0BCBA8-C6B1-4188-9ED1-0FBE8AFFAD75}
2012-03-01 18:10:19 ——– d—–w- c:\users\dennis\appdata\local\{7C2A3EB2-25CC-447D-A300-F588BB0B7461}
2012-03-01 18:09:11 ——– d—–w- c:\users\dennis\appdata\local\{7AEED36D-E2F4-4820-B5A8-8F78BAAE7811}
2012-02-29 23:12:59 ——– d—–w- c:\users\dennis\appdata\local\{1D31B446-7D02-4080-A755-77B1524DD0EB}
2012-02-29 23:11:10 ——– d—–w- c:\users\dennis\appdata\local\{70DFBEA5-DE4A-448A-B16A-DC4615902E51}
.
==================== Find3M ====================
.
2012-03-09 23:09:23 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-08 03:42:32 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-01-31 12:44:05 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-01-04 08:58:41 442880 —-a-w- c:\windows\system32\ntshrui.dll
.
============= FINISH: 12:53:42.38 ===============
Oh yeah another thing its doing is rerouting URL's to different addresses with out my approval. Kind of annoyance when browsing the web.

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, jeff matthews

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

A good rule of thumb is to never use more than one anti-virus software. Keep either AVG or MSE and remove the one that you don't need. Your choice. :)

—————————————————————————————————

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
===================================================

We just want the scan log from TDSSKiller only, no need for cure.

Download TDSSKiller.exe and save it to your desktop
Execute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

Please post the contents of the log in your next reply.

===================================================

On your next reply please post :
aswMBR log
TDSS Killer log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hmm, well MLBR scan crashed my computer twice. First it asked for an avast definitions in which i replied to and downloaded. After the dl was finished, it failed and windows.exe crashed. 2nd Time i scanned with it, it rebooted my machine, when it came back, the pop up message "improper shutdown" acured, so it wasn't an update or anything. TDSkiller never found anything, so i guess i don't have to post a log for that.
Ok, thanks for reporting. We will skip aswMBR for the time being.

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
ComboFix 12-04-01.01 - Dennis 04/01/2012 21:45:20.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.1983.1050 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Dennis\Documents\ChromeSetup.exe c:\windows\system32\Cache c:\windows\system32\Cache\139cda1a38e98cb1.fb c:\windows\system32\Cache\272512937d9e61a4.fb c:\windows\system32\Cache\287204568329e189.fb c:\windows\system32\Cache\28bc8f716fd76a47.fb c:\windows\system32\Cache\2c53092c95605355.fb c:\windows\system32\Cache\3917078cb68ec657.fb c:\windows\system32\Cache\590ba23ce359fd0c.fb c:\windows\system32\Cache\610289e025a3ee9a.fb c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb c:\windows\system32\Cache\6d270c1cce0237a6.fb c:\windows\system32\Cache\8b93a950dc3d17d7.fb c:\windows\system32\Cache\a8556537add6dfc5.fb c:\windows\system32\Cache\ad10a52aff5e038d.fb c:\windows\system32\Cache\c4d28dca2e7648be.fb c:\windows\system32\Cache\d201ef9910cd39de.fb c:\windows\system32\Cache\d2e94710a5708128.fb c:\windows\system32\Cache\d3341a29cf3e6c36.fb c:\windows\system32\Cache\d79b9dfe81484ec4.fb c:\windows\system32\Cache\e0de16f883bea794.fb c:\windows\system32\drivers\etc\hosts.txt . . ((((((((((((((((((((((((( Files Created from 2012-03-02 to 2012-04-02 ))))))))))))))))))))))))))))))) . . 2012-04-02 04:55 . 2012-04-02 04:55 ——– d—–w- c:\users\Dennis\AppData\Local\temp 2012-04-02 04:55 . 2012-04-02 04:55 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-02 03:33 . 2012-03-14 02:15 6582328 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E16CADA5-C685-46B6-AFD0-DFB57681294D}\mpengine.dll 2012-03-31 20:51 . 2012-03-31 20:51 ——– d—–w- c:\program files\Common Files\Java 2012-03-31 20:50 . 2012-03-31 20:50 ——– d—–w- c:\program files\Java 2012-03-20 19:41 . 2012-03-20 19:50 ——– d—–w- c:\program files\Common Files\Steam 2012-03-20 19:41 . 2012-04-01 18:25 ——– d—–w- c:\program files\Steam 2012-03-16 00:25 . 2012-03-16 00:25 ——– d—–w- c:\program files\Cisco 2012-03-16 00:24 . 2010-11-03 10:49 630304 —-a-r- c:\windows\system32\drivers\rtl8192cu.sys 2012-03-16 00:23 . 2009-03-31 21:31 380928 —-a-w- c:\windows\RtlUI2.exe 2012-03-16 00:23 . 2008-07-01 19:31 614400 —-a-w- c:\windows\system32\Rtlihvs.dll 2012-03-16 00:23 . 2009-04-02 17:27 188416 —-a-w- c:\windows\system32\RTLExtUI.dll 2012-03-16 00:23 . 2012-03-16 00:23 ——– d—–w- c:\program files\Airlink101 2012-03-16 00:23 . 2009-02-05 09:49 451072 —-a-w- c:\windows\system32\ISSRemoveSP.exe 2012-03-13 19:07 . 2011-11-19 14:50 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-03-13 19:07 . 2011-11-19 14:50 3913584 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-13 19:06 . 2012-02-03 03:54 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-03-13 19:06 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-03-13 19:04 . 2012-01-25 05:27 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-13 19:04 . 2012-01-25 05:32 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-03-13 19:04 . 2012-01-25 05:32 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-03-13 19:04 . 2012-02-17 05:34 919040 —-a-w- c:\windows\system32\rdpcorets.dll 2012-03-13 19:04 . 2012-02-17 05:34 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-13 19:04 . 2012-02-17 04:14 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-13 19:04 . 2012-02-17 04:13 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-03-10 02:40 . 2012-03-10 02:40 ——– d—–w- c:\users\Dennis\AppData\Local\Yahoo 2012-03-10 02:39 . 2012-03-10 02:39 ——– d—–w- c:\users\Dennis\AppData\Roaming\Yahoo! . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-31 20:50 . 2011-04-19 02:50 472808 —-a-w- c:\windows\system32\deployJava1.dll 2012-03-14 02:15 . 2011-10-15 22:57 6582328 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-03-09 23:09 . 2011-12-01 22:11 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-12 18:27 . 2012-02-12 18:28 713784 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7F56B4D7-8853-45E0-BC29-91EFA4041302}\gapaengine.dll 2012-01-31 12:44 . 2011-04-19 01:20 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-01-04 08:58 . 2012-02-14 20:12 442880 —-a-w- c:\windows\system32\ntshrui.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2012-03-16 19:57 1869152 —-a-w- c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll" [2012-03-16 1869152] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392] "Mal Updater 2"="c:\program files\Mal Updater 2\MalUpdater.exe" [2012-02-02 2613760] "uTorrent"="c:\users\Dennis\Desktop\utorrent.exe" [2012-03-04 740216] "Steam"="c:\program files\Steam\Steam.exe" [2012-03-20 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-06 13605408] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-06 92704] "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-25 2416480] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-09-01 449608] "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-03-16 982880] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "ROC_roc_dec12"="c:\program files\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-29 928096] "Cm112GX"="c:\windows\system\HsMgr.exe" [2008-07-11 200704] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 ASUSU1;ASUS Xonar U3 Audio Interface;c:\windows\system32\drivers\cm112.sys [2010-12-15 1518592] R3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-19 1343400] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120] S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592] S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608] S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248] S1 MpKsl9acab2d7;MpKsl9acab2d7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{625C80B9-733F-484F-B63C-992D12E52ABA}\MpKsl9acab2d7.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [2011-08-19 2399560] S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776] S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-09-01 366152] S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-03-25 490280] S2 Realtek11nCU;Realtek11nCU;c:\program files\Airlink101\Airlink101 WLAN Monitor\RtlService.exe [2010-04-16 36864] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 vToolbarUpdater10.2.0;vToolbarUpdater10.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [2012-03-16 918880] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-09-01 22216] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000] S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192cu.sys [2010-11-03 630304] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 05680713 *Deregistered* - 05680713 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-06-17 19:11 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2012-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-965785594-764187485-2921294778-1000Core.job - c:\users\Dennis\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-20 05:48] . 2012-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-965785594-764187485-2921294778-1000UA.job - c:\users\Dennis\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-20 05:48] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com mStart Page = hxxp://www.yahoo.com IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.0.1 [removed] Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll FF - ProfilePath - c:\users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\xxrwuihz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Ba31b2d43-8fa5-4bf8-8b61-3993e127cdee%7D&mid=e1768720aaed47d18cebd15262d43ebe-555bad6521ae01bbd8150207adddc7da0a809f2f&ds=AVG&v=10.2.0.3&lang=en&pr=pr&d=2011-09-29%2020%3A11%3A48&sap=ku&q= FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: DivX Plus Web Player HTML5 : {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\html5video FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\DivX\DivX Plus Web Player\firefox\wpa FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG2012\Firefox4 FF - Ext: AVG Security Toolbar: avg@toolbar - c:\programdata\AVG Secure Search\10.0.0.7 FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file) WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file) HKLM-Run-Cm112Sound - cm112.cpl . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-965785594-764187485-2921294778-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-965785594-764187485-2921294778-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-04-01 21:58:21 ComboFix-quarantined-files.txt 2012-04-02 04:58 . Pre-Run: 63,949,631,488 bytes free Post-Run: 64,052,568,064 bytes free . - - End Of File - - 69AEC4EE21D91AF647C154EE12F46541
Hi,

Multiple AntiVirus Running

I see you have more than one Anti-Virus program installed, ( AVG 2012 ) and ( MSE ).

While this may seem like greater protection, it can cause problems including slowdowns, system hangs or even crashes. This can happen if both AntiVirus applications attempt to access the same file at the same time. This may cause the applications to interfere with each other, or cause the system to lock up. It can also be a drain on system resources, making a machine run slower than it should.

Choose one of them and remove the other.

AVG 2012 Remover : http://download.avg.com/filedir/util/avgre…6_2012_2125.exe

Or

MSE
Windows Vista or Windows 7
Go to Control Panel and Click Uninstall a Program
Right-click Microsoft Security Essentials, and then click Uninstall.
Restart the computer

===================================================

I wish to see the following file from CF. Please attach the text file in your next reply.

C:\Qoobox\ComboFix-quarantined-files.txt

===================================================
Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

Folder::
c:\users\dennis\appdata\local\{74100644-9AE4-49A4-97CC-CB6D11B6BCDF}
c:\users\dennis\appdata\local\{5F4D5A1F-E992-4545-AB8B-F3358B6BEA59}
c:\users\dennis\appdata\local\{5D1EA4B3-A141-46EB-9902-E9EB73A6D7A1}
c:\users\dennis\appdata\local\{9877209D-836E-4E84-A940-11216D5DB26D}
c:\users\dennis\appdata\local\{3830DD9D-8837-47EF-AFBA-2AB2876A69FD}
c:\users\dennis\appdata\local\{C934D716-DC13-4699-9E05-951D34B90960}
c:\users\dennis\appdata\local\{C8D49D48-3F9F-4EC9-94EB-007EF27C93EB}
c:\users\dennis\appdata\local\{C1E3F9E0-3D5B-4E9D-B5CE-01C1E4A4BFBC}
c:\users\dennis\appdata\local\{CE3E69E5-90C2-4555-979F-DD8E105B0343}
c:\users\dennis\appdata\local\{AF51E302-D165-4B5E-85EE-78A0F1763E3D}
c:\users\dennis\appdata\local\{222F52AB-0A59-4F34-A05D-AA036146FC36}
c:\users\dennis\appdata\local\{DF4855B5-D009-4645-B27F-EE42A403ED7A}
c:\users\dennis\appdata\local\{1CB484C7-B0DF-41B2-8CDD-7E9B2AD48F75}
c:\users\dennis\appdata\local\{B3E4D63A-9043-4889-85DF-A3A203FA6CBD}
c:\users\dennis\appdata\local\{BA9C0A7D-F650-4137-B740-C3C313FBEBE1}
c:\users\dennis\appdata\local\{993BE580-89C3-4E41-8972-F3CEA4A15A19}
c:\users\dennis\appdata\local\{C5D1D1A1-96F8-4E25-A13B-1688659669F3}
c:\users\dennis\appdata\local\{885F0C99-163D-40E6-8E61-5D43FAB91321}
c:\users\dennis\appdata\local\{BDC0C9BE-2248-4162-B428-4D8C7B87D539}
c:\users\dennis\appdata\local\{93F42560-B863-43CA-AD28-A1E2D9A3F888}
c:\users\dennis\appdata\local\{914717D4-AA16-4DD4-8596-6330F18BAAFE}
c:\users\dennis\appdata\local\{B0960A0F-D8B3-4A41-9F73-EC4A79719D6D}
c:\users\dennis\appdata\local\{8546323F-8385-4F4C-B549-926D133DAF7D}
c:\users\dennis\appdata\local\{70AAC818-02CA-4634-8F06-D5554996ACB7}
c:\users\dennis\appdata\local\{A4D65001-F5FA-43DA-BBF5-21DF9366C948}
c:\users\dennis\appdata\local\{440A06E0-C762-4889-A552-10E21FEDFA5A}
c:\users\dennis\appdata\local\{0D274200-4D65-4F5E-9008-BB563E952075}
c:\users\dennis\appdata\local\{7165A823-0A20-43CA-90F5-5E2E537BD0EE}
c:\users\dennis\appdata\local\{B4A6BDA9-FDEF-442D-B730-6DC3414CF7A8}
c:\users\dennis\appdata\local\{8D2C3663-1AC0-40ED-9B75-7D020EA17553}
c:\users\dennis\appdata\local\{7AABB238-03B2-4857-8F3D-B711712D620C}
c:\users\dennis\appdata\local\{AAEEA108-BF8A-4142-AE1F-0874D62D591A}
c:\users\dennis\appdata\local\{09F60F2C-495E-4EAB-B018-D6BBE021B750}
c:\users\dennis\appdata\local\{C2903B1C-31D3-4B48-A28C-967225587555}
c:\users\dennis\appdata\local\{3C12D491-988A-49AC-BA75-D3CF1D9EF222}
c:\users\dennis\appdata\local\{373E1277-B42F-4492-97AF-D97CBB40D3AE}
c:\users\dennis\appdata\local\{15BD8C76-6674-4F2B-993B-09DDEDA2866D}
c:\users\dennis\appdata\local\{F8D9ECA3-01D8-47CC-BA2B-B231EC1E77F3}
c:\users\dennis\appdata\local\{2A14878D-D301-4738-8F91-4DCA781886FE}
c:\users\dennis\appdata\local\{7EDEF8D8-C3AF-4110-817A-26E7CB206ACD}
c:\users\dennis\appdata\local\{5637D58B-F965-47CD-87C4-746850B8DA17}
c:\users\dennis\appdata\local\{E5DD5FE9-DBD4-4445-A525-4013AF79769C}
c:\users\dennis\appdata\local\{C2B00891-4FAC-40C6-B510-C4FB98E8A71F}
c:\users\dennis\appdata\local\{454C3A89-90B4-47F9-B9EF-17E143B722E0}
c:\users\dennis\appdata\local\{26932F12-D6F2-47AC-8F59-E5F31E1DF9ED}
c:\users\dennis\appdata\local\{768A59EA-A6C1-4EE1-B0D1-42746DAD63B0}
c:\users\dennis\appdata\local\{5A1519B6-4A3F-4756-9876-26A2AAC05165}
c:\users\dennis\appdata\local\{C67C6E99-39F0-43DC-AB4B-ECB940F5DFEB}
c:\users\dennis\appdata\local\{3BA62051-44D3-4AA6-A942-E7F07D34E536}
c:\users\dennis\appdata\local\{294BBBC5-68DF-4B27-91C4-3BB7ACF0A5AC}
c:\users\dennis\appdata\local\{18A0B555-0212-4BF1-B077-604382581006}
c:\users\dennis\appdata\local\{43ECC7B9-E8B7-42B5-B59C-951047DE45C9}
c:\users\dennis\appdata\local\{CE863B3A-41D8-42F6-8A0A-0381A4BDA9EB}
c:\users\dennis\appdata\local\{41912061-C5D5-4E17-A5A2-AED242394F70}
c:\users\dennis\appdata\local\{6ECBD009-35B9-44F8-9FC9-03D0B5132219}
c:\users\dennis\appdata\local\{BF3CB7CB-2933-4D4A-A7BA-27E1CCF85761}
c:\users\dennis\appdata\local\{28561BDA-56B4-422E-9AF7-36F61BBFA0E5}
c:\users\dennis\appdata\local\{100263A7-D7AA-4A76-A03C-AF8A2DADF38B}
c:\users\dennis\appdata\local\{3F43CB28-B863-4749-A4DA-AE8E589B6511}
c:\users\dennis\appdata\local\{37E5229A-20CA-484F-BF2A-769FD0D750BD}
c:\users\dennis\appdata\local\{5507FD06-3D48-42CE-A936-3F182681D992}
c:\users\dennis\appdata\local\{9B47611B-65C7-459B-8151-5BED98BCE6E1}
c:\users\dennis\appdata\local\{241061C4-D480-4D00-943D-96FE357487BA}
c:\users\dennis\appdata\local\{2C05215C-8379-414D-90E6-26C57B09019B}
c:\users\dennis\appdata\local\{EB75A4E1-A102-497D-BB33-0FF4463F396C}
c:\users\dennis\appdata\local\{7E3BA6A1-6006-40B4-8DE4-BE2DE1A11D40}
c:\users\dennis\appdata\local\{C0BC4E8D-22E7-45DF-B54F-6E618651FBE7}
c:\users\dennis\appdata\local\{AC44CD63-5468-4DB7-A4E4-E096753E99FF}
c:\users\dennis\appdata\local\{8452B954-8D6E-459E-81F7-375E6DDED053}
c:\users\dennis\appdata\local\{1F2B39E6-F961-498F-BD8F-E938A2E0BC87}
c:\users\dennis\appdata\local\{F53273F9-596B-494F-893C-B5E2CBFA3BCA}
c:\users\dennis\appdata\local\{387928B6-870D-4112-A8F0-602E087C161B}
c:\users\dennis\appdata\local\{87C8C5D4-6E4B-4BF3-A502-052FB3B811EA}
c:\users\dennis\appdata\local\{E45ADCFC-A4BD-4A6E-88BA-5F289A779087}
c:\users\dennis\appdata\local\{57AC5DF6-FEF2-4CB9-A371-7282D3AB5721}
c:\users\dennis\appdata\local\{DE70BBC9-9146-442B-856D-085EE4192AF3}
c:\users\dennis\appdata\local\{BABF228D-04B3-426A-9A8D-472488CD71D1}
c:\users\dennis\appdata\local\{88D4ADE8-CFD0-4E8B-BF7A-E6AFB20313F0}
c:\users\dennis\appdata\local\{88C74DAF-F3EA-4375-8A05-53E1A40C0DA7}
c:\users\dennis\appdata\local\{5C654109-87E2-4337-BE74-9CA63C485F77}
c:\users\dennis\appdata\local\{9F0BCBA8-C6B1-4188-9ED1-0FBE8AFFAD75}
c:\users\dennis\appdata\local\{7C2A3EB2-25CC-447D-A300-F588BB0B7461}
c:\users\dennis\appdata\local\{7AEED36D-E2F4-4820-B5A8-8F78BAAE7811}
c:\users\dennis\appdata\local\{1D31B446-7D02-4080-A755-77B1524DD0EB}
c:\users\dennis\appdata\local\{70DFBEA5-DE4A-448A-B16A-DC4615902E51}

DDS:
uRun: [Mal Updater 2] c:\program files\mal updater 2\MalUpdater.exe


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

When finished, it shall produce a log for you. Please post that log, C:\ComboFix.txt, in your next reply.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

===================================================

On your next reply please post :
ComboFix Quarantined Files
ComboFix log
How is it running at the moment?


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
ComboFix 12-04-01.01 - Dennis 04/02/2012 13:06:07.2.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.1983.1279 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Dennis\Desktop\CFScript.txt AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\dennis\appdata\local\{09F60F2C-495E-4EAB-B018-D6BBE021B750} c:\users\dennis\appdata\local\{0D274200-4D65-4F5E-9008-BB563E952075} c:\users\dennis\appdata\local\{100263A7-D7AA-4A76-A03C-AF8A2DADF38B} c:\users\dennis\appdata\local\{15BD8C76-6674-4F2B-993B-09DDEDA2866D} c:\users\dennis\appdata\local\{18A0B555-0212-4BF1-B077-604382581006} c:\users\dennis\appdata\local\{1CB484C7-B0DF-41B2-8CDD-7E9B2AD48F75} c:\users\dennis\appdata\local\{1D31B446-7D02-4080-A755-77B1524DD0EB} c:\users\dennis\appdata\local\{1F2B39E6-F961-498F-BD8F-E938A2E0BC87} c:\users\dennis\appdata\local\{222F52AB-0A59-4F34-A05D-AA036146FC36} c:\users\dennis\appdata\local\{241061C4-D480-4D00-943D-96FE357487BA} c:\users\dennis\appdata\local\{26932F12-D6F2-47AC-8F59-E5F31E1DF9ED} c:\users\dennis\appdata\local\{28561BDA-56B4-422E-9AF7-36F61BBFA0E5} c:\users\dennis\appdata\local\{294BBBC5-68DF-4B27-91C4-3BB7ACF0A5AC} c:\users\dennis\appdata\local\{2A14878D-D301-4738-8F91-4DCA781886FE} c:\users\dennis\appdata\local\{2C05215C-8379-414D-90E6-26C57B09019B} c:\users\dennis\appdata\local\{373E1277-B42F-4492-97AF-D97CBB40D3AE} c:\users\dennis\appdata\local\{37E5229A-20CA-484F-BF2A-769FD0D750BD} c:\users\dennis\appdata\local\{3830DD9D-8837-47EF-AFBA-2AB2876A69FD} c:\users\dennis\appdata\local\{387928B6-870D-4112-A8F0-602E087C161B} c:\users\dennis\appdata\local\{3BA62051-44D3-4AA6-A942-E7F07D34E536} c:\users\dennis\appdata\local\{3C12D491-988A-49AC-BA75-D3CF1D9EF222} c:\users\dennis\appdata\local\{3F43CB28-B863-4749-A4DA-AE8E589B6511} c:\users\dennis\appdata\local\{41912061-C5D5-4E17-A5A2-AED242394F70} c:\users\dennis\appdata\local\{43ECC7B9-E8B7-42B5-B59C-951047DE45C9} c:\users\dennis\appdata\local\{440A06E0-C762-4889-A552-10E21FEDFA5A} c:\users\dennis\appdata\local\{454C3A89-90B4-47F9-B9EF-17E143B722E0} c:\users\dennis\appdata\local\{5507FD06-3D48-42CE-A936-3F182681D992} c:\users\dennis\appdata\local\{5637D58B-F965-47CD-87C4-746850B8DA17} c:\users\dennis\appdata\local\{57AC5DF6-FEF2-4CB9-A371-7282D3AB5721} c:\users\dennis\appdata\local\{5A1519B6-4A3F-4756-9876-26A2AAC05165} c:\users\dennis\appdata\local\{5C654109-87E2-4337-BE74-9CA63C485F77} c:\users\dennis\appdata\local\{5D1EA4B3-A141-46EB-9902-E9EB73A6D7A1} c:\users\dennis\appdata\local\{5F4D5A1F-E992-4545-AB8B-F3358B6BEA59} c:\users\dennis\appdata\local\{6ECBD009-35B9-44F8-9FC9-03D0B5132219} c:\users\dennis\appdata\local\{70AAC818-02CA-4634-8F06-D5554996ACB7} c:\users\dennis\appdata\local\{70DFBEA5-DE4A-448A-B16A-DC4615902E51} c:\users\dennis\appdata\local\{7165A823-0A20-43CA-90F5-5E2E537BD0EE} c:\users\dennis\appdata\local\{74100644-9AE4-49A4-97CC-CB6D11B6BCDF} c:\users\dennis\appdata\local\{768A59EA-A6C1-4EE1-B0D1-42746DAD63B0} c:\users\dennis\appdata\local\{7AABB238-03B2-4857-8F3D-B711712D620C} c:\users\dennis\appdata\local\{7AEED36D-E2F4-4820-B5A8-8F78BAAE7811} c:\users\dennis\appdata\local\{7C2A3EB2-25CC-447D-A300-F588BB0B7461} c:\users\dennis\appdata\local\{7E3BA6A1-6006-40B4-8DE4-BE2DE1A11D40} c:\users\dennis\appdata\local\{7EDEF8D8-C3AF-4110-817A-26E7CB206ACD} c:\users\dennis\appdata\local\{8452B954-8D6E-459E-81F7-375E6DDED053} c:\users\dennis\appdata\local\{8546323F-8385-4F4C-B549-926D133DAF7D} c:\users\dennis\appdata\local\{87C8C5D4-6E4B-4BF3-A502-052FB3B811EA} c:\users\dennis\appdata\local\{885F0C99-163D-40E6-8E61-5D43FAB91321} c:\users\dennis\appdata\local\{88C74DAF-F3EA-4375-8A05-53E1A40C0DA7} c:\users\dennis\appdata\local\{88D4ADE8-CFD0-4E8B-BF7A-E6AFB20313F0} c:\users\dennis\appdata\local\{8D2C3663-1AC0-40ED-9B75-7D020EA17553} c:\users\dennis\appdata\local\{914717D4-AA16-4DD4-8596-6330F18BAAFE} c:\users\dennis\appdata\local\{93F42560-B863-43CA-AD28-A1E2D9A3F888} c:\users\dennis\appdata\local\{9877209D-836E-4E84-A940-11216D5DB26D} c:\users\dennis\appdata\local\{993BE580-89C3-4E41-8972-F3CEA4A15A19} c:\users\dennis\appdata\local\{9B47611B-65C7-459B-8151-5BED98BCE6E1} c:\users\dennis\appdata\local\{9F0BCBA8-C6B1-4188-9ED1-0FBE8AFFAD75} c:\users\dennis\appdata\local\{A4D65001-F5FA-43DA-BBF5-21DF9366C948} c:\users\dennis\appdata\local\{AAEEA108-BF8A-4142-AE1F-0874D62D591A} c:\users\dennis\appdata\local\{AC44CD63-5468-4DB7-A4E4-E096753E99FF} c:\users\dennis\appdata\local\{AF51E302-D165-4B5E-85EE-78A0F1763E3D} c:\users\dennis\appdata\local\{B0960A0F-D8B3-4A41-9F73-EC4A79719D6D} c:\users\dennis\appdata\local\{B3E4D63A-9043-4889-85DF-A3A203FA6CBD} c:\users\dennis\appdata\local\{B4A6BDA9-FDEF-442D-B730-6DC3414CF7A8} c:\users\dennis\appdata\local\{BA9C0A7D-F650-4137-B740-C3C313FBEBE1} c:\users\dennis\appdata\local\{BABF228D-04B3-426A-9A8D-472488CD71D1} c:\users\dennis\appdata\local\{BDC0C9BE-2248-4162-B428-4D8C7B87D539} c:\users\dennis\appdata\local\{BF3CB7CB-2933-4D4A-A7BA-27E1CCF85761} c:\users\dennis\appdata\local\{C0BC4E8D-22E7-45DF-B54F-6E618651FBE7} c:\users\dennis\appdata\local\{C1E3F9E0-3D5B-4E9D-B5CE-01C1E4A4BFBC} c:\users\dennis\appdata\local\{C2903B1C-31D3-4B48-A28C-967225587555} c:\users\dennis\appdata\local\{C2B00891-4FAC-40C6-B510-C4FB98E8A71F} c:\users\dennis\appdata\local\{C5D1D1A1-96F8-4E25-A13B-1688659669F3} c:\users\dennis\appdata\local\{C67C6E99-39F0-43DC-AB4B-ECB940F5DFEB} c:\users\dennis\appdata\local\{C8D49D48-3F9F-4EC9-94EB-007EF27C93EB} c:\users\dennis\appdata\local\{C934D716-DC13-4699-9E05-951D34B90960} c:\users\dennis\appdata\local\{CE3E69E5-90C2-4555-979F-DD8E105B0343} c:\users\dennis\appdata\local\{CE863B3A-41D8-42F6-8A0A-0381A4BDA9EB} c:\users\dennis\appdata\local\{DE70BBC9-9146-442B-856D-085EE4192AF3} c:\users\dennis\appdata\local\{DF4855B5-D009-4645-B27F-EE42A403ED7A} c:\users\dennis\appdata\local\{E45ADCFC-A4BD-4A6E-88BA-5F289A779087} c:\users\dennis\appdata\local\{E5DD5FE9-DBD4-4445-A525-4013AF79769C} c:\users\dennis\appdata\local\{EB75A4E1-A102-497D-BB33-0FF4463F396C} c:\users\dennis\appdata\local\{F53273F9-596B-494F-893C-B5E2CBFA3BCA} c:\users\dennis\appdata\local\{F8D9ECA3-01D8-47CC-BA2B-B231EC1E77F3} . . ((((((((((((((((((((((((( Files Created from 2012-03-02 to 2012-04-02 ))))))))))))))))))))))))))))))) . . 2012-04-02 20:17 . 2012-04-02 20:17 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2012-04-02 20:17 . 2012-04-02 20:17 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-02 04:55 . 2012-04-02 20:17 ——– d—–w- c:\users\Dennis\AppData\Local\temp 2012-04-02 03:33 . 2012-03-14 02:15 6582328 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E16CADA5-C685-46B6-AFD0-DFB57681294D}\mpengine.dll 2012-03-31 20:51 . 2012-03-31 20:51 ——– d—–w- c:\program files\Common Files\Java 2012-03-31 20:50 . 2012-03-31 20:50 ——– d—–w- c:\program files\Java 2012-03-20 19:41 . 2012-03-20 19:50 ——– d—–w- c:\program files\Common Files\Steam 2012-03-20 19:41 . 2012-04-01 18:25 ——– d—–w- c:\program files\Steam 2012-03-16 00:25 . 2012-03-16 00:25 ——– d—–w- c:\program files\Cisco 2012-03-16 00:24 . 2010-11-03 10:49 630304 —-a-r- c:\windows\system32\drivers\rtl8192cu.sys 2012-03-16 00:23 . 2009-03-31 21:31 380928 —-a-w- c:\windows\RtlUI2.exe 2012-03-16 00:23 . 2008-07-01 19:31 614400 —-a-w- c:\windows\system32\Rtlihvs.dll 2012-03-16 00:23 . 2009-04-02 17:27 188416 —-a-w- c:\windows\system32\RTLExtUI.dll 2012-03-16 00:23 . 2012-03-16 00:23 ——– d—–w- c:\program files\Airlink101 2012-03-16 00:23 . 2009-02-05 09:49 451072 —-a-w- c:\windows\system32\ISSRemoveSP.exe 2012-03-13 19:07 . 2011-11-19 14:50 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-03-13 19:07 . 2011-11-19 14:50 3913584 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-13 19:06 . 2012-02-03 03:54 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-03-13 19:06 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-03-13 19:04 . 2012-01-25 05:27 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-13 19:04 . 2012-01-25 05:32 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-03-13 19:04 . 2012-01-25 05:32 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-03-13 19:04 . 2012-02-17 05:34 919040 —-a-w- c:\windows\system32\rdpcorets.dll 2012-03-13 19:04 . 2012-02-17 05:34 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-13 19:04 . 2012-02-17 04:14 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-13 19:04 . 2012-02-17 04:13 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-03-10 02:40 . 2012-03-10 02:40 ——– d—–w- c:\users\Dennis\AppData\Local\Yahoo 2012-03-10 02:39 . 2012-03-10 02:39 ——– d—–w- c:\users\Dennis\AppData\Roaming\Yahoo! . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-31 20:50 . 2011-04-19 02:50 472808 —-a-w- c:\windows\system32\deployJava1.dll 2012-03-14 02:15 . 2011-10-15 22:57 6582328 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-03-09 23:09 . 2011-12-01 22:11 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-12 18:27 . 2012-02-12 18:28 713784 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7F56B4D7-8853-45E0-BC29-91EFA4041302}\gapaengine.dll 2012-01-31 12:44 . 2011-04-19 01:20 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-01-04 08:58 . 2012-02-14 20:12 442880 —-a-w- c:\windows\system32\ntshrui.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2012-03-16 19:57 1869152 —-a-w- c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll" [2012-03-16 1869152] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392] "Mal Updater 2"="c:\program files\Mal Updater 2\MalUpdater.exe" [2012-02-02 2613760] "uTorrent"="c:\users\Dennis\Desktop\utorrent.exe" [2012-03-04 740216] "Steam"="c:\program files\Steam\Steam.exe" [2012-03-20 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-06 13605408] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-06 92704] "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-25 2416480] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-09-01 449608] "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-03-16 982880] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "ROC_roc_dec12"="c:\program files\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-29 928096] "Cm112GX"="c:\windows\system\HsMgr.exe" [2008-07-11 200704] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 ASUSU1;ASUS Xonar U3 Audio Interface;c:\windows\system32\drivers\cm112.sys [2010-12-15 1518592] R3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-19 1343400] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120] S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592] S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608] S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248] S1 MpKsl9acab2d7;MpKsl9acab2d7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{625C80B9-733F-484F-B63C-992D12E52ABA}\MpKsl9acab2d7.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [2011-08-19 2399560] S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776] S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-09-01 366152] S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-03-25 490280] S2 Realtek11nCU;Realtek11nCU;c:\program files\Airlink101\Airlink101 WLAN Monitor\RtlService.exe [2010-04-16 36864] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 vToolbarUpdater10.2.0;vToolbarUpdater10.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [2012-03-16 918880] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-09-01 22216] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000] S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192cu.sys [2010-11-03 630304] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 05680713 *Deregistered* - 05680713 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-06-17 19:11 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2012-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-965785594-764187485-2921294778-1000Core.job - c:\users\Dennis\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-20 05:48] . 2012-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-965785594-764187485-2921294778-1000UA.job - c:\users\Dennis\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-20 05:48] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com mStart Page = hxxp://www.yahoo.com IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.0.1 [removed] Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll FF - ProfilePath - c:\users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\xxrwuihz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Ba31b2d43-8fa5-4bf8-8b61-3993e127cdee%7D&mid=e1768720aaed47d18cebd15262d43ebe-555bad6521ae01bbd8150207adddc7da0a809f2f&ds=AVG&v=10.2.0.3&lang=en&pr=pr&d=2011-09-29%2020%3A11%3A48&sap=ku&q= FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: DivX Plus Web Player HTML5 : {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\html5video FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\DivX\DivX Plus Web Player\firefox\wpa FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG2012\Firefox4 FF - Ext: AVG Security Toolbar: avg@toolbar - c:\programdata\AVG Secure Search\10.0.0.7 FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-965785594-764187485-2921294778-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-965785594-764187485-2921294778-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-04-02 13:20:00 ComboFix-quarantined-files.txt 2012-04-02 20:20 ComboFix2.txt 2012-04-02 04:58 . Pre-Run: 66,041,716,736 bytes free Post-Run: 65,708,118,016 bytes free . - - End Of File - - DC5BC7116EB804F73AA1621CDABD3328 Yeah, wow what did you do. Pages are loading much quicker, obvously the problem i think was in google chrome the browser i was using but im not sure. IN any case opening windows, scrolling, clicking on icons, etc, is all much quicker now then it used to be. What sort of infections did you actually get rid of with that initial scan. Those tools must be really powerful stuff. I tried my regular antimaleware, and avg scans, as well as spybot but to no avail, i couldn't get rid of the reason why the computer was so slow. And just so you know i never ran these programs after i made this topic.
Could you please post the quarantined log from CF for me? C:\Qoobox\ComboFix-quarantined-files.txt Thanks :)
Alright here you go, are we going to do any final clean up or any other extensive testing to make sure all of the infections are gone. Because just because computer is absent of symptoms does not necessarily mean that the pc is completely clean, i learned that through bitter experiences. 2012-04-02 20:05:49 . 2012-04-02 20:05:49 0 —-a-w- C:\Qoobox\Quarantine\catchme.txt 2012-04-02 04:57:03 . 2012-04-02 04:57:03 126 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-Cm112Sound.reg.dat 2012-04-02 04:57:00 . 2012-04-02 04:57:00 600 —-a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}.reg.dat 2012-04-02 04:56:57 . 2012-04-02 04:56:57 118 —-a-w- C:\Qoobox\Quarantine\Registry_backups\URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}.reg.dat 2012-04-02 04:52:14 . 2012-04-02 20:13:48 16,485 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2012-04-02 04:42:44 . 2012-04-02 20:05:49 124 —-a-w- C:\Qoobox\Quarantine\catchme.log 2012-03-16 19:57:11 . 2012-03-16 19:57:02 7,902 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\6d270c1cce0237a6.fb.vir 2012-01-29 07:24:20 . 2012-03-16 19:57:02 669 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\a8556537add6dfc5.fb.vir 2012-01-29 07:24:19 . 2012-01-29 07:24:04 7,902 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\139cda1a38e98cb1.fb.vir 2011-12-24 01:00:51 . 2012-03-16 19:57:02 586 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\c4d28dca2e7648be.fb.vir 2011-12-24 01:00:51 . 2012-03-16 19:57:02 1,062 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\e0de16f883bea794.fb.vir 2011-12-24 01:00:50 . 2011-12-24 01:00:34 7,790 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\8b93a950dc3d17d7.fb.vir 2011-11-13 20:00:08 . 2011-11-13 20:04:55 438,379 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\drivers\etc\hosts.txt.vir 2011-11-09 21:31:03 . 2012-03-16 19:57:03 639 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\590ba23ce359fd0c.fb.vir 2011-11-09 21:31:03 . 2012-03-16 19:57:02 630 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\272512937d9e61a4.fb.vir 2011-11-09 21:31:03 . 2012-03-16 19:57:02 398 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\6c59ac5e7e7a3ad0.fb.vir 2011-11-09 21:31:03 . 2012-03-16 19:57:02 627 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\651c5d3cdbfb8bd1.fb.vir 2011-11-09 21:31:03 . 2012-03-16 19:57:03 1,045 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\d201ef9910cd39de.fb.vir 2011-11-09 21:31:03 . 2012-03-16 19:57:02 366 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\ad10a52aff5e038d.fb.vir 2011-11-09 21:31:03 . 2012-03-16 19:57:02 622 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\287204568329e189.fb.vir 2011-11-09 21:31:03 . 2012-03-16 19:57:02 365 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\610289e025a3ee9a.fb.vir 2011-11-09 21:31:02 . 2012-03-16 19:57:02 627 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\d79b9dfe81484ec4.fb.vir 2011-11-09 21:31:02 . 2012-03-16 19:57:02 567 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\d2e94710a5708128.fb.vir 2011-11-09 21:31:02 . 2012-03-16 19:57:02 1,022 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\3917078cb68ec657.fb.vir 2011-11-09 21:31:02 . 2012-03-16 19:57:02 633 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\2c53092c95605355.fb.vir 2011-11-09 21:31:02 . 2012-03-16 19:57:02 1,291 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\28bc8f716fd76a47.fb.vir 2011-11-09 21:31:02 . 2011-11-09 21:30:59 6,109 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\cache\d3341a29cf3e6c36.fb.vir 2011-04-19 01:24:15 . 2010-07-15 23:46:58 567,664 —-a-w- C:\Qoobox\Quarantine\C\Users\Dennis\Documents\ChromeSetup.exe.vir
Yes we are going to do some follow up. :)

Is there any reason that you exclude this entry from CFScript?

uRun: [Mal Updater 2] c:\program files\mal updater 2\MalUpdater.exe

===================================================

Follow these steps to display hidden files and folders.

  • Open Folder Options by clicking the Start button [external image: Posted Image], clicking Control Panel, clicking Appearance and Personalization, and then clicking Folder Options.
  • Click the View tab.
  • Under Advanced settings, click Show hidden files and folders
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan


click on Browse, and upload the following file for analysis:
C:\Qoobox\Quarantine\C\Users\Dennis\Documents\ChromeSetup.exe.vir

Then click Submit. Allow the file to be scanned, and then please copy and paste the results link(for Virus Total) here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.
I never excluded any entries in the testing. I copied and pasted exactly what the log shown. MAL updater is a program i use quite frequently so i don't see how that can be an infectious file. Why did the scanners archive it has being a potential threat? It is basically a software app that enables me to update organized lists and entries from a certain forum site i been using for years. It is a fanmade application but ive never had any issues with it before.

Also i ran that test with Google chrome, my web browser and it didn't go through, it came up with a small window that said "Oops" and then i click ok and it tried to re analyse it but did the same thing.

Finally i used IE to analyse it and it has no issues with the test, so here it is.

https://www.virustotal.com/file/793fc250bc3…sis/1333572373/


I just want to add that what ever testing I did with combo fix at that time seemed to fix many of the slow down issues to some extent, but now today the browser is unusually slow again and i am getting the same symtoms as i was before like pictures not loading, videos having trouble streaming, urls re routing several times before actually connecting, Java adobe reading enabled pugins failing, etc.
For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Alright here it is Scan result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 14-03-2012 Ran by [removed] at 06-04-2012 15:11:06 Running from F:\ Windows 7 Ultimate (X86) OS Language: English(US) The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\…\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [997920 2011-06-15] (Microsoft Corporation) HKLM\…\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [13605408 2009-03-06] (NVIDIA Corporation) HKLM\…\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [92704 2009-03-06] (NVIDIA Corporation) HKLM\…\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" [2416480 2012-01-24] (AVG Technologies CZ, s.r.o.) HKLM\…\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [449608 2011-08-31] (Malwarebytes Corporation) HKLM\…\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" [982880 2012-03-16] () HKLM\…\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] () HKLM\…\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation) HKLM\…\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-30] (Adobe Systems Incorporated) HKLM\…\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM\…\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-12] (Adobe Systems Incorporated) HKLM\…\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-01-03] (Adobe Systems Incorporated) HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated) HKLM\…\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 [928096 2012-01-28] () HKLM\…\Run: [Cm112GX] C:\Windows\system\HsMgr.exe Envoke [200704 2008-07-10] () HKLM\…\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.) HKU\Dennis\…\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet [5252408 2010-06-01] (Yahoo! Inc.) HKU\Dennis\…\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2009-06-17] (Hewlett-Packard Company) HKU\Dennis\…\Run: [Mal Updater 2] C:\Program Files\Mal Updater 2\MalUpdater.exe [2613760 2012-02-01] (eden.fm) HKU\Dennis\…\Run: [uTorrent] "C:\Users\Dennis\Desktop\utorrent.exe" /MINIMIZED [740216 2012-03-03] (BitTorrent, Inc.) HKU\Dennis\…\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent [1242448 2012-03-20] (Valve Corporation) HKU\Dennis\…\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4283256 2011-05-13] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 [removed] ================================ Services (Whitelisted) ================== 2 avgfws; "C:\Program Files\AVG\AVG2012\avgfws.exe" [2399560 2011-08-19] (AVG Technologies CZ, s.r.o.) 3 AVGIDSAgent; "C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe" [4433248 2011-10-12] (AVG Technologies CZ, s.r.o.) 2 avgwd; "C:\Program Files\AVG\AVG2012\avgwdsvc.exe" [192776 2011-08-02] (AVG Technologies CZ, s.r.o.) 2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [366152 2011-08-31] (Malwarebytes Corporation) 3 Microsoft SharePoint Workspace Audit Service; "C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" /auditservice [31125880 2011-06-12] (Microsoft Corporation) 2 NAUpdate; "C:\Program Files\Nero\Update\NASvc.exe" [490280 2010-03-25] (Nero AG) 2 Realtek11nCU; C:\Program Files\Airlink101\Airlink101 WLAN Monitor\RtlService.exe [36864 2010-04-16] (Realtek) 2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) 3 SwitchBoard; "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [517096 2010-02-19] (Adobe Systems Incorporated) 2 vToolbarUpdater10.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [918880 2012-03-16] () 2 MsMpSvc; "c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe" [x] 3 NisSrv; "c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe" [x] ========================== Drivers (Whitelisted) ============= 3 ASUSU1; C:\Windows\System32\drivers\cm112.sys [1518592 2010-12-14] (C-Media Electronics Inc) 3 AVGIDSDriver; C:\Windows\System32\DRIVERS\AVGIDSDriver.Sys [134736 2011-07-11] (AVG Technologies CZ, s.r.o. ) 0 AVGIDSEH; C:\Windows\System32\DRIVERS\AVGIDSEH.Sys [23120 2011-07-11] (AVG Technologies CZ, s.r.o. ) 3 AVGIDSFilter; C:\Windows\System32\DRIVERS\AVGIDSFilter.Sys [24272 2011-07-11] (AVG Technologies CZ, s.r.o. ) 3 AVGIDSShim; C:\Windows\System32\DRIVERS\AVGIDSShim.Sys [16720 2011-10-04] (AVG Technologies CZ, s.r.o. ) 1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [230608 2011-10-07] (AVG Technologies CZ, s.r.o.) 1 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [40016 2011-08-08] (AVG Technologies CZ, s.r.o.) 0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [32592 2011-09-13] (AVG Technologies CZ, s.r.o.) 1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [295248 2011-07-11] (AVG Technologies CZ, s.r.o.) 3 BridgeMP; C:\Windows\System32\DRIVERS\bridge.sys [78336 2009-07-13] (Microsoft Corporation) 2 cpuz134; \??\C:\Windows\system32\drivers\cpuz134_x32.sys [20328 2010-07-09] (Windows ® Win 7 DDK provider) 0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () 3 HBtnKey; C:\Windows\System32\DRIVERS\cpqbttn.sys [15544 2010-02-24] (Hewlett-Packard Company) 3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH) 3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22216 2011-08-31] (Malwarebytes Corporation) 1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation) 3 MpNWMon; C:\Windows\System32\DRIVERS\MpNWMon.sys [43392 2011-04-18] (Microsoft Corporation) 3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [657408 2009-07-13] (Ralink Technology Corp.) 3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [65024 2011-04-27] (Microsoft Corporation) 3 NVENETFD; C:\Windows\System32\DRIVERS\nvm62x32.sys [347264 2009-07-13] (NVIDIA Corporation) 2 rismxdp; C:\Windows\System32\DRIVERS\rixdptsk.sys [37376 2006-11-14] (REDC) 3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [630304 2010-11-03] (Realtek Semiconductor Corporation ) 0 speedfan; C:\Windows\System32\speedfan.sys [21696 2010-12-18] (Almico Software) 3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL3.SYS [207360 2009-07-13] (Conexant Systems, Inc.) 3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV3.SYS [980992 2009-07-13] (Conexant Systems, Inc.) 3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT3.SYS [661504 2009-07-13] (Conexant Systems, Inc.) 3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam.sys [11520 2008-05-06] (Western Digital Technologies) 3 catchme; \??\C:\Users\Dennis\AppData\Local\Temp\catchme.sys [x] 3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x] 3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x] 3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x] ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-04-06 02:01 - 2012-04-06 02:02 - 0000000 ____D C:\Users\Dennis\AppData\Local\{EFE21AAB-1C56-484F-9E84-84E9948AC435} 2012-04-05 12:03 - 2012-04-05 12:03 - 0000000 ____D C:\Users\Dennis\AppData\Local\{91DD6A37-DD81-4F8A-9ABF-BEEBBDEDA3A7} 2012-04-05 12:03 - 2012-04-05 12:03 - 0000000 ____D C:\Users\Dennis\AppData\Local\{34A8D1E0-4E75-4670-B5F8-4C2761C6FC7E} 2012-04-04 11:41 - 2012-04-04 11:41 - 0000000 ____D C:\Users\Dennis\AppData\Local\{0043A935-CD21-4BAD-BC73-99C5697A5413} 2012-04-03 21:33 - 2012-04-03 21:33 - 0000000 ____D C:\Users\Dennis\AppData\Local\{D560EF46-E63F-4F8F-94F5-077E9F086040} 2012-04-03 21:33 - 2012-04-03 21:33 - 0000000 ____D C:\Users\Dennis\AppData\Local\{1D036B5F-FB0A-4E9D-B1ED-7195EDB7E546} 2012-04-03 09:32 - 2012-04-03 09:33 - 0000000 ____D C:\Users\Dennis\AppData\Local\{56A8EE7B-4D03-4335-AAE3-22F3007670E2} 2012-04-02 14:35 - 2012-04-02 14:36 - 0000270 ____A C:\Users\Dennis\Desktop\hitman reborn guide.rtf 2012-04-02 12:20 - 2012-04-02 12:20 - 0021922 ____A C:\ComboFix.txt 2012-04-02 12:18 - 2012-04-02 12:18 - 0000000 __SHD C:\$RECYCLE.BIN 2012-04-01 20:55 - 2012-04-01 20:55 - 0000027 ____A C:\Windows\System32\Drivers\etc\hosts 2012-04-01 20:42 - 2012-04-02 12:20 - 0000000 ____D C:\Qoobox 2012-04-01 20:42 - 2012-04-01 20:56 - 0000000 ____D C:\Windows\ERDNT 2012-04-01 20:42 - 2011-06-25 22:45 - 0256000 ____A C:\Windows\PEV.exe 2012-04-01 20:42 - 2010-11-07 09:20 - 0208896 ____A C:\Windows\MBR.exe 2012-04-01 20:42 - 2009-04-19 20:56 - 0060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2012-04-01 20:42 - 2000-08-30 16:00 - 0518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2012-04-01 20:42 - 2000-08-30 16:00 - 0406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2012-04-01 20:42 - 2000-08-30 16:00 - 0098816 ____A C:\Windows\sed.exe 2012-04-01 20:42 - 2000-08-30 16:00 - 0080412 ____A C:\Windows\grep.exe 2012-04-01 20:42 - 2000-08-30 16:00 - 0068096 ____A C:\Windows\zip.exe 2012-04-01 20:40 - 2012-04-01 20:39 - 4453008 ____R (Swearware) C:\Users\Dennis\Desktop\ComboFix.exe 2012-04-01 20:38 - 2012-04-01 20:39 - 4453008 ____A (Swearware) C:\Users\Dennis\Downloads\ComboFix.exe 2012-04-01 10:32 - 2012-04-01 12:24 - 0129944 ____A C:\TDSSKiller.2.7.23.0_01.04.2012_11.32.44_log.txt 2012-04-01 10:24 - 2012-04-01 10:25 - 0000000 ____D C:\Users\Dennis\AppData\Local\{2D03D307-9E26-4B61-8B92-E1544CEE62A8} 2012-04-01 10:17 - 2012-04-01 10:17 - 397979524 ____A C:\Windows\MEMORY.DMP 2012-04-01 10:17 - 2012-04-01 10:17 - 0142048 ____A C:\Windows\Minidump\040112-42213-01.dmp 2012-04-01 10:17 - 2012-04-01 10:17 - 0000000 ____D C:\Windows\Minidump 2012-04-01 08:50 - 2012-04-01 08:49 - 4731392 ____A (AVAST Software) C:\Users\Dennis\Desktop\aswMBR.exe 2012-04-01 08:50 - 2012-04-01 08:49 - 2068016 ____A (Kaspersky Lab ZAO) C:\Users\Dennis\Desktop\tdsskiller.exe 2012-04-01 08:49 - 2012-04-01 08:49 - 2068016 ____A (Kaspersky Lab ZAO) C:\Users\Dennis\Downloads\tdsskiller.exe 2012-04-01 08:48 - 2012-04-01 08:49 - 4731392 ____A (AVAST Software) C:\Users\Dennis\Downloads\aswMBR.exe 2012-03-31 12:51 - 2012-03-31 12:51 - 0000000 ____D C:\Program Files\Common Files\Java 2012-03-31 12:50 - 2012-03-31 12:50 - 0157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe 2012-03-31 12:50 - 2012-03-31 12:50 - 0149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe 2012-03-31 12:50 - 2012-03-31 12:50 - 0149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe 2012-03-31 12:50 - 2012-03-31 12:50 - 0000000 ____D C:\Program Files\Java 2012-03-31 12:47 - 2012-03-31 12:47 - 0908576 ____A (Sun Microsystems, Inc.) C:\Users\Dennis\Downloads\chromeinstall-6u31 (2).exe 2012-03-31 09:39 - 2012-03-31 09:39 - 0000000 ____D C:\Users\Dennis\AppData\Local\{A60993B6-3F56-4204-B4D2-03AE51803A6A} 2012-03-30 11:51 - 2012-03-30 11:41 - 0625664 ____A C:\Users\Dennis\Desktop\dds.scr 2012-03-30 11:41 - 2012-03-30 11:41 - 0625664 ____A C:\Users\Dennis\Downloads\dds.scr 2012-03-28 00:15 - 2012-03-28 00:15 - 0000000 ____D C:\Users\Dennis\Downloads\[ITOUEI] PuriPuro (Complete Manga) [English Translated by Tonigobe] (MaxQ) 2012-03-27 22:03 - 2012-03-27 22:05 - 11429701 ____A C:\Users\Dennis\Downloads\skyrimmappdf.zip 2012-03-26 14:51 - 2012-03-26 14:51 - 0000000 ____D C:\Users\Dennis\Downloads\[Saida Kazuaki] Paipain - [Brolen & Makasu] 2012-03-26 14:43 - 2012-03-26 14:43 - 0000000 ____D C:\Users\Dennis\Downloads\[Makinosaka Shinichi] Pure Days (Complete, English) 2012-03-26 14:36 - 2012-03-26 14:36 - 0000000 ____D C:\Users\Dennis\Downloads\[Carn] Dere Nochi Torare (Complete, 1-4 Decsensored) [English] 2012-03-26 14:18 - 2012-03-26 14:18 - 0000162 ___AH C:\Users\Dennis\Desktop\~$melist Organized by hrs.rtf 2012-03-24 21:14 - 2012-03-24 21:22 - 0063495 ____A C:\Users\Dennis\Desktop\Trophy game list.xlsx 2012-03-23 09:31 - 2012-04-04 23:40 - 0067464 ____A C:\Users\Dennis\Desktop\gamelist Organized by hrs.rtf 2012-03-21 21:14 - 2012-03-21 21:15 - 0910112 ____A (Sun Microsystems, Inc.) C:\Users\Dennis\Downloads\chromeinstall-6u31 (1).exe 2012-03-21 21:14 - 2012-03-21 21:14 - 0910112 ____A (Sun Microsystems, Inc.) C:\Users\Dennis\Downloads\chromeinstall-6u31.exe 2012-03-21 08:35 - 2012-03-21 08:35 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Type.90 - Blood Lunch (English) 2012-03-20 17:28 - 2012-03-20 17:28 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Nagare Ippon - Week Point (English) 2012-03-20 11:41 - 2012-04-01 10:25 - 0000000 ____D C:\Program Files\Steam 2012-03-20 11:41 - 2012-03-20 11:50 - 0000000 ____D C:\Program Files\Common Files\Steam 2012-03-20 11:41 - 2012-03-20 11:41 - 0000875 ____A C:\Users\Public\Desktop\Steam.lnk 2012-03-18 15:59 - 2012-03-18 15:59 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Oyster - The Semen Junkie (English) 2012-03-18 15:59 - 2012-03-18 15:59 - 0000000 ____D C:\Users\Dennis\Downloads\[Leopard] Futariyome (Complete) [English] 2012-03-18 15:51 - 2012-03-18 15:51 - 0000000 ____D C:\Users\Dennis\Downloads\[Mitarashi Kousei] Kazoku Donburi [Complete] [English] =Team Vanilla= 2012-03-18 15:47 - 2012-03-18 15:47 - 0000000 ____D C:\Users\Dennis\Downloads\[biribiri] Itou Ei - Anata wo Sutte mo Iidesuka (Complete) 2012-03-18 15:36 - 2012-03-18 15:36 - 0000000 ____D C:\Users\Dennis\Downloads\[desudesu]_Saida_Kazuaki_-_Virgin_Hunt 2012-03-18 15:22 - 2012-03-18 15:22 - 0000000 ____D C:\Users\Dennis\Downloads\[Po-ju] Secret Journey Ch.0-7 Complete (Eng) 2012-03-18 15:13 - 2012-03-18 15:13 - 0000000 ____D C:\Users\Dennis\Downloads\Radical GOGO Baby! [Complete] 2012-03-18 14:54 - 2012-03-18 14:54 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Chunrouzan - Obscene Picture Book (English) 2012-03-18 14:42 - 2012-03-18 14:42 - 0000000 ____D C:\Users\Dennis\Downloads\Oh_Imoto 2012-03-15 16:25 - 2012-03-15 16:25 - 0002074 ____A C:\Users\Public\Desktop\AirLink101 Wireless Monitor.lnk 2012-03-15 16:25 - 2012-03-15 16:25 - 0000000 ____D C:\Program Files\Cisco 2012-03-15 16:24 - 2010-11-03 02:49 - 0630304 ___RA (Realtek Semiconductor Corporation ) C:\Windows\System32\Drivers\rtl8192cu.sys 2012-03-15 16:23 - 2012-03-15 16:23 - 0000000 ____D C:\Program Files\Airlink101 2012-03-15 16:23 - 2009-04-02 09:27 - 0188416 ____A (Realtek Semiconductor Corp. ) C:\Windows\System32\RTLExtUI.dll 2012-03-15 16:23 - 2009-03-31 13:31 - 0380928 ____A (Realtek) C:\Windows\RtlUI2.exe 2012-03-15 16:23 - 2009-02-05 01:49 - 0451072 ____A C:\Windows\System32\ISSRemoveSP.exe 2012-03-15 16:23 - 2009-01-05 19:31 - 0000901 ____A C:\Windows\RtlUI2.exe.manifest 2012-03-15 16:23 - 2008-07-01 11:31 - 0614400 ____A (Realtek Semiconductor Corp. ) C:\Windows\System32\Rtlihvs.dll 2012-03-14 11:32 - 2012-03-14 11:32 - 0000000 ____D C:\Users\Dennis\Downloads\[Takaoka Motofumi] F-Mode (Complete) [ENG] 2012-03-14 11:18 - 2012-03-14 11:18 - 0000000 ____D C:\Users\Dennis\Downloads\[biribiri]_[Rakko]_Pura-Tina_Plus_[Complete] 2012-03-14 11:12 - 2012-03-14 11:12 - 0000000 ____D C:\Users\Dennis\Downloads\[Minakonami] Futanari Ijirikko (English) 2012-03-14 11:04 - 2012-03-14 11:04 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Hindenburg - I'm Being Impregnated! (English) 2012-03-14 10:57 - 2012-03-14 10:57 - 0000000 ____D C:\Users\Dennis\Downloads\[Kiya Shii] Docchi mo LOVE! (Complete) [English][Decensored] 2012-03-13 11:07 - 2011-11-19 06:50 - 3968368 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2012-03-13 11:07 - 2011-11-19 06:50 - 3913584 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-03-13 11:06 - 2012-02-09 21:38 - 1077248 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2012-03-13 11:06 - 2012-02-02 19:54 - 2343424 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-03-13 11:04 - 2012-02-16 21:34 - 0919040 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll 2012-03-13 11:04 - 2012-02-16 21:34 - 0826880 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll 2012-03-13 11:04 - 2012-02-16 20:14 - 0183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-03-13 11:04 - 2012-02-16 20:13 - 0024576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys 2012-03-13 11:04 - 2012-01-24 21:32 - 0129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-03-13 11:04 - 2012-01-24 21:32 - 0058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-03-13 11:04 - 2012-01-24 21:27 - 0008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe 2012-03-09 20:58 - 2012-03-09 20:59 - 0000000 ____D C:\Users\Dennis\Downloads\[Takaoka Motofumi] Rutsubo (Complete) [ENG] 2012-03-09 20:58 - 2012-03-09 20:58 - 0000000 ____D C:\Users\Dennis\Downloads\[DP] Poko To Wonderful (Complete) [Uncensored][Eng] 2012-03-09 20:48 - 2012-03-09 20:48 - 0000000 ____D C:\Users\Dennis\Downloads\Uziga Waita - Death Face 2012-03-09 20:42 - 2012-03-09 20:42 - 0000000 ____D C:\Users\Dennis\Downloads\Innocence 2012-03-09 18:40 - 2012-03-09 18:40 - 0000000 ____D C:\Users\Dennis\AppData\Local\Yahoo 2012-03-09 18:39 - 2012-03-09 18:39 - 0000000 ____D C:\Users\Dennis\AppData\Roaming\Yahoo! 2012-03-07 21:11 - 2012-03-07 21:11 - 0000000 ____D C:\Users\Dennis\Downloads\Takashiro_Go-ya_-_Nyoudou__LWB_ 2012-03-07 21:06 - 2012-03-07 21:06 - 0000000 ____D C:\Users\Dennis\Downloads\Type90_-_Oh_Miss_Nanase_Complete 2012-03-07 21:04 - 2012-03-07 21:04 - 0000000 ____D C:\Users\Dennis\Downloads\Horny_Apartment 2012-03-07 20:11 - 2012-04-05 20:45 - 0002403 ____A C:\Users\Dennis\Desktop\Google Chrome.lnk ============ 3 Months Modified Files and Folders =============== 2012-04-06 15:11 - 2012-04-06 15:10 - 0000000 ____D C:\FRST 2012-04-06 14:05 - 2011-11-19 21:48 - 0000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-965785594-764187485-2921294778-1000UA.job 2012-04-06 14:04 - 2006-01-01 00:20 - 1827104 ____A C:\Windows\WindowsUpdate.log 2012-04-06 14:03 - 2011-04-18 16:17 - 0729688 ____A C:\Windows\System32\PerfStringBackup.INI 2012-04-06 14:02 - 2012-02-20 11:25 - 0086356 ____A C:\Users\Dennis\Desktop\Daily Journal.docx 2012-04-06 14:01 - 2009-07-13 20:34 - 0017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-04-06 14:01 - 2009-07-13 20:34 - 0017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-04-06 10:26 - 2011-05-02 08:08 - 0000000 ____D C:\Windows\System32\Drivers\AVG 2012-04-06 10:26 - 2011-05-02 07:39 - 0000000 ____D C:\Users\All Users\MFAData 2012-04-06 10:26 - 2011-05-02 07:39 - 0000000 ____D C:\ProgramData\MFAData 2012-04-06 02:12 - 2011-11-19 21:48 - 0000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-965785594-764187485-2921294778-1000Core.job 2012-04-06 02:02 - 2012-04-06 02:01 - 0000000 ____D C:\Users\Dennis\AppData\Local\{EFE21AAB-1C56-484F-9E84-84E9948AC435} 2012-04-05 20:45 - 2012-03-07 20:11 - 0002403 ____A C:\Users\Dennis\Desktop\Google Chrome.lnk 2012-04-05 12:03 - 2012-04-05 12:03 - 0000000 ____D C:\Users\Dennis\AppData\Local\{91DD6A37-DD81-4F8A-9ABF-BEEBBDEDA3A7} 2012-04-05 12:03 - 2012-04-05 12:03 - 0000000 ____D C:\Users\Dennis\AppData\Local\{34A8D1E0-4E75-4670-B5F8-4C2761C6FC7E} 2012-04-05 12:02 - 2011-04-19 15:35 - 0000000 ____D C:\Users\Dennis\Tracing 2012-04-05 12:00 - 2011-05-02 14:09 - 0000000 ____D C:\Users\Dennis\Desktop\Anime 2012-04-04 23:40 - 2012-03-23 09:31 - 0067464 ____A C:\Users\Dennis\Desktop\gamelist Organized by hrs.rtf 2012-04-04 11:48 - 2011-05-21 13:07 - 0000000 ____D C:\Config.Msi 2012-04-04 11:41 - 2012-04-04 11:41 - 0000000 ____D C:\Users\Dennis\AppData\Local\{0043A935-CD21-4BAD-BC73-99C5697A5413} 2012-04-03 21:33 - 2012-04-03 21:33 - 0000000 ____D C:\Users\Dennis\AppData\Local\{D560EF46-E63F-4F8F-94F5-077E9F086040} 2012-04-03 21:33 - 2012-04-03 21:33 - 0000000 ____D C:\Users\Dennis\AppData\Local\{1D036B5F-FB0A-4E9D-B1ED-7195EDB7E546} 2012-04-03 21:33 - 2011-04-18 19:39 - 0000000 ____D C:\Users\Dennis\AppData\Local\Windows Live 2012-04-03 09:33 - 2012-04-03 09:32 - 0000000 ____D C:\Users\Dennis\AppData\Local\{56A8EE7B-4D03-4335-AAE3-22F3007670E2} 2012-04-02 14:36 - 2012-04-02 14:35 - 0000270 ____A C:\Users\Dennis\Desktop\hitman reborn guide.rtf 2012-04-02 12:56 - 2012-02-03 12:22 - 0000000 ____D C:\Program Files\SpeedFan 2012-04-02 12:20 - 2012-04-02 12:20 - 0021922 ____A C:\ComboFix.txt 2012-04-02 12:20 - 2012-04-01 20:42 - 0000000 ____D C:\Qoobox 2012-04-02 12:18 - 2012-04-02 12:18 - 0000000 __SHD C:\$RECYCLE.BIN 2012-04-02 12:17 - 2009-07-13 18:04 - 0000215 ____A C:\Windows\system.ini 2012-04-01 20:58 - 2009-07-13 18:37 - 0000000 __RHD C:\users\Default 2012-04-01 20:58 - 2009-07-13 18:37 - 0000000 ___RD C:\users\Public 2012-04-01 20:56 - 2012-04-01 20:42 - 0000000 ____D C:\Windows\ERDNT 2012-04-01 20:55 - 2012-04-01 20:55 - 0000027 ____A C:\Windows\System32\Drivers\etc\hosts 2012-04-01 20:39 - 2012-04-01 20:40 - 4453008 ____R (Swearware) C:\Users\Dennis\Desktop\ComboFix.exe 2012-04-01 20:39 - 2012-04-01 20:38 - 4453008 ____A (Swearware) C:\Users\Dennis\Downloads\ComboFix.exe 2012-04-01 12:24 - 2012-04-01 10:32 - 0129944 ____A C:\TDSSKiller.2.7.23.0_01.04.2012_11.32.44_log.txt 2012-04-01 10:25 - 2012-04-01 10:24 - 0000000 ____D C:\Users\Dennis\AppData\Local\{2D03D307-9E26-4B61-8B92-E1544CEE62A8} 2012-04-01 10:25 - 2012-03-20 11:41 - 0000000 ____D C:\Program Files\Steam 2012-04-01 10:25 - 2011-05-23 13:38 - 0000000 ____D C:\Users\Dennis\AppData\Roaming\uTorrent 2012-04-01 10:24 - 2011-12-28 13:49 - 0000000 ____D C:\Users\Dennis\AppData\Roaming\Mal Updater 2012-04-01 10:17 - 2012-04-01 10:17 - 397979524 ____A C:\Windows\MEMORY.DMP 2012-04-01 10:17 - 2012-04-01 10:17 - 0142048 ____A C:\Windows\Minidump\040112-42213-01.dmp 2012-04-01 10:17 - 2012-04-01 10:17 - 0000000 ____D C:\Windows\Minidump 2012-04-01 10:17 - 2009-07-13 20:53 - 0000006 ___AH C:\Windows\Tasks\SA.DAT 2012-04-01 10:17 - 2009-07-13 20:39 - 0025364 ____A C:\Windows\setupact.log 2012-04-01 10:17 - 2006-01-01 00:17 - 1559187456 __ASH C:\hiberfil.sys 2012-04-01 08:52 - 2011-12-18 02:34 - 0000000 ____D C:\Users\Dennis\Documents\Ellen 2012-04-01 08:49 - 2012-04-01 08:50 - 4731392 ____A (AVAST Software) C:\Users\Dennis\Desktop\aswMBR.exe 2012-04-01 08:49 - 2012-04-01 08:50 - 2068016 ____A (Kaspersky Lab ZAO) C:\Users\Dennis\Desktop\tdsskiller.exe 2012-04-01 08:49 - 2012-04-01 08:49 - 2068016 ____A (Kaspersky Lab ZAO) C:\Users\Dennis\Downloads\tdsskiller.exe 2012-04-01 08:49 - 2012-04-01 08:48 - 4731392 ____A (AVAST Software) C:\Users\Dennis\Downloads\aswMBR.exe 2012-03-31 12:51 - 2012-03-31 12:51 - 0000000 ____D C:\Program Files\Common Files\Java 2012-03-31 12:50 - 2012-03-31 12:50 - 0157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe 2012-03-31 12:50 - 2012-03-31 12:50 - 0149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe 2012-03-31 12:50 - 2012-03-31 12:50 - 0149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe 2012-03-31 12:50 - 2012-03-31 12:50 - 0000000 ____D C:\Program Files\Java 2012-03-31 12:50 - 2011-04-18 18:50 - 0472808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll 2012-03-31 12:47 - 2012-03-31 12:47 - 0908576 ____A (Sun Microsystems, Inc.) C:\Users\Dennis\Downloads\chromeinstall-6u31 (2).exe 2012-03-31 09:39 - 2012-03-31 09:39 - 0000000 ____D C:\Users\Dennis\AppData\Local\{A60993B6-3F56-4204-B4D2-03AE51803A6A} 2012-03-30 11:41 - 2012-03-30 11:51 - 0625664 ____A C:\Users\Dennis\Desktop\dds.scr 2012-03-30 11:41 - 2012-03-30 11:41 - 0625664 ____A C:\Users\Dennis\Downloads\dds.scr 2012-03-28 00:24 - 2011-04-20 20:16 - 0000000 ____D C:\Users\All Users\boost_interprocess 2012-03-28 00:24 - 2011-04-20 20:16 - 0000000 ____D C:\ProgramData\boost_interprocess 2012-03-28 00:22 - 2011-04-18 17:30 - 0000000 ____D C:\Users\Dennis\AppData\Roaming\TigerPlayer 2012-03-28 00:15 - 2012-03-28 00:15 - 0000000 ____D C:\Users\Dennis\Downloads\[ITOUEI] PuriPuro (Complete Manga) [English Translated by Tonigobe] (MaxQ) 2012-03-27 22:05 - 2012-03-27 22:03 - 11429701 ____A C:\Users\Dennis\Downloads\skyrimmappdf.zip 2012-03-26 14:51 - 2012-03-26 14:51 - 0000000 ____D C:\Users\Dennis\Downloads\[Saida Kazuaki] Paipain - [Brolen & Makasu] 2012-03-26 14:43 - 2012-03-26 14:43 - 0000000 ____D C:\Users\Dennis\Downloads\[Makinosaka Shinichi] Pure Days (Complete, English) 2012-03-26 14:36 - 2012-03-26 14:36 - 0000000 ____D C:\Users\Dennis\Downloads\[Carn] Dere Nochi Torare (Complete, 1-4 Decsensored) [English] 2012-03-26 14:18 - 2012-03-26 14:18 - 0000162 ___AH C:\Users\Dennis\Desktop\~$melist Organized by hrs.rtf 2012-03-24 21:22 - 2012-03-24 21:14 - 0063495 ____A C:\Users\Dennis\Desktop\Trophy game list.xlsx 2012-03-22 23:44 - 2012-03-03 23:33 - 0000000 ____D C:\Users\Dennis\Downloads\[MIKOSHIRO Nagitoh] Saint Margareta Academy [ENG] 2012-03-21 21:15 - 2012-03-21 21:14 - 0910112 ____A (Sun Microsystems, Inc.) C:\Users\Dennis\Downloads\chromeinstall-6u31 (1).exe 2012-03-21 21:14 - 2012-03-21 21:14 - 0910112 ____A (Sun Microsystems, Inc.) C:\Users\Dennis\Downloads\chromeinstall-6u31.exe 2012-03-21 08:35 - 2012-03-21 08:35 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Type.90 - Blood Lunch (English) 2012-03-20 17:28 - 2012-03-20 17:28 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Nagare Ippon - Week Point (English) 2012-03-20 11:50 - 2012-03-20 11:41 - 0000000 ____D C:\Program Files\Common Files\Steam 2012-03-20 11:41 - 2012-03-20 11:41 - 0000875 ____A C:\Users\Public\Desktop\Steam.lnk 2012-03-20 11:41 - 2011-04-18 16:23 - 0000000 ____D C:\users\Dennis 2012-03-18 15:59 - 2012-03-18 15:59 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Oyster - The Semen Junkie (English) 2012-03-18 15:59 - 2012-03-18 15:59 - 0000000 ____D C:\Users\Dennis\Downloads\[Leopard] Futariyome (Complete) [English] 2012-03-18 15:51 - 2012-03-18 15:51 - 0000000 ____D C:\Users\Dennis\Downloads\[Mitarashi Kousei] Kazoku Donburi [Complete] [English] =Team Vanilla= 2012-03-18 15:47 - 2012-03-18 15:47 - 0000000 ____D C:\Users\Dennis\Downloads\[biribiri] Itou Ei - Anata wo Sutte mo Iidesuka (Complete) 2012-03-18 15:36 - 2012-03-18 15:36 - 0000000 ____D C:\Users\Dennis\Downloads\[desudesu]_Saida_Kazuaki_-_Virgin_Hunt 2012-03-18 15:22 - 2012-03-18 15:22 - 0000000 ____D C:\Users\Dennis\Downloads\[Po-ju] Secret Journey Ch.0-7 Complete (Eng) 2012-03-18 15:13 - 2012-03-18 15:13 - 0000000 ____D C:\Users\Dennis\Downloads\Radical GOGO Baby! [Complete] 2012-03-18 14:54 - 2012-03-18 14:54 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Chunrouzan - Obscene Picture Book (English) 2012-03-18 14:42 - 2012-03-18 14:42 - 0000000 ____D C:\Users\Dennis\Downloads\Oh_Imoto 2012-03-16 11:57 - 2011-12-23 17:00 - 0000000 ____D C:\Users\All Users\AVG Secure Search 2012-03-16 11:57 - 2011-12-23 17:00 - 0000000 ____D C:\ProgramData\AVG Secure Search 2012-03-16 11:57 - 2011-09-29 19:11 - 0000000 ____D C:\Program Files\AVG Secure Search 2012-03-15 16:25 - 2012-03-15 16:25 - 0002074 ____A C:\Users\Public\Desktop\AirLink101 Wireless Monitor.lnk 2012-03-15 16:25 - 2012-03-15 16:25 - 0000000 ____D C:\Program Files\Cisco 2012-03-15 16:24 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\DriverStore 2012-03-15 16:23 - 2012-03-15 16:23 - 0000000 ____D C:\Program Files\Airlink101 2012-03-15 16:23 - 2011-04-18 18:26 - 0000000 ___HD C:\Program Files\InstallShield Installation Information 2012-03-14 11:32 - 2012-03-14 11:32 - 0000000 ____D C:\Users\Dennis\Downloads\[Takaoka Motofumi] F-Mode (Complete) [ENG] 2012-03-14 11:18 - 2012-03-14 11:18 - 0000000 ____D C:\Users\Dennis\Downloads\[biribiri]_[Rakko]_Pura-Tina_Plus_[Complete] 2012-03-14 11:12 - 2012-03-14 11:12 - 0000000 ____D C:\Users\Dennis\Downloads\[Minakonami] Futanari Ijirikko (English) 2012-03-14 11:04 - 2012-03-14 11:04 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Hindenburg - I'm Being Impregnated! (English) 2012-03-14 10:57 - 2012-03-14 10:57 - 0000000 ____D C:\Users\Dennis\Downloads\[Kiya Shii] Docchi mo LOVE! (Complete) [English][Decensored] 2012-03-13 13:14 - 2009-07-13 20:33 - 3764584 ____A C:\Windows\System32\FNTCACHE.DAT 2012-03-13 11:38 - 2011-04-18 20:06 - 54215544 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-03-13 11:36 - 2011-10-02 12:16 - 0000000 ____D C:\Users\All Users\Microsoft Help 2012-03-13 11:36 - 2011-10-02 12:16 - 0000000 ____D C:\ProgramData\Microsoft Help 2012-03-13 10:23 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\Microsoft.NET 2012-03-13 10:05 - 2012-03-03 22:29 - 0000000 ____D C:\Users\Dennis\Downloads\[Manga torrents] 2012-03-09 20:59 - 2012-03-09 20:58 - 0000000 ____D C:\Users\Dennis\Downloads\[Takaoka Motofumi] Rutsubo (Complete) [ENG] 2012-03-09 20:58 - 2012-03-09 20:58 - 0000000 ____D C:\Users\Dennis\Downloads\[DP] Poko To Wonderful (Complete) [Uncensored][Eng] 2012-03-09 20:48 - 2012-03-09 20:48 - 0000000 ____D C:\Users\Dennis\Downloads\Uziga Waita - Death Face 2012-03-09 20:42 - 2012-03-09 20:42 - 0000000 ____D C:\Users\Dennis\Downloads\Innocence 2012-03-09 18:40 - 2012-03-09 18:40 - 0000000 ____D C:\Users\Dennis\AppData\Local\Yahoo 2012-03-09 18:39 - 2012-03-09 18:39 - 0000000 ____D C:\Users\Dennis\AppData\Roaming\Yahoo! 2012-03-09 15:09 - 2011-12-01 14:11 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2012-03-07 21:11 - 2012-03-07 21:11 - 0000000 ____D C:\Users\Dennis\Downloads\Takashiro_Go-ya_-_Nyoudou__LWB_ 2012-03-07 21:06 - 2012-03-07 21:06 - 0000000 ____D C:\Users\Dennis\Downloads\Type90_-_Oh_Miss_Nanase_Complete 2012-03-07 21:04 - 2012-03-07 21:04 - 0000000 ____D C:\Users\Dennis\Downloads\Horny_Apartment 2012-03-07 20:09 - 2012-03-05 01:17 - 0000000 ____D C:\Users\Dennis\Downloads\Purimu no Nikki 2012-03-07 11:36 - 2012-02-20 11:25 - 0028733 ____H C:\Users\Dennis\Desktop\~WRL3150.tmp 2012-03-06 04:23 - 2012-03-05 01:17 - 0000000 ____D C:\Users\Dennis\Downloads\Petit-roid 3 2012-03-06 04:02 - 2012-03-06 01:10 - 0000000 ____D C:\Users\Dennis\Downloads\Parabellum 2012-03-06 03:48 - 2012-03-05 01:17 - 0000000 ____D C:\Users\Dennis\Downloads\Ken Yori Tsuyoshi 2012-03-06 03:25 - 2012-03-05 01:17 - 0000000 ____D C:\Users\Dennis\Downloads\Island 2012-03-06 01:07 - 2012-03-06 01:07 - 0000000 ____D C:\Users\Dennis\Downloads\[SubDESU-H] Deep Voice 2012-03-05 03:35 - 2012-03-05 03:35 - 0000000 ____D C:\Users\Dennis\Downloads\[SaHa] Hindenburg - Sibling Love (English) 2012-03-05 03:27 - 2012-03-05 03:27 - 0000000 ____D C:\Users\Dennis\Downloads\SANBUN_Kyouden_-_10_After 2012-03-05 03:21 - 2012-03-05 03:21 - 0000000 ____D C:\Users\Dennis\Downloads\[Akihiko] An Bawdy Paradise (Complete) [ENG] [Yoroshii] 2012-03-05 02:51 - 2012-03-05 02:51 - 0000000 ____D C:\Users\Dennis\Downloads\Kairakuten-nene 2012-03-05 02:49 - 2012-03-05 02:49 - 0000000 ____D C:\Users\Dennis\Downloads\Shell 2012-03-05 02:44 - 2012-03-04 00:02 - 0000000 ____D C:\Users\Dennis\Downloads\Pink Panzer 2012-03-05 02:43 - 2012-03-04 18:17 - 0000000 ____D C:\Users\Dennis\Downloads\Nosewasure 2012-03-04 16:07 - 2012-03-03 16:08 - 0000000 ____D C:\Users\Dennis\Downloads\Wa ga niku ni muretsudoi, kurae 2012-03-03 23:23 - 2012-03-03 16:39 - 0000000 ____D C:\Users\Dennis\Downloads\Yume Mitaina Hoshi Mitaina 2012-03-03 23:08 - 2012-03-03 16:08 - 0000000 ____D C:\Users\Dennis\Downloads\Kannazuki no Shimai 2012-03-03 22:33 - 2012-03-03 16:13 - 0000000 ____D C:\Users\Dennis\Downloads\H na 2012-03-03 16:11 - 2011-05-23 13:38 - 0740216 ____A (BitTorrent, Inc.) C:\Users\Dennis\Desktop\utorrent.exe 2012-03-03 16:10 - 2012-03-03 16:09 - 0000000 ____D C:\Users\Dennis\Downloads\Concerto_[EROBEAT] 2012-03-03 16:08 - 2012-03-03 16:06 - 0000000 ____D C:\Users\Dennis\Downloads\[loli Manga] 2012-02-28 05:15 - 2012-02-28 05:15 - 0000000 ____D C:\Users\Dennis\AppData\Local\{136BB913-FB31-4E25-8059-CE9E452B5FB3} 2012-02-27 12:37 - 2012-02-27 12:37 - 0000000 ____D C:\Users\Dennis\AppData\Local\{D6A9C9DE-F523-4EC4-AE2B-B423B3FA1033} 2012-02-26 23:58 - 2012-02-26 23:58 - 0000000 ____D C:\Users\Dennis\AppData\Local\{A5ECE4F0-9E72-43B2-AB6B-F98E736DB745} 2012-02-26 11:58 - 2012-02-26 11:58 - 0000000 ____D C:\Users\Dennis\AppData\Local\{48FB0A49-A341-440F-8662-724A1D1171D0} 2012-02-26 11:58 - 2012-02-26 11:57 - 0000000 ____D C:\Users\Dennis\AppData\Local\{26059781-BD22-48B9-AA24-363A36B97FB0} 2012-02-26 08:24 - 2012-02-26 08:24 - 0000000 ____D C:\Users\Dennis\AppData\Local\{E29A9BD0-072E-4624-A8C3-9CE6E252ABD7} 2012-02-25 18:49 - 2012-02-25 18:49 - 0000000 ____D C:\Users\Dennis\AppData\Local\{2E662F45-47E1-4931-AB73-8D956CC78288} 2012-02-25 18:49 - 2012-02-25 18:46 - 0000000 ____D C:\Users\Dennis\AppData\Local\{3FB7BA93-6B17-4D16-8031-0428530E9880} 2012-02-25 11:26 - 2012-02-25 11:26 - 0000000 ____D C:\Users\Dennis\AppData\Local\{A47E9944-6D53-49F9-AEC6-36450FA6D208} 2012-02-24 15:13 - 2012-02-24 15:13 - 0000000 ____D C:\Users\Dennis\AppData\Local\{1D2A2283-6966-4D58-9C55-E8AC3C4DD71C} 2012-02-23 20:23 - 2012-02-23 20:23 - 0000000 ____D C:\Users\Dennis\AppData\Local\{529C1761-79DE-46D1-B033-9F8328D85238} 2012-02-23 03:26 - 2012-02-23 03:26 - 0000000 ____D C:\Users\Dennis\AppData\Local\{5A4E3016-088B-4290-8784-9C755A541E86} 2012-02-23 03:25 - 2012-02-23 03:25 - 0000000 ____D C:\Users\Dennis\AppData\Local\{31A2E9BE-B4F5-4402-95E7-DDB95566AF66} 2012-02-21 13:30 - 2012-02-21 13:30 - 0000000 ____D C:\Users\Dennis\AppData\Local\{CDA89FCC-5D2F-4B85-B022-D73490CBF31E} 2012-02-21 00:20 - 2012-02-21 00:19 - 0000000 ____D C:\Users\Dennis\AppData\Local\{A308D979-162A-457C-AF38-EA0D062FB544} 2012-02-21 00:19 - 2012-02-21 00:19 - 0000000 ____D C:\Users\Dennis\AppData\Local\{8D034DD3-2F13-4336-BD6F-87AFF0D5312F} 2012-02-20 12:34 - 2012-02-20 12:34 - 0000162 ___AH C:\Users\Dennis\Desktop\~$ily Journal.docx 2012-02-20 11:16 - 2012-02-20 11:16 - 0000000 ____D C:\Users\Dennis\AppData\Local\{806F2023-871F-4492-A4FC-873D5EF0D251} 2012-02-20 11:16 - 2012-02-20 11:15 - 0000000 ____D C:\Users\Dennis\AppData\Local\{EE3B7A21-C420-41DA-94EF-17BC80F082CC} 2012-02-19 23:14 - 2012-02-19 23:13 - 0000000 ____D C:\Users\Dennis\AppData\Local\{5DBDDBD2-BD7F-476F-A19D-734DA3AAEBB9} 2012-02-19 23:13 - 2012-02-19 23:12 - 0000000 ____D C:\Users\Dennis\AppData\Local\{A8DFFBCA-6B33-4075-8FEE-406A3B26BFC2} 2012-02-19 11:05 - 2012-02-19 11:05 - 0000000 ____D C:\Users\Dennis\AppData\Local\{BE1FE7FE-0D15-457E-A749-12C6A9BB7A07} 2012-02-19 11:05 - 2012-02-18 16:06 - 0000000 ____D C:\Users\Dennis\AppData\Local\{09DBEFD3-8988-479A-B55F-6D826B3D7CDF} 2012-02-18 16:07 - 2012-02-18 16:07 - 0000000 ____D C:\Users\Dennis\AppData\Local\{F8686700-4DB8-4737-BE48-A948B0AC7025} 2012-02-18 02:32 - 2012-02-18 02:32 - 0000000 ____D C:\Users\Dennis\AppData\Local\{DBE554D8-4AC8-46D8-BF4A-0ED6CBCFC0A7} 2012-02-17 10:07 - 2012-02-17 10:07 - 0000000 ____D C:\Users\Dennis\AppData\Local\{E5755A60-4247-4AD7-889A-5362D463C303} 2012-02-16 21:34 - 2012-03-13 11:04 - 0919040 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll 2012-02-16 21:34 - 2012-03-13 11:04 - 0826880 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll 2012-02-16 20:14 - 2012-03-13 11:04 - 0183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-02-16 20:13 - 2012-03-13 11:04 - 0024576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys 2012-02-16 18:35 - 2012-02-16 18:35 - 0000000 ____D C:\Users\Dennis\AppData\Local\{E50344ED-FC2C-449B-AAF4-C7858404B06F} 2012-02-16 18:35 - 2012-02-16 18:35 - 0000000 ____D C:\Users\Dennis\AppData\Local\{7B368DCE-E3F8-4C60-851A-0535C10DEB4A} 2012-02-16 14:03 - 2012-02-16 13:59 - 14839088 ____A (Microsoft Corporation) C:\Users\Dennis\Desktop\windows-kb890830-v4.5.exe 2012-02-16 06:57 - 2012-02-16 06:57 - 0000000 ____D C:\Users\Dennis\AppData\Local\{5C070A7B-8453-4EAC-A005-9E2A73319FCF} 2012-02-15 14:10 - 2011-04-18 16:23 - 0000174 ___SH C:\Users\Dennis\Start Menu\Programs\Startup\desktop.ini 2012-02-15 14:10 - 2011-04-18 16:23 - 0000174 ___SH C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini 2012-02-15 14:07 - 2011-04-18 19:55 - 0000000 ____D C:\Program Files\Microsoft Silverlight 2012-02-15 13:27 - 2012-02-15 13:27 - 0000000 ____D C:\Users\Dennis\AppData\Local\{D85DD5DF-2FB2-459A-B2F8-1B873FB66AA3} 2012-02-15 13:26 - 2012-02-15 13:26 - 0000000 ____D C:\Users\Dennis\AppData\Local\{B8C2CCBE-7E60-4E86-9308-F2A8F62C2561} 2012-02-14 10:34 - 2012-02-14 10:34 - 0000000 ____D C:\Users\Dennis\AppData\Local\{97D77386-A6B4-4774-B877-A8CA013C5282} 2012-02-13 17:05 - 2012-02-13 16:55 - 92130275 ____A C:\Users\Dennis\Downloads\HD680-1202.zip 2012-02-13 16:55 - 2012-02-13 16:55 - 3798975 ____A C:\Users\Dennis\Downloads\HD680.pdf 2012-02-13 14:44 - 2012-02-13 14:44 - 0000000 ____D C:\Users\Dennis\AppData\Local\{ADFF410C-6DD1-4ED6-8020-FCB01103E51C} 2012-02-13 14:44 - 2012-02-10 17:08 - 0000000 ____D C:\Users\Dennis\AppData\Local\{4999B649-3B5D-47E0-A688-116A9FABA586} 2012-02-12 10:08 - 2012-02-12 10:08 - 0000000 ____D C:\Users\Dennis\AppData\Local\{28BDC1CC-4118-4154-830B-246428CC11C6} 2012-02-10 17:09 - 2012-02-10 17:09 - 0000000 ____D C:\Users\Dennis\AppData\Local\{3E4E1844-0F9A-4651-9553-E4208DD06958} 2012-02-10 17:05 - 2011-04-18 20:13 - 0052424 ____A C:\Windows\PFRO.log 2012-02-10 08:23 - 2012-02-10 08:23 - 0000000 ____D C:\Users\Dennis\AppData\Local\{79692020-766D-40A3-9ECB-B0FF99916407} 2012-02-10 00:19 - 2012-02-10 00:19 - 0028949 ____A C:\Users\Dennis\Downloads\zelda_288x288.jpg 2012-02-10 00:18 - 2012-02-10 00:18 - 0062650 ____A C:\Users\Dennis\Documents\Skyward-Sword.jpg 2012-02-10 00:17 - 2012-02-10 00:17 - 0556153 ____A C:\Users\Dennis\Downloads\zep_juto_pose_type_a_02.jpg 2012-02-09 21:38 - 2012-03-13 11:06 - 1077248 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2012-02-09 17:43 - 2012-02-09 17:42 - 0000000 ____D C:\Users\Dennis\AppData\Local\{6936E0CB-9BCF-4A82-B7D0-2DFEA4E3C213} 2012-02-09 17:42 - 2012-02-09 17:42 - 0000000 ____D C:\Users\Dennis\AppData\Local\{D6D4F291-22ED-48FB-B0D4-9F11708A2F0D} 2012-02-08 00:03 - 2012-02-08 00:03 - 0000000 ____D C:\Users\Dennis\AppData\Local\{CEE64FA9-DB2B-4576-BCD1-EFDBB7B4CFAA} 2012-02-07 17:34 - 2012-02-07 17:34 - 0000000 ____D C:\Users\Dennis\Downloads\_H-Manga.info__Boy_s_Empire 2012-02-07 17:24 - 2012-02-07 17:19 - 47096002 ____A C:\Users\Dennis\Downloads\_H-Manga.info__Boy_s_Empire.rar 2012-02-07 15:51 - 2012-02-07 15:51 - 0001194 ____A C:\Users\Dennis\Desktop\Any Video Converter.lnk 2012-02-07 15:51 - 2012-02-07 15:51 - 0000000 ____D C:\Users\Dennis\Documents\Any Video Converter 2012-02-07 15:51 - 2012-02-07 15:51 - 0000000 ____D C:\Users\Dennis\AppData\Roaming\AnvSoft 2012-02-07 15:50 - 2012-02-07 15:50 - 0000000 ____D C:\Program Files\AnvSoft 2012-02-07 15:49 - 2012-02-07 15:46 - 23819960 ____A (Any-Video-Converter.com ) C:\Users\Dennis\Downloads\avc-free.exe 2012-02-07 07:14 - 2012-02-07 07:14 - 0000000 ____D C:\Users\Dennis\AppData\Local\{4B47AA02-C613-49EE-A32D-1B4C52B6D7D5} 2012-02-06 00:42 - 2012-02-06 00:42 - 0000000 ____D C:\Users\Dennis\AppData\Local\{8527FE4B-2D97-4433-97D5-B674400561D6} 2012-02-05 09:20 - 2012-02-05 09:20 - 0000000 ____D C:\Users\Dennis\AppData\Local\{87A4883F-EF95-472E-A1B4-6E4C0E01EE3A} 2012-02-05 09:19 - 2012-02-05 09:19 - 0000000 ____D C:\Users\Dennis\AppData\Local\{D07D6E22-7491-44BF-B1C8-FBF9CB55C04F} 2012-02-04 20:02 - 2012-02-04 20:02 - 0000000 ____D C:\Users\Dennis\AppData\Local\{8E13DF8C-01BB-4BB4-BDF7-8B3EFBF7FC4F} 2012-02-04 20:01 - 2012-02-04 20:01 - 0000000 ____D C:\Users\Dennis\AppData\Local\{CED3437A-CD72-4FED-9F23-071CE3D0C9BB} 2012-02-04 08:01 - 2012-02-04 08:01 - 0000000 ____D C:\Users\Dennis\AppData\Local\{9B87A7BB-09E2-44B7-A1E1-B49F363D87C7} 2012-02-03 15:48 - 2012-02-03 15:48 - 0000000 ____D C:\Users\Dennis\AppData\Local\{067F232E-C4EF-46BD-A7AF-F6A5A9A5A519} 2012-02-03 12:22 - 2012-02-03 12:22 - 0000965 ____A C:\Users\Dennis\Desktop\SpeedFan.lnk 2012-02-03 12:22 - 2012-02-03 12:22 - 0000045 ____A C:\Windows\System32\initdebug.nfo 2012-02-03 03:09 - 2012-02-03 03:09 - 0000000 ____D C:\Users\Dennis\AppData\Local\{E0B06CB0-78ED-4CF6-857E-735BBA21F7C8} 2012-02-03 03:09 - 2012-02-03 03:08 - 0000000 ____D C:\Users\Dennis\AppData\Local\{1EFC1793-F286-4800-8D4E-4F711244084F} 2012-02-02 19:54 - 2012-03-13 11:06 - 2343424 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-02-02 15:08 - 2012-02-02 15:08 - 0000000 ____D C:\Users\Dennis\AppData\Local\{79EA98A1-821A-4F94-9D29-72ED5DAFEB21} 2012-02-02 15:08 - 2012-02-02 15:06 - 0000000 ____D C:\Users\Dennis\AppData\Local\{EA153FF0-48C0-439D-B7D3-5F2EABD81AEC} 2012-02-01 23:11 - 2012-02-01 23:10 - 0000000 ____D C:\Users\Dennis\AppData\Local\{2092BE5A-3CF1-4451-9BB7-E2EE7CE26D43} 2012-02-01 23:10 - 2012-02-01 23:10 - 0000000 ____D C:\Users\Dennis\AppData\Local\{6DF99341-E889-43AF-804B-E887050E9DAB} 2012-02-01 21:57 - 2012-02-01 21:57 - 0174009 ____A C:\Users\Dennis\Downloads\009.jpg 2012-02-01 21:57 - 2012-02-01 21:57 - 0170171 ____A C:\Users\Dennis\Downloads\010.jpg 2012-02-01 21:57 - 2012-02-01 21:57 - 0155788 ____A C:\Users\Dennis\Downloads\011.jpg 2012-02-01 21:56 - 2012-02-01 21:56 - 0181562 ____A C:\Users\Dennis\Downloads\007.jpg 2012-02-01 21:56 - 2012-02-01 21:56 - 0172455 ____A C:\Users\Dennis\Downloads\008.jpg 2012-02-01 17:11 - 2011-12-28 13:48 - 0000000 ____D C:\Program Files\Mal Updater 2 2012-02-01 16:49 - 2012-02-01 16:49 - 0000000 ____D C:\Users\Dennis\AppData\Roaming\ASUS 2012-02-01 16:48 - 2011-04-18 16:23 - 0000000 ____D C:\Users\Dennis\AppData\Local\VirtualStore 2012-02-01 16:41 - 2012-02-01 16:40 - 0046297 ____A C:\Windows\Cm112.ini.cfl 2012-02-01 16:41 - 2012-02-01 16:40 - 0000000 ____D C:\Program Files\ASUS Xonar U3 Audio 2012-02-01 16:41 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\system 2012-02-01 16:40 - 2012-02-01 16:39 - 0000842 ____A C:\Windows\Cm112.ini.imi 2012-02-01 11:20 - 2011-09-29 19:12 - 0000854 ____A C:\Users\Public\Desktop\AVG 2012.lnk 2012-02-01 11:10 - 2012-02-01 11:10 - 0000000 ____D C:\Users\Dennis\AppData\Local\{323A3FDF-1FA4-424A-9DAA-809C3454A1D0} 2012-02-01 11:09 - 2012-02-01 11:09 - 0000000 ____D C:\Users\Dennis\AppData\Local\{2B42AF24-F9BE-4F8F-B120-A7C5E7987122} 2012-01-31 21:21 - 2012-01-31 21:21 - 0000000 ____D C:\Users\Dennis\AppData\Local\{EB93E95D-83AD-4E2C-9A68-6E053D3FD012} 2012-01-31 21:21 - 2012-01-31 21:21 - 0000000 ____D C:\Users\Dennis\AppData\Local\{1C9DCF41-E125-4196-B90F-7728FD8D303C} 2012-01-31 09:20 - 2012-01-31 09:20 - 0000000 ____D C:\Users\Dennis\AppData\Local\{CA5B9EE5-2D2E-47B0-B873-8CEF46988E18} 2012-01-31 09:20 - 2012-01-31 09:20 - 0000000 ____D C:\Users\Dennis\AppData\Local\{0870B86A-F652-42CA-97C8-76C6FE2584D8} 2012-01-31 04:44 - 2011-04-18 17:20 - 0237072 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2012-01-30 18:44 - 2012-01-30 18:44 - 0000000 ____D C:\Users\Dennis\AppData\Local\{1190CDE9-3F3B-4385-85E2-C3AF0B8C89B2} 2012-01-30 18:44 - 2012-01-30 18:43 - 0000000 ____D C:\Users\Dennis\AppData\Local\{0C686C73-712D-4720-86BA-7C274B0383A4} 2012-01-30 06:19 - 2012-01-30 06:19 - 0000000 ____D C:\Users\Dennis\AppData\Local\{F88FF4A7-C4E6-4661-B846-CD92D23EA6F7} 2012-01-29 14:47 - 2012-01-29 14:47 - 0000000 ____D C:\Users\Dennis\AppData\Local\{60A1EEB8-5849-4CDA-8BD1-B22434B196A0} 2012-01-29 14:47 - 2012-01-29 14:47 - 0000000 ____D C:\Users\Dennis\AppData\Local\{3F9FB9B7-BD2B-415F-B00C-48286DD13313} 2012-01-29 02:47 - 2012-01-29 02:47 - 0000000 ____D C:\Users\Dennis\AppData\Local\{07B340E3-3660-4F28-86F2-9B13921A0664} 2012-01-29 02:46 - 2012-01-29 02:46 - 0000000 ____D C:\Users\Dennis\AppData\Local\{62631556-8AC5-4444-90B0-DFC642B099E9} 2012-01-28 14:46 - 2012-01-28 14:46 - 0000000 ____D C:\Users\Dennis\AppData\Local\{A1ED57E5-4138-4975-8F41-0B06308606EF} 2012-01-28 14:46 - 2012-01-28 14:46 - 0000000 ____D C:\Users\Dennis\AppData\Local\{14027736-3E2F-4F0E-8F01-804225086FAE} 2012-01-28 02:46 - 2012-01-28 02:46 - 0000000 ____D C:\Users\Dennis\AppData\Local\{F8D813F8-0950-4353-BAED-0655F641FDB7} 2012-01-28 02:46 - 2012-01-28 02:45 - 0000000 ____D C:\Users\Dennis\AppData\Local\{12555D09-E9A5-4053-872A-047655F9CA6A} 2012-01-27 14:46 - 2012-01-27 14:46 - 0000000 ____D C:\Users\Dennis\AppData\Local\{7D405D58-CDED-4B93-A399-5C6C1F6ABF22} 2012-01-27 00:21 - 2012-01-27 00:21 - 0000000 ____D C:\Users\Dennis\AppData\Local\{45354B3F-4A4D-47C6-A0BB-F7C8DED80E99} 2012-01-27 00:21 - 2012-01-27 00:18 - 0000000 ____D C:\Users\Dennis\AppData\Local\{6838B72F-BDB3-41E5-9012-1A2BDAEBFADA} 2012-01-25 12:48 - 2012-01-25 12:48 - 0000000 ____D C:\Users\Dennis\AppData\Local\{C3E0DE82-A4FE-4E5F-990D-278A33F37921} 2012-01-25 12:48 - 2012-01-25 12:48 - 0000000 ____D C:\Users\Dennis\AppData\Local\{0500E9EC-F6D3-45D9-B539-9435823D5B14} 2012-01-24 21:32 - 2012-03-13 11:04 - 0129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-01-24 21:32 - 2012-03-13 11:04 - 0058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-01-24 21:27 - 2012-03-13 11:04 - 0008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe 2012-01-23 19:42 - 2012-01-23 19:42 - 0000000 ____D C:\Users\Dennis\AppData\Local\{4620232A-2411-48DF-B2C8-CC6BECE32C02} 2012-01-23 19:42 - 2012-01-23 19:41 - 0000000 ____D C:\Users\Dennis\AppData\Local\{D6C3FA62-5CD0-4F86-8F30-D7541724F796} 2012-01-23 06:21 - 2012-01-23 06:21 - 0000000 ____D C:\Users\Dennis\AppData\Local\{A828135E-6A08-4737-9945-3D93B2806EB3} 2012-01-22 15:16 - 2012-01-22 15:17 - 0052811 ____A C:\Users\Dennis\Documents\13097.jpg 2012-01-22 13:40 - 2012-01-22 13:40 - 0000000 ____D C:\Users\Dennis\AppData\Local\{60731805-593F-4F9A-B444-7D750858760F} 2012-01-22 13:39 - 2012-01-22 13:39 - 0000000 ____D C:\Users\Dennis\AppData\Local\{2CBA2CA0-AD83-4F03-83C9-C7264FC43609} 2012-01-22 00:28 - 2012-01-22 00:28 - 0000000 ____D C:\Users\Dennis\AppData\Local\{74A867D4-4E0D-4A29-BB06-A1C9884BCAD3} 2012-01-21 09:47 - 2012-01-21 09:47 - 0000000 ____D C:\Users\Dennis\AppData\Local\{F3954483-9E28-4E53-B760-D33A64D6CED6} 2012-01-20 21:33 - 2012-01-20 21:32 - 0000000 ____D C:\Users\Dennis\AppData\Local\{C1EDF8D1-C7F4-4574-840E-73357E2C30B5} 2012-01-20 21:32 - 2012-01-20 21:31 - 0000000 ____D C:\Users\Dennis\AppData\Local\{471D8089-8BED-4173-B47B-2237E15844E9} 2012-01-19 18:23 - 2012-01-19 18:23 - 0000000 ____D C:\Users\Dennis\AppData\Local\{14EBFF03-AAB5-4880-887F-D7EAEAAF9D9A} 2012-01-19 18:22 - 2012-01-19 18:22 - 0000000 ____D C:\Users\Dennis\AppData\Local\{7DD8B7F8-E811-4410-806C-0AC11B18F1DE} 2012-01-18 17:12 - 2012-01-18 17:12 - 0000000 ____D C:\Users\Dennis\AppData\Local\{8BC17178-72E4-4F4A-AD92-DA1292039856} 2012-01-18 17:12 - 2012-01-18 17:12 - 0000000 ____D C:\Users\Dennis\AppData\Local\{78AB0107-B938-4363-987B-2CEA499F2596} 2012-01-17 18:04 - 2012-01-17 18:04 - 0000000 ____D C:\Users\Dennis\AppData\Local\{8382102A-135F-4450-8889-D308368C3B07} 2012-01-17 18:04 - 2012-01-17 18:03 - 0000000 ____D C:\Users\Dennis\AppData\Local\{7EF994B0-6FD0-4EFD-A153-8257286FB62D} 2012-01-16 13:30 - 2012-01-16 13:29 - 0000000 ____D C:\Users\Dennis\AppData\Local\{46C054A2-E46B-4D54-882C-5837B8AA3C5A} 2012-01-16 13:29 - 2012-01-16 13:28 - 0000000 ____D C:\Users\Dennis\AppData\Local\{DEED853E-502C-4B42-AA11-454A86DF11F0} 2012-01-15 12:48 - 2012-01-15 12:48 - 0000000 ____D C:\Users\Dennis\AppData\Local\{6F478017-6EA9-4C74-A033-99288AFFA787} 2012-01-15 12:47 - 2012-01-15 12:47 - 0000000 ____D C:\Users\Dennis\AppData\Local\{936F16CD-A14D-4E0D-AE5C-06E882782156} 2012-01-14 17:12 - 2012-01-14 17:12 - 0000000 ____D C:\Users\Dennis\AppData\Local\{BF612041-6D44-45B8-8633-7C13BBA074E3} 2012-01-13 16:07 - 2012-01-13 16:07 - 0026323 ____A C:\Users\Dennis\Downloads\Yuna_Final_Fantasy_Banner_by_gamfaqs2gamfaqs.jpg 2012-01-13 13:15 - 2012-01-13 13:15 - 0001984 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk 2012-01-13 13:15 - 2011-05-24 12:09 - 0000000 ____D C:\Program Files\Common Files\Adobe 2012-01-13 13:15 - 2011-05-24 12:09 - 0000000 ____D C:\Program Files\Adobe 2012-01-13 13:15 - 2011-04-18 17:27 - 0000000 ____D C:\Users\All Users\Adobe 2012-01-13 13:15 - 2011-04-18 17:27 - 0000000 ____D C:\ProgramData\Adobe 2012-01-13 13:14 - 2011-04-18 17:26 - 0000000 ____D C:\Users\Dennis\AppData\Local\Adobe 2012-01-13 12:50 - 2012-01-13 12:49 - 0000000 ____D C:\Users\Dennis\AppData\Local\{5E8EAAFB-6D69-45B8-AE57-0380FCA3D83E} 2012-01-13 12:49 - 2012-01-12 22:33 - 0000000 ____D C:\Users\Dennis\AppData\Local\{E43D40A3-D2E7-4C31-A5EB-A6691D384BD4} 2012-01-12 22:34 - 2012-01-12 22:34 - 0000000 ____D C:\Users\Dennis\AppData\Local\{8235A180-CD94-47B7-A50E-7C980C466EAE} 2012-01-12 22:34 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\config\TxR 2012-01-12 22:28 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\wfp 2012-01-12 22:26 - 2011-09-29 19:11 - 0000000 ____D C:\Program Files\Common Files\AVG Secure Search 2012-01-12 22:26 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\registration 2012-01-12 17:56 - 2012-01-12 17:56 - 0000000 ____D C:\Users\Dennis\AppData\Local\{64C2638F-7195-4BE0-9D2A-68788FD73137} 2012-01-11 15:39 - 2012-01-11 15:39 - 0000000 ____D C:\Users\Dennis\AppData\Local\{279075D8-528F-49E7-9EE4-A7D701D0E547} 2012-01-10 10:31 - 2012-01-10 10:31 - 0000000 ____D C:\Users\Dennis\AppData\Local\{298C3241-3FFD-4720-9C99-8078BDF857A7} 2012-01-10 10:31 - 2012-01-10 10:31 - 0000000 ____D C:\Users\Dennis\AppData\Local\{267F8B29-9831-48E0-BC8D-15E7EE27862C} 2012-01-09 19:40 - 2012-01-09 19:39 - 0000000 ____D C:\Users\Dennis\AppData\Local\{FBB6AAAC-7E76-4577-BDE0-74FB067E09E8} 2012-01-09 19:39 - 2012-01-09 19:37 - 0000000 ____D C:\Users\Dennis\AppData\Local\{D0A58833-2D5A-4487-A183-56C86745D5C2} 2012-01-08 22:02 - 2012-01-08 22:02 - 0000000 ____D C:\Users\Dennis\AppData\Local\{6784D3C3-B787-428B-AFCA-29C41FC211BF} 2012-01-08 22:02 - 2012-01-08 22:01 - 0000000 ____D C:\Users\Dennis\AppData\Local\{9B783446-9422-4B9D-9EB0-8AA4505A5567} ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ========================= Memory info ====================== Percentage of memory in use: 20% Total physical RAM: 1982.61 MB Available physical RAM: 1571.97 MB Total Pagefile: 1982.61 MB Available Pagefile: 1568.24 MB Total Virtual: 2047.88 MB Available Virtual: 1970.31 MB ======================= Partitions ========================= 1 Drive c: () (Fixed) (Total:148.95 GB) (Free:59.28 GB) NTFS 3 Drive f: (KINGSTON) (Removable) (Total:14.91 GB) (Free:1.22 GB) FAT32 4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 149 GB 0 B Disk 1 Online 14 GB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 100 MB 1024 KB Partition 2 Primary 148 GB 101 MB ================================================================================ ====================== Disk: 0 Partition 1 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 Y System Rese NTFS Partition 100 MB Healthy ================================================================================ ====================== Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C NTFS Partition 148 GB Healthy ================================================================================ ====================== Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 14 GB 4032 KB ================================================================================ ====================== Disk: 1 Partition 1 Type : 0C Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 F KINGSTON FAT32 Removable 14 GB Healthy ================================================================================ ====================== ========================================================== Last Boot: 2012-04-01 08:22 ======================= End Of Log ==========================
No worries about the delay.

In Vista or Windows 7: Boot to System Recovery Options and run FRST.
Type the following in the edit box after "Search:".

giveio.sys*

It then should look like:

Search: giveio.sys*

Click Search button and post the log (Search.txt) it makes to your reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI