This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google redirect [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL result:

OTL Extras logfile created on: 5/13/2012 12:10:42 AM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\gordon\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.93 Gb Available Physical Memory | 64.43% Memory free
6.19 Gb Paging File | 4.98 Gb Available in Paging File | 80.42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.82 Gb Total Space | 6.79 Gb Free Space | 1.87% Space Free | Partition Type: NTFS
Drive D: | 8.79 Gb Total Space | 1.01 Gb Free Space | 11.46% Space Free | Partition Type: NTFS
Drive E: | 7.95 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.51 Gb Total Space | 341.37 Gb Free Space | 36.65% Space Free | Partition Type: NTFS

Computer Name: FALCON | User Name: gordon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Opera.HTML] – C:\Program Files\Opera\Opera.exe (Opera Software)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)
https [open] – "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 1
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
"DisabledInterfaces" = {EFE1BE67-45BA-44DE-B7D3-1366D66F25D0}

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{16108AD3-E26D-4E2A-B5DF-8330C53B24D9}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdater.exe |
"{1FE00676-64C1-4B4A-AD20-CC00A0C58E1A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{249CC12D-93C3-42E5-923A-56338C5EF53E}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{35810F30-05FA-4220-A1D8-AE2EE7ACD68A}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{6327FAC7-D66F-4CC8-BA84-F5C3E1DDFC51}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{63760FDB-D578-4357-ABDE-6F1DB10E1135}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{645F43CE-2F8A-451A-8973-D7DB28AC12DC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6BAA18C7-46C3-4C14-9D16-F07CBEB2DBB9}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{75751383-2AF0-45CF-8152-2390498A0DE7}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{7B66C992-EFEC-4792-B9FA-B784C46D9620}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{81EA92A4-BE1A-4ACF-A699-E658C0426B94}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{938C18CD-A6F8-4497-972D-C4F47E8F5990}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9764303E-642B-4A22-9A69-B4B2C5FC2B3C}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{A7A9B62C-B955-4691-BEB5-F049D128EC82}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A8A4FBB7-000B-40A1-955E-D80C29D59DB9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B6C9C96F-B063-4BE4-A33A-0FE2348D9146}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdateservice.exe |
"{B9647C64-5B84-4B24-8ADC-BB5DF1701664}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{BF0F4FA4-624E-43AE-91BB-473409E689DF}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{C63C86A5-2207-4DBA-965D-1D9D98138CB8}" = rport=2869 | protocol=6 | dir=out | app=system |
"{D7734F60-2CF6-49A1-9CB4-2EF00C1EB019}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{D86C4B92-4547-4C82-B3B6-9B5D10E0AA51}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{E045388D-0335-4FD9-808F-A3744142EC47}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{E0BB1FFC-BCA0-416D-8E23-9E3CF3EAD164}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F099D9D8-FB9C-4596-A5E9-331948C86FB1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F8CEDEC3-119D-4241-822A-5103B8B2E055}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{FF435AD4-3FB6-4399-AA6C-055ED818DFE0}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0241C1FA-7D48-4DA3-87E5-3E5194E963E8}" = protocol=17 | dir=in | app=c:\games\far cry 2\bin\fc2editor.exe |
"{032A392B-8001-4E8A-8D02-2A50A6E48192}" = protocol=6 | dir=in | app=c:\games\far cry 2\bin\fc2editor.exe |
"{06478314-F6E1-4F56-B972-40D010A587B0}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{07ED1155-7114-44EE-9B41-EB9839976B37}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{0DFA269C-26A7-40DB-8FBC-A3FC70A7E581}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{1EF135C2-154F-4BF9-B678-18960993B301}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{21902072-0920-4796-8D11-A82CF9F37D20}" = protocol=17 | dir=in | app=c:\games\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe |
"{3131DDC0-842D-4C3B-B285-24C0AB04EE9B}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{34670EE4-2746-43E3-84DA-1F404EC540D3}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{346C2322-1C44-4F63-BDD5-B85A899CD800}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{36D357A1-D341-4620-B005-F6C86DBA6941}" = protocol=17 | dir=in | app=c:\games\far cry 2\bin\farcry2.exe |
"{38E7690A-F85F-44FD-B3AB-85BBA796593F}" = protocol=6 | dir=in | app=c:\games\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe |
"{413561A6-DAEF-4696-BEDF-87833E5BCFA6}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{43EA2E4F-C243-42FF-AE2E-2EEAC492648E}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{49A83C40-3C94-486B-BF4C-502AD34B6288}" = protocol=17 | dir=in | app=c:\games\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
"{4FBDE0BB-1A50-4157-BFEA-8B2168D3CCBD}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{53A0430D-1A73-4165-9C00-55D06EEBDE3E}" = protocol=6 | dir=in | app=c:\games\far cry 2\bin\farcry2.exe |
"{5780A299-35BA-46BF-B44F-A66D92204142}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{58A419AB-921B-4648-9A0E-00976E394C5D}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5BDBFC9A-E203-4565-BDEF-9C4992728E77}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{5CA21C12-E216-4F3C-B3F0-652171BDE98E}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{5DC12EB2-3138-4C44-B6D8-AB833BE89667}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{603DB5A6-355E-41EF-9FC6-36C8DAFCA36F}" = dir=in | app=c:\program files\myspace\im\myspaceim.exe |
"{6487EA9A-8DB9-4348-B6F8-64D9A485280B}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{65DA4D97-0A87-4F68-AAFD-64D4ABD81411}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{6617FC3F-4751-4300-9F2F-69F90C6ACA7C}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{66F74F27-FC4F-4DC5-A959-6AE2534D48CD}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{6833F444-B376-4EDA-BF33-04D7A368E9D9}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{7A0B0CFE-BC0D-4071-B66D-1EF5091D6445}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{7CEE62E6-D978-44C6-942D-659B75B9F6D0}" = protocol=17 | dir=in | app=c:\games\warhammer battle march\warhammer.exe |
"{7D7F39E5-B2AD-4CE0-954C-7906D6858549}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{8D1102E8-1E72-4C17-A00F-33668FFCD129}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{8EBB644D-085A-4DC4-A9C4-AEAE780E69AA}" = protocol=6 | dir=in | app=c:\games\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
"{8F1682A4-5AA9-4FEB-8418-7D64467D9AD5}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{92AACAFC-FCCC-423A-9B4C-1D066BB10A14}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{94DF8515-039D-4005-B1FF-A27EDD2C71AA}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{95B217BE-EEC4-485E-B083-B9E6A784F629}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A288DBB2-B431-4BCC-893F-59F3520095CF}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{AC28ECE6-3242-4537-ACA0-D0AEE9C742F4}" = protocol=17 | dir=in | app=c:\games\far cry 2\bin\fc2launcher.exe |
"{AEC5499F-07F6-4588-8CFB-BB3C59419A48}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{B03F517A-1CF8-43C7-ADF0-27A4C348040A}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{B0573369-E230-4ECF-8DC2-C9D49DEB3F86}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{B3BDDB28-59F9-4D2B-8684-7B5C1937A725}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B5AA0ACE-2BCA-433A-BDE3-781819ACFD45}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B6B91126-7819-4C08-BD7E-40FC1A20E5F5}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{B6DA5977-8D45-4EC4-91B6-6EE10B72F7DF}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{B803FFE0-DC22-4826-9A8A-D4E819E9DB28}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{BE9140E1-0086-42A0-8DDA-8D24E745FB78}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C21E2FCF-6CBF-4906-85D1-2F8C4FF970D7}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{C62083F6-5FB9-411E-B8A6-4993A243DEB8}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{C63196A3-4A44-48CF-A489-0DB2A9547F84}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CC30DD4B-197B-47C7-943A-270591DCDD41}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{CEDF7FD6-6F14-48DD-82C8-3DFBD2410562}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{CF471B8D-A6B4-410E-8CE9-5BC53EF1DF0F}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D1D8639D-30CE-407A-9149-D7DD1010B530}" = protocol=6 | dir=in | app=c:\games\warhammer battle march\warhammer.exe |
"{D27726D2-59C2-47E1-ABB6-0061D2ED489A}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D54BBCBA-6939-47AC-B9D8-93C255199921}" = protocol=6 | dir=in | app=c:\games\far cry 2\bin\fc2launcher.exe |
"{D6E6AF0A-B78D-46C5-80D9-535E33BC1D2C}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{D93C4189-507D-425C-A0D0-EDC652211590}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{E437E273-42DA-4D19-B5D3-9F32CFF6B241}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"{E484D9B8-2C8B-46EA-B48B-2D8622CEC99E}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{EE4597DA-B1AF-411D-A63C-D31B5151A8A4}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FD58EF6D-DB0B-4C17-984B-76A80318A154}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"TCP Query User{5190401F-2995-4374-B12D-8F237B924187}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"UDP Query User{DB728B92-7A97-4898-8D16-C2EDE617B633}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{046ED2B7-14D5-4F2C-A275-09D54CEFE757}" = GTactix
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0523EAF4-402C-4435-A0DA-13C40193D811}" = Logitech GamePanel Software 2.02
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks v.0.6.3.11
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 21
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{2A17F4DB-C3B7-4E45-AECC-7F9FF6909C4B}" = NETGEAR WN121T wireless USB 2.0 adapter
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4EAE665D-957A-4D04-9679-3AD582008877}" = NVIDIA PhysX
"{4EF6FDB0-3B11-4820-9860-8E08E9965195}" = Snapfish Media Detector
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{519ACA84-2F7E-4482-8201-B0DCB6C8B3A5}" = Taksi Desktop Video Recorder v0.779
"{5339885F-4597-4343-BD3B-74280CC79424}" = ArcSoft VideoImpression 2
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{574736E1-57BD-413B-8CA8-2945F94185CE}" = PC Camera
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{66A9D30D-1464-4C7F-B2F3-507DADAF2595}" = Microsoft IntelliPoint 6.3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6D217AEE-2D67-4486-A73D-106C726BCDF1}_is1" = Leawo Free Video Accelerator Version: 3.0.3.0
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75E71ADD-042C-4F30-BFAC-A9EC42351313}" = Python 2.4.3
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{8410B358-107A-4FB7-AB2B-6FD952F15A8F}" = Nero 8
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}" = Kaspersky Internet Security 2009
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{B0C0F5E6-10B1-11D6-9296-0050BA073EEC}" = Presto! VideoWorks 6
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0209
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.7.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BB6D4A78-4BDB-4FBD-81CB-00DC2FC2BF41}" = Seagate Manager Installer
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D6A1E429-CCE1-4140-A615-710B806D12BA}" = Motorola Driver Installation 3.2.0
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F0AF91F4-D1ED-490E-8751-997AF2A3FF0D}_is1" = Leawo Free FLV Converter version 2.3.0.9
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATC_is1" = Advanced Tactical Center™ 1.0
"AudioCS" = Creative Audio Console
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BitTorrent" = BitTorrent
"Camera Drivers_is1" = Camera Drivers V1.4
"CCleaner" = CCleaner
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"EADM" = EA Download Manager
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"FLV Player2.0.25" = FLV Player
"FragFX" = FragFX
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HyperCam 2" = HyperCam 2
"InstallShield_{2A17F4DB-C3B7-4E45-AECC-7F9FF6909C4B}" = NETGEAR WN121T wireless USB 2.0 adapter
"InstallShield_{BB6D4A78-4BDB-4FBD-81CB-00DC2FC2BF41}" = Seagate Manager Installer
"InstallWIX_{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}" = Kaspersky Internet Security 2009
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.4.4 (Basic)
"lvdrivers_11.80" = Logitech QuickCam Driver Package
"MatrixMania Screensaver" = MatrixMania Screensaver
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"MSNINST" = MSN
"MySpaceIM" = MySpaceIM
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OGPlanet Game Launcher US" = OGPlanet Game Launcher
"Opera 11.61.1250" = Opera 11.61
"SD Gundam Capsule Fighter" = SD Gundam Capsule Fighter
"sp6" = Logitech SetPoint 6.32
"Star Trek Online" = Star Trek Online
"Steam App 1250" = Killing Floor
"Steam App 240" = Counter-Strike: Source
"Steam App 7760" = X-Com: UFO Defense
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TripleAVersion1_3_2_2" = TripleA Version 1_3_2_2
"TurboTax 2010" = TurboTax 2010
"Veoh Web Player Beta" = Veoh Web Player
"WildTangent hpdesktop Master Uninstall" = My HP Games
"WinGimp-2.0_is1" = GIMP 2.6.6
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/31/2012 4:12:23 PM | Computer Name = Falcon | Source = Application Error | ID = 1000
Description = Faulting application Skype.exe, version 5.5.59.124, time stamp 0x4e96c098,
faulting module Skype.exe, version 5.5.59.124, time stamp 0x4e96c098, exception
code 0xc0000005, fault offset 0x001dae87, process id 0x3834, application start time
0x01cd0f672f8780b0.

Error - 3/31/2012 4:54:37 PM | Computer Name = Falcon | Source = Application Error | ID = 1000
Description = Faulting application YahooMessenger.exe, version 11.5.0.192, time
stamp 0x4f45c49d, faulting module RPCRT4.dll, version 6.0.6002.18024, time stamp
0x49f05bcc, exception code 0xc0000005, fault offset 0x000ae0d9, process id 0x21e8,
application start time 0x01cd0e9e3be7a1b0.

Error - 4/1/2012 2:28:09 AM | Computer Name = Falcon | Source = Application Error | ID = 1000
Description = Faulting application Skype.exe, version 5.5.59.124, time stamp 0x4e96c098,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x03020302, process id 0x85b8, application start time 0x01cd0fd092f3ae30.

Error - 4/2/2012 9:02:13 PM | Computer Name = Falcon | Source = Application Error | ID = 1000
Description = Faulting application worldoftanks.exe, version 0.7.2.0, time stamp
0x4f685c83, faulting module worldoftanks.exe, version 0.7.2.0, time stamp 0x4f685c83,
exception code 0xc0000005, fault offset 0x008f6d03, process id 0x1122c, application
start time 0x01cd1127de774e90.

Error - 4/3/2012 12:09:08 AM | Computer Name = Falcon | Source = EventSystem | ID = 4609
Description =

Error - 4/6/2012 7:46:30 AM | Computer Name = Falcon | Source = Application Error | ID = 1000
Description = Faulting application YahooMessenger.exe, version 11.5.0.192, time
stamp 0x4f45c49d, faulting module RPCRT4.dll, version 6.0.6002.18024, time stamp
0x49f05bcc, exception code 0xc0000005, fault offset 0x000ae0d9, process id 0x129c,
application start time 0x01cd11510a68ddfe.

Error - 4/6/2012 7:47:07 AM | Computer Name = Falcon | Source = Application Error | ID = 1000
Description = Faulting application YahooMessenger.exe, version 11.5.0.192, time
stamp 0x4f45c49d, faulting module yui.dll, version 2008.2.1.1, time stamp 0x4f45c575,
exception code 0xc0000005, fault offset 0x0005255b, process id 0x129c, application
start time 0x01cd11510a68ddfe.

Error - 4/7/2012 2:11:24 PM | Computer Name = Falcon | Source = Application Error | ID = 1000
Description = Faulting application AxisAllies.exe, version 0.0.0.0, time stamp 0x35f9be1f,
faulting module AxisAllies.exe, version 0.0.0.0, time stamp 0x35f9be1f, exception
code 0xc0000005, fault offset 0x000422cf, process id 0x4a14, application start time
0x01cd14e83fba5206.

Error - 4/9/2012 4:24:47 PM | Computer Name = Falcon | Source = Application Hang | ID = 1002
Description = The program MsiExec.exe version 4.5.6002.18005 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 7118 Start Time: 01cd168eb91cec60 Termination Time: 5

Error - 4/11/2012 5:06:28 AM | Computer Name = Falcon | Source = Application Error | ID = 1000
Description = Faulting application worldoftanks.exe, version 0.7.2.0, time stamp
0x4f685c83, faulting module worldoftanks.exe, version 0.7.2.0, time stamp 0x4f685c83,
exception code 0xc0000005, fault offset 0x008f6fd5, process id 0xc458, application
start time 0x01cd174b16c7eec0.

[ Media Center Events ]
Error - 6/9/2009 10:06:52 AM | Computer Name = avatar | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 6/28/2009 11:34:12 PM | Computer Name = avatar | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7003
Description =

Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7023
Description =

Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7023
Description =

Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7003
Description =

Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7023
Description =

Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7023
Description =

Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7023
Description =

Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7023
Description =

Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7023
Description =

Error - 5/12/2012 5:19:30 AM | Computer Name = Falcon | Source = Service Control Manager | ID = 7026
Description =


< End of report >
OTL logfile created on: 5/13/2012 12:10:42 AM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\gordon\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.93 Gb Available Physical Memory | 64.43% Memory free
6.19 Gb Paging File | 4.98 Gb Available in Paging File | 80.42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.82 Gb Total Space | 6.79 Gb Free Space | 1.87% Space Free | Partition Type: NTFS
Drive D: | 8.79 Gb Total Space | 1.01 Gb Free Space | 11.46% Space Free | Partition Type: NTFS
Drive E: | 7.95 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.51 Gb Total Space | 341.37 Gb Free Space | 36.65% Space Free | Partition Type: NTFS

Computer Name: FALCON | User Name: gordon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\gordon\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Common Files\Logishrd\LComMgr\Communications_Helper.exe ()
PRC - C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Logishrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - \\.\globalroot\SystemRoot\system32\svchost.exe ()
PRC - C:\Program Files\NETGEAR\WN121T\wn121t.exe ()


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\System32\0409\sp.DLL ()
MOD - C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Logitech\QuickCam\LAppRes.DLL ()
MOD - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
MOD - C:\Program Files\Common Files\Logishrd\LComMgr\LogiVOIPDevicePlugin.dll ()
MOD - C:\Program Files\Common Files\Logishrd\LComMgr\LogiCordless4001.dll ()
MOD - C:\Program Files\Common Files\Logishrd\LComMgr\LogiCordless.dll ()
MOD - C:\Program Files\Logitech\QuickCam\EFVal.dll ()
MOD - C:\Program Files\Common Files\Logishrd\LComMgr\Communications_Helper.exe ()
MOD - C:\Program Files\Common Files\Logishrd\LComMgr\DevMngr.dll ()
MOD - C:\Program Files\Common Files\Logishrd\LVCOMSER\LVCSPS.dll ()
MOD - C:\Program Files\NETGEAR\WN121T\wn121t.exe ()


========== Win32 Services (SafeList) ==========

SRV - (websenserealtimeanalyzer) – %systemroot%\system32\hwpsgt.dll File not found
SRV - (vaiomediaplatform-videoserver-appserver) – %systemroot%\system32\downloadmanagerlite.dll File not found
SRV - (USIUDF) – %systemroot%\system32\lxcf_device.dll File not found
SRV - (us30service) – %systemroot%\system32\wmiaprpl.dll File not found
SRV - (stllssvr) – c:\Program Files\Common Files\SureThing Shared\stllssvr.exe File not found
SRV - (spcstb) – %systemroot%\system32\tcsd_win32.exe.dll File not found
SRV - (SE2Bobex) – %systemroot%\system32\EUSBMSD.dll File not found
SRV - (s117obex) – %systemroot%\system32\pmounter.dll File not found
SRV - (O2SCBUS) – %systemroot%\system32\ARCSOFTVIRTUALCAPTURE.dll File not found
SRV - (ltmodem5) – %systemroot%\system32\incdpass.dll File not found
SRV - (lfsfilt) – %systemroot%\system32\prepdrvr.dll File not found
SRV - (ldlcserv) – %systemroot%\system32\AFGMp50.dll File not found
SRV - (lcs) – %systemroot%\system32\dvpapi.dll File not found
SRV - (jsdaemon) – %systemroot%\system32\tvs.dll File not found
SRV - (isamsmt) – %systemroot%\system32\ma763004.dll File not found
SRV - (ipcsvc) – %systemroot%\system32\W2acehid.dll File not found
SRV - (Intels51) – %systemroot%\system32\iksyssec.dll File not found
SRV - (iaantmon) – %systemroot%\system32\tmesbs32.dll File not found
SRV - (fsaua) – %systemroot%\system32\Ndismeetro.dll File not found
SRV - (fsaa) – %systemroot%\system32\ofcpfwsvc.dll File not found
SRV - (dnetc) – %systemroot%\system32\hsvcmod.dll File not found
SRV - (clientservice) – %systemroot%\system32\WUSB54GCSVC.dll File not found
SRV - (Cinemsup) – %systemroot%\system32\slapd-data52.dll File not found
SRV - (BCMModem) – %systemroot%\system32\s616obex.dll File not found
SRV - (ATKFUSService) – %systemroot%\system32\pavagente.dll File not found
SRV - (Accelerometer) – %systemroot%\system32\cmdmon.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SPService) – C:\WINDOWS\System32\0409\sp.DLL ()
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\Logishrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (inorpc) – C:\WINDOWS\System32\atmarpc.dll (Oak Technology Inc.)
SRV - (WcesComm) – C:\WINDOWS\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\WINDOWS\WindowsMobile\rapimgr.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (XDva391) – C:\Windows\system32\XDva391.sys File not found
DRV - (XAudio) – system32\DRIVERS\xaudio.sys File not found
DRV - (winachsf) – system32\DRIVERS\HSX_CNXT.sys File not found
DRV - (STV680) – system32\drivers\STV680.sys File not found
DRV - (RT73) – system32\DRIVERS\rt73.sys File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (mdmxsdk) – system32\DRIVERS\mdmxsdk.sys File not found
DRV - (MaplomL) – File not found
DRV - (Maplom) – File not found
DRV - (ivusb) – system32\DRIVERS\ivusb.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (HSXHWBS2) – system32\DRIVERS\HSXHWBS2.sys File not found
DRV - (HSF_DP) – system32\DRIVERS\HSX_DP.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (nvlddmkm) – C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (LMouFilt) – C:\WINDOWS\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LUsbFilt) – C:\WINDOWS\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (Linksys_adapter) – C:\WINDOWS\System32\drivers\AE2500vista.sys (Broadcom Corporation)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\System32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (USB_RNDIS_VISTA) – C:\WINDOWS\System32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (CoachVid) – C:\WINDOWS\System32\drivers\CoachVid.sys (FotoNation Inc.)
DRV - (KLIF) – C:\WINDOWS\System32\drivers\klif.sys ()
DRV - (klbg) – C:\WINDOWS\System32\drivers\klbg.sys (Kaspersky Lab)
DRV - (atksgt) – C:\WINDOWS\System32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\System32\drivers\lirsgt.sys ()
DRV - (nvstor32) – C:\WINDOWS\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (LVUSBSta) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\System32\drivers\LVPr2Mon.sys ()
DRV - (kl1) – C:\WINDOWS\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (ha20x2k) – C:\WINDOWS\System32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – C:\WINDOWS\System32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTHWIUT.DLL) – C:\WINDOWS\System32\CTHWIUT.DLL (Creative Technology Ltd.)
DRV - (CT20XUT.DLL) – C:\WINDOWS\System32\CT20XUT.DLL (Creative Technology Ltd.)
DRV - (CTEXFIFX.DLL) – C:\WINDOWS\System32\CTEXFIFX.DLL (Creative Technology Ltd.)
DRV - (KLIM6) – C:\WINDOWS\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (Point32) – C:\WINDOWS\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (WDC_SAM) – C:\WINDOWS\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (MRV6X32U) Marvell TOPDOG 802.11n WLAN Driver for Vista x86 (USB8x) – C:\WINDOWS\System32\drivers\MRVW24B.sys (Marvell Semiconductor, Inc)
DRV - (KLFLTDEV) – C:\WINDOWS\System32\drivers\klfltdev.sys (Kaspersky Lab)
DRV - (motmodem) – C:\WINDOWS\System32\drivers\motmodem.sys (Motorola)
DRV - (L8042Kbd) – C:\WINDOWS\System32\drivers\L8042Kbd.sys (Logitech Inc.)
DRV - (Achernar) – C:\WINDOWS\System32\drivers\Achernar.sys (NewSoft Technology Corporation)
DRV - (Afc) – C:\WINDOWS\System32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (VSTHWBS2) – C:\WINDOWS\System32\drivers\VSTBS23.SYS (Conexant Systems, Inc.)
DRV - (Ps2) – C:\WINDOWS\System32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (WT6563F) – C:\WINDOWS\System32\drivers\WT6563F.sys (Weltrend Semiconductor, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\..\SearchScopes,DefaultScope = {71EF9C57-6C15-4BC1-8E33-AF986047FB2C}
IE - HKLM\..\SearchScopes\{274FBA77-48F1-4108-A6BD-449B7F429289}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDUS7
IE - HKLM\..\SearchScopes\{6D96A4D6-4A13-408D-B965-463DF0566E36}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpd
IE - HKLM\..\SearchScopes\{71EF9C57-6C15-4BC1-8E33-AF986047FB2C}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=hp-pvdt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{080FBDF6-B230-4e4d-A4E7-7C7A56D7BABC}: "URL" = http://searchservice.myspace.com/index.cfm…amp;orig=IMC-IE
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms…000001bb952584d
IE - HKCU\..\SearchScopes\{274FBA77-48F1-4108-A6BD-449B7F429289}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDUS7
IE - HKCU\..\SearchScopes\{6D96A4D6-4A13-408D-B965-463DF0566E36}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpd
IE - HKCU\..\SearchScopes\{71EF9C57-6C15-4BC1-8E33-AF986047FB2C}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=hp-pvdt
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.update: false
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@ogplanet.com/npOGPPlugin: C:\Windows\system32\npOGPPlugin.dll (OGPlanet)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll File not found
FF - HKLM\Software\MozillaPlugins\@veoh.com/VeohTVPlugin: C:\Program Files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@veoh.com/VeohWebPlayer: C:\Program Files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\gordon\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/15 00:34:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/15 09:13:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\THBExt [2008/10/02 10:03:42 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Veoh Networks\VeohWebPlayer\FFVideoFinder

[2012/04/15 09:49:31 | 000,000,000 | -H-D | M] (No name found) – C:\Users\gordon\AppData\Roaming\mozilla\Extensions
[2012/04/15 10:31:18 | 000,000,000 | —D | M] (No name found) – C:\Users\gordon\AppData\Roaming\mozilla\Firefox\Profiles\mn9yqrg3.default\extensions
[2012/04/15 10:31:00 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\gordon\AppData\Roaming\mozilla\Firefox\Profiles\mn9yqrg3.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/04/15 10:31:18 | 000,000,000 | —D | M] (FoxLingo) – C:\Users\gordon\AppData\Roaming\mozilla\Firefox\Profiles\mn9yqrg3.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2012/04/27 05:56:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/27 05:56:55 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/03/12 21:39:39 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/03/29 06:02:49 | 000,002,288 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012/03/12 21:38:32 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/03/12 21:38:32 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\gordon\AppData\Local\Google\Chrome\Application\10.0.648.205\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\gordon\AppData\Local\Google\Chrome\Application\10.0.648.205\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\gordon\AppData\Local\Google\Chrome\Application\10.0.648.205\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U21 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
CHR - plugin: Veoh Web Player Beta (Enabled) = C:\Program Files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\gordon\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm ()
O8 - Extra context menu item: Download with &Media; Finder - C:\Program Files\Media Finder\hook.html File not found
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll (Kaspersky Lab)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3912B7E4-8932-4AFA-87AA-471DD2C676A0}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7B5A7321-11B0-464D-BA23-3A74381B731E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BEF6FFD8-3996-406E-992D-5DAE7FA63F59}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7B99119-827F-49EC-9FD9-45D246F6F4FD}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\WINDOWS\System32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Users\gordon\ShikamaruMasterOfShadowJutsu.jpg
O24 - Desktop BackupWallPaper: C:\Users\gordon\ShikamaruMasterOfShadowJutsu.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/07 10:14:08 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/01/26 20:39:43 | 000,000,034 | R— | M] () - E:\AUTORUN.INF – [ UDF ]
O32 - AutoRun File - [2010/01/10 18:54:52 | 000,000,170 | —- | M] () - F:\Autorun.inf – [ NTFS ]
O33 - MountPoints2\{091ddc47-e115-11de-8544-001bb952584d}\Shell - "" = AutoRun
O33 - MountPoints2\{091ddc47-e115-11de-8544-001bb952584d}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{2a341c88-833e-11dd-a787-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{2a341c88-833e-11dd-a787-806e6f6e6963}\Shell\AutoRun\command - "" = E:\PC_Clickme.exe – [2007/01/26 20:39:43 | 001,205,666 | R— | M] (Macromedia, Inc.)
O33 - MountPoints2\{4b2db1ab-243d-11de-93a3-001bb952584d}\Shell\AutoRun\command - "" = J:\.\RapidBlogManager.exe
O33 - MountPoints2\{8a2343cb-e10e-11de-9f57-001bb952584d}\Shell - "" = AutoRun
O33 - MountPoints2\{8a2343cb-e10e-11de-9f57-001bb952584d}\Shell\AutoRun\command - "" = "K:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: ldlcserv - %systemroot%\system32\AFGMp50.dll File not found
NetSvcs: lfsfilt - %systemroot%\system32\prepdrvr.dll File not found
NetSvcs: us30service - %systemroot%\system32\wmiaprpl.dll File not found
NetSvcs: O2SCBUS - %systemroot%\system32\ARCSOFTVIRTUALCAPTURE.dll File not found
NetSvcs: SE2Bobex - %systemroot%\system32\EUSBMSD.dll File not found
NetSvcs: dnetc - %systemroot%\system32\hsvcmod.dll File not found
NetSvcs: ATKFUSService - %systemroot%\system32\pavagente.dll File not found
NetSvcs: jsdaemon - %systemroot%\system32\tvs.dll File not found
NetSvcs: iaantmon - %systemroot%\system32\tmesbs32.dll File not found
NetSvcs: Accelerometer - %systemroot%\system32\cmdmon.dll File not found
NetSvcs: vaiomediaplatform-videoserver-appserver - %systemroot%\system32\downloadmanagerlite.dll File not found
NetSvcs: Intels51 - %systemroot%\system32\iksyssec.dll File not found
NetSvcs: isamsmt - %systemroot%\system32\ma763004.dll File not found
NetSvcs: inorpc - C:\WINDOWS\System32\atmarpc.dll (Oak Technology Inc.)
NetSvcs: fsaua - %systemroot%\system32\Ndismeetro.dll File not found
NetSvcs: ltmodem5 - %systemroot%\system32\incdpass.dll File not found
NetSvcs: fsaa - %systemroot%\system32\ofcpfwsvc.dll File not found
NetSvcs: websenserealtimeanalyzer - %systemroot%\system32\hwpsgt.dll File not found
NetSvcs: lcs - %systemroot%\system32\dvpapi.dll File not found
NetSvcs: clientservice - %systemroot%\system32\WUSB54GCSVC.dll File not found
NetSvcs: BCMModem - %systemroot%\system32\s616obex.dll File not found
NetSvcs: spcstb - %systemroot%\system32\tcsd_win32.exe.dll File not found
NetSvcs: s117obex - %systemroot%\system32\pmounter.dll File not found
NetSvcs: USIUDF - %systemroot%\system32\lxcf_device.dll File not found
NetSvcs: ipcsvc - %systemroot%\system32\W2acehid.dll File not found
NetSvcs: Cinemsup - %systemroot%\system32\slapd-data52.dll File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: msvideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.JPEG - C:\Windows\System32\JpegCode.dll (Zoran Microelectronics Ltd.)
Drivers32: VIDC.MJPG - C:\Windows\System32\JpegCode.dll (Zoran Microelectronics Ltd.)
Drivers32: VIDC.NSVI - C:\Windows\System32\Nsvideo.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/05/13 00:08:28 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\gordon\Desktop\HiJackThis.exe
[2012/05/13 00:01:38 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\gordon\Desktop\OTL.exe
[2012/05/12 00:42:06 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/05/11 20:42:57 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/05/11 20:42:57 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/05/11 20:42:56 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/05/11 20:42:55 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/05/11 20:42:55 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/05/11 20:42:23 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/05/11 20:42:22 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/05/11 20:42:22 | 002,044,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/05/01 04:35:23 | 000,000,000 | —D | C] – C:\Users\gordon\Desktop\Type59 all-star
[2012/04/27 05:56:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/04/27 05:56:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2012/04/19 12:50:03 | 000,000,000 | —D | C] – C:\Users\gordon\Desktop\Desktop

========== Files - Modified Within 30 Days ==========

[2012/05/13 00:08:26 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\gordon\Desktop\HiJackThis.exe
[2012/05/13 00:01:34 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\gordon\Desktop\OTL.exe
[2012/05/12 23:41:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/12 22:18:22 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/12 22:18:22 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/12 02:25:39 | 000,642,906 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/05/12 02:25:39 | 000,120,096 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/05/12 02:18:34 | 000,320,040 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/05/12 02:18:28 | 000,000,000 | -HS- | M] () – C:\Windows\System32\dds_trash_log.cmd
[2012/05/12 02:18:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/12 02:15:30 | 009,558,560 | —- | M] () – C:\Windows\System32\drivers\fidbox.dat
[2012/05/12 02:15:30 | 001,966,112 | -HS- | M] () – C:\Windows\System32\drivers\fidbox2.dat
[2012/05/12 02:15:30 | 000,084,140 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.idx
[2012/05/12 02:15:30 | 000,054,400 | —- | M] () – C:\Windows\System32\BMXStateBkp-{00000001-00000000-00000006-00001102-00000005-00311102}.rfx
[2012/05/12 02:15:30 | 000,054,400 | —- | M] () – C:\Windows\System32\BMXState-{00000001-00000000-00000006-00001102-00000005-00311102}.rfx
[2012/05/12 02:15:30 | 000,014,088 | -HS- | M] () – C:\Windows\System32\drivers\fidbox2.idx
[2012/05/12 02:15:30 | 000,000,788 | —- | M] () – C:\Windows\System32\DVCState-{00000001-00000000-00000006-00001102-00000005-00311102}.rfx
[2012/05/12 02:14:54 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2012/05/12 00:31:21 | 000,223,232 | —- | M] () – C:\Users\gordon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/11 13:28:37 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2012/05/11 09:47:27 | 000,001,516 | —- | M] () – C:\Windows\wininit.ini
[2012/05/09 09:06:30 | 000,001,009 | —- | M] () – C:\Users\gordon\Desktop\JSGME - Shortcut.lnk
[2012/05/05 06:41:55 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/05/05 06:41:55 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/05/02 04:52:26 | 413,611,958 | —- | M] () – C:\Users\gordon\Desktop\NA.11.12.21.CPFAF.wmv
[2012/05/01 05:07:07 | 000,509,266 | —- | M] () – C:\Users\gordon\Desktop\20120501_0502_china-Ch01_Type59_ensk.wotreplay
[2012/04/30 13:04:07 | 000,568,685 | —- | M] () – C:\Users\gordon\Desktop\20120430_1258_ussr-T_50_2_steppes.wotreplay
[2012/04/15 09:53:52 | 000,000,878 | —- | M] () – C:\Users\gordon\Documents\cc_20120415_095346.reg
[2012/04/15 09:29:23 | 000,000,862 | —- | M] () – C:\Users\gordon\Documents\cc_20120415_092920.reg
[2012/04/15 09:28:52 | 000,001,440 | —- | M] () – C:\Users\gordon\Documents\cc_20120415_092847.reg
[2012/04/15 09:28:19 | 000,040,470 | —- | M] () – C:\Users\gordon\Documents\cc_20120415_092802.reg
[2012/04/15 00:34:37 | 000,000,879 | —- | M] () – C:\Users\gordon\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/04/14 13:19:45 | 045,359,445 | —- | M] () – C:\Users\gordon\Desktop\263013.flv
[2012/04/14 12:58:29 | 006,663,338 | —- | M] () – C:\Users\gordon\Desktop\2010-06-06-andreasworld-3.wmv.mp4
[2012/04/14 12:55:42 | 010,666,933 | —- | M] () – C:\Users\gordon\Desktop\2010-06-06-andreasworld4.wmv.mp4
[2012/04/14 12:54:55 | 010,221,610 | —- | M] () – C:\Users\gordon\Desktop\2010-06-06-andreasworld-1.wmv.mp4

========== Files Created - No Company Name ==========

[2012/05/09 09:06:30 | 000,001,009 | —- | C] () – C:\Users\gordon\Desktop\JSGME - Shortcut.lnk
[2012/05/04 06:15:28 | 641,415,913 | —- | C] () – C:\Users\gordon\Desktop\NaughtyAlysha.12.02.29.Still.Horny.XXX.WMV-Sex4Free.PORNOH.INFO.wmv
[2012/05/02 03:37:12 | 413,611,958 | —- | C] () – C:\Users\gordon\Desktop\NA.11.12.21.CPFAF.wmv
[2012/05/01 04:21:01 | 000,509,266 | —- | C] () – C:\Users\gordon\Desktop\20120501_0502_china-Ch01_Type59_ensk.wotreplay
[2012/04/30 12:28:34 | 000,568,685 | —- | C] () – C:\Users\gordon\Desktop\20120430_1258_ussr-T_50_2_steppes.wotreplay
[2012/04/15 09:53:49 | 000,000,878 | —- | C] () – C:\Users\gordon\Documents\cc_20120415_095346.reg
[2012/04/15 09:29:22 | 000,000,862 | —- | C] () – C:\Users\gordon\Documents\cc_20120415_092920.reg
[2012/04/15 09:28:49 | 000,001,440 | —- | C] () – C:\Users\gordon\Documents\cc_20120415_092847.reg
[2012/04/15 09:28:06 | 000,040,470 | —- | C] () – C:\Users\gordon\Documents\cc_20120415_092802.reg
[2012/04/15 00:34:37 | 000,000,879 | —- | C] () – C:\Users\gordon\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/04/15 00:34:37 | 000,000,867 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/04/14 13:19:44 | 045,359,445 | —- | C] () – C:\Users\gordon\Desktop\263013.flv
[2012/04/14 12:58:29 | 006,663,338 | —- | C] () – C:\Users\gordon\Desktop\2010-06-06-andreasworld-3.wmv.mp4
[2012/04/14 12:54:54 | 010,221,610 | —- | C] () – C:\Users\gordon\Desktop\2010-06-06-andreasworld-1.wmv.mp4
[2012/04/14 12:51:58 | 010,666,933 | —- | C] () – C:\Users\gordon\Desktop\2010-06-06-andreasworld4.wmv.mp4
[2012/03/31 11:20:16 | 000,001,516 | —- | C] () – C:\Windows\wininit.ini
[2012/02/09 21:05:44 | 000,416,064 | —- | C] () – C:\Windows\System32\nvStreaming.exe
[2011/12/21 14:13:24 | 000,053,299 | R— | C] () – C:\Windows\System32\pthreadVC.dll
[2011/06/21 01:24:07 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/05/29 09:40:40 | 000,319,488 | -HS- | C] () – C:\Users\gordon\AppData\Local\skc.exe
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\System32\xlive.dll.cat

========== LOP Check ==========

[2008/09/17 10:00:08 | 000,000,000 | -HSD | M] – C:\Users\gordon\AppData\Roaming\.#
[2008/10/13 23:16:05 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\Activision
[2012/05/05 19:32:56 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\BitTorrent
[2008/09/20 05:55:35 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\Command & Conquer 3 Kane's Wrath
[2009/08/16 06:52:00 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2012/02/03 07:50:09 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\gtk-2.0
[2009/07/16 17:41:09 | 000,000,000 | -H-D | M] – C:\Users\gordon\AppData\Roaming\Leadertech
[2010/05/06 04:57:59 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\Leawo
[2008/09/15 11:11:48 | 000,000,000 | -H-D | M] – C:\Users\gordon\AppData\Roaming\MSNInstaller
[2008/10/03 23:45:51 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\Opera
[2009/12/26 10:06:04 | 000,000,000 | -H-D | M] – C:\Users\gordon\AppData\Roaming\PeerNetworking
[2008/11/01 09:03:35 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\Red Alert 3
[2008/09/15 09:10:40 | 000,000,000 | -H-D | M] – C:\Users\gordon\AppData\Roaming\Snapfish
[2012/04/23 06:28:17 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\TS3Client
[2011/06/11 18:56:24 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\ts3overlay
[2011/02/22 05:25:14 | 000,000,000 | -H-D | M] – C:\Users\gordon\AppData\Roaming\Unity
[2012/05/10 11:48:24 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\uPlayer
[2011/05/06 12:42:07 | 000,000,000 | —D | M] – C:\Users\gordon\AppData\Roaming\wargaming.net
[2009/12/04 14:12:42 | 000,000,000 | -H-D | M] – C:\Users\gordon\AppData\Roaming\Western Digital
[2008/09/15 10:45:40 | 000,000,000 | -H-D | M] – C:\Users\gordon\AppData\Roaming\WildTangent
[2012/05/12 02:15:00 | 000,032,646 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2007/05/07 10:14:08 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2007/05/07 10:30:38 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2009/12/30 07:26:14 | 000,000,373 | —- | M] () – C:\CD3rdPartyWrapper.log
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/02/08 18:23:58 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/02/08 18:23:58 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/05/12 02:16:34 | 3533,254,656 | -HS- | M] () – C:\pagefile.sys
[2007/05/07 09:55:18 | 000,000,471 | —- | M] () – C:\RHDSetup.log
[2011/04/29 17:06:18 | 000,006,140 | —- | M] () – C:\scramble.log
[2012/03/29 06:03:39 | 000,000,237 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/12/04 16:50:01 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/09/17 00:11:05 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 03:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/04 17:33:03 | 000,000,286 | -HS- | M] () – C:\Users\gordon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/05/13 00:08:26 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\gordon\Desktop\HiJackThis.exe
[2012/05/13 00:01:34 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\gordon\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-05-12 08:25:07

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB28152$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\gordon\Desktop\Volkswagen_Commercial_The_Force.flv:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\gordon\Desktop\PICT0001.AVI:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\gordon\Desktop\Kinectimals.mp4:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\gordon\Desktop\jadeonyahoo.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\gordon\Desktop\Chinese Guy is a SEXIST_.mp4:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\gordon\Desktop\03_captain_america_the_first_avenger_2011_brrip_xvid_sam_7f5.flv:TOC.WMV

< End of report >
Hi,

BitTorrent

Above listed ones are P2P file sharing programs. P2P downloads are nowadays one of those things that most likely bring infection into the system. My recommendation is to uninstall these (and other if present) P2P file sharing programs.


Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds file to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop. Post them back to your topic.
I got this message when I tried with Kaspersky on: MBR.DAT belonging to group 'Low Restricted' is trying to download driver in a hidden way C:\USERS\GORDON\APPDATA\LOCAL\TEMP\MBR.SYS. Kaspersky Internet Security will not be able to control application activity after installation.
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_21 Run by [removed] at 23:20:53 on 2012-05-14 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3070.1884 [GMT -7:00] . SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\WUDFHost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\NETGEAR\WN121T\wn121t.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Windows\system32\IoctlSvc.exe C:\Windows\system32\svchost.exe -k netsvc C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe C:\Program Files\Logitech\SetPointP\SetPoint.exe C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop uInternet Settings,ProxyOverride = *.local BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: {CA4520F3-AE13-4FB1-A513-58E23991C86D} - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll TB: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll mRun: [] mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wn121t\wn121t.exe uPolicies-explorer: HideSCAHealth = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Download with &Media Finder - c:\program files\media finder\hook.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: mswsock.dll Trusted Zone: intuit.com\ttlc DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab TCP: DhcpNameServer = 10.0.0.1 TCP: Interfaces\{3912B7E4-8932-4AFA-87AA-471DD2C676A0} : DhcpNameServer = 75.75.75.75 75.75.76.76 TCP: Interfaces\{7B5A7321-11B0-464D-BA23-3A74381B731E} : DhcpNameServer = 192.168.1.1 192.168.1.1 TCP: Interfaces\{BEF6FFD8-3996-406E-992D-5DAE7FA63F59} : DhcpNameServer = 192.168.1.1 192.168.1.1 TCP: Interfaces\{D7B99119-827F-49EC-9FD9-45D246F6F4FD} : DhcpNameServer = 10.0.0.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: klogon - c:\windows\system32\klogon.dll AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\adialhk.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\gordon\appdata\roaming\mozilla\firefox\profiles\mn9yqrg3.default\ FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\users\gordon\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll FF - plugin: c:\windows\system32\npmproxy.dll FF - plugin: c:\windows\system32\npOGPPlugin.dll . ============= SERVICES / DRIVERS =============== . R0 Achernar;Achernar - SCSI Command Filter Drivers;c:\windows\system32\drivers\Achernar.sys [2009-4-10 18432] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2008-7-9 20496] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-16 21504] R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-3-27 165160] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-2-22 2348352] R2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [2008-9-16 21504] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-2-9 382272] R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640] S2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe [2008-7-29 206088] S2 clientservice;Ccproxy;c:\windows\system32\svchost.exe -k netsvcs [2008-9-16 21504] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 lfsfilt;MREMP50;c:\windows\system32\svchost.exe -k netsvcs [2008-9-16 21504] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-2-29 158856] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-6 257696] S3 CoachVid;CoachVid;c:\windows\system32\drivers\CoachVid.sys [2009-4-6 45344] S3 Linksys_adapter;Linksys Adapter Network Driver;c:\windows\system32\drivers\AE2500vista.sys [2011-12-21 1073216] S3 MRV6X32U;Marvell TOPDOG 802.11n WLAN Driver for Vista x86 (USB8x);c:\windows\system32\drivers\MRVW24B.sys [2008-3-19 310016] S3 USB_RNDIS_VISTA;Westell WireSpeed Dual Connect Modem;c:\windows\system32\drivers\usb8023.sys [2009-10-20 15872] S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648] S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 WT6563F;PS3 ISP Update;c:\windows\system32\drivers\WT6563F.sys [2010-3-15 13120] . =============== Created Last 30 ================ . 2012-05-12 03:43:15 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys 2012-05-12 03:43:12 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-05-12 03:43:09 1404928 —-a-w- c:\program files\common files\microsoft shared\ink\InkObj.dll 2012-05-12 03:43:09 1218048 —-a-w- c:\program files\windows journal\NBDoc.DLL 2012-05-12 03:43:08 983040 —-a-w- c:\program files\windows journal\JNTFiltr.dll 2012-05-12 03:43:08 964608 —-a-w- c:\program files\windows journal\JNWDRV.dll 2012-05-12 03:43:08 936960 —-a-w- c:\program files\common files\microsoft shared\ink\journal.dll 2012-05-12 03:43:07 47104 —-a-w- c:\program files\windows journal\PDIALOG.exe 2012-05-12 03:42:57 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-05-12 03:42:57 1069056 —-a-w- c:\windows\system32\DWrite.dll 2012-05-12 03:42:56 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2012-05-12 03:42:55 683008 —-a-w- c:\windows\system32\d2d1.dll 2012-05-12 03:42:55 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2012-05-12 03:42:23 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-12 03:42:22 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-05-12 03:42:22 2044928 —-a-w- c:\windows\system32\win32k.sys 2012-04-16 20:04:54 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-16 20:04:54 172032 —-a-w- c:\windows\system32\wintrust.dll 2012-04-16 20:04:54 157696 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-16 20:04:54 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys . ==================== Find3M ==================== . 2012-05-15 02:51:42 0 –sha-w- c:\windows\system32\dds_trash_log.cmd 2012-05-05 13:41:55 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-05-05 13:41:55 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-03-07 18:53:26 16400 —-a-w- c:\windows\system32\drivers\LNonPnP.sys 2012-02-28 15:26:16 834048 —-a-w- c:\windows\system32\wininet.dll 2012-02-28 14:21:25 389632 —-a-w- c:\windows\system32\html.iec 2012-02-28 13:56:50 1383424 —-a-w- c:\windows\system32\mshtml.tlb . ============= FINISH: 23:22:08.51 ===============

Attachments:

Hi again,

One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

However, if you do not have the resources to reinstall your computer and would like me to attempt to clean it, I will be happy to do so. In that case, see the steps below.
Should you have any questions, please feel free to ask.


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.


Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
ComboFix 12-05-15.03 - gordon 05/15/2012 10:10:23.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3070.2012 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\programdata\eDiPjPoAhMp06504
c:\programdata\eDiPjPoAhMp06504\eDiPjPoAhMp06504
c:\programdata\eDiPjPoAhMp06504\eDiPjPoAhMp06504.exe
c:\programdata\fC31001EoAbG31001
c:\programdata\fC31001EoAbG31001\fC31001EoAbG31001
c:\programdata\fC31001EoAbG31001\fC31001EoAbG31001.exe
c:\users\gordon\AppData\Local\skc.exe
c:\users\gordon\AppData\Roaming\.#
c:\windows\$NtUninstallKB28152$\3238178042\cfg.ini
c:\windows\system32\0409\sp.Dll
c:\windows\system32\atmarpc.dll
c:\windows\system32\dds_trash_log.cmd
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\$NtUninstallKB28152$ . . . . Failed to delete
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_SPService
——-\Service_inorpc
.
.
((((((((((((((((((((((((( Files Created from 2012-04-15 to 2012-05-15 )))))))))))))))))))))))))))))))
.
.
2012-05-15 17:22 . 2012-05-15 17:24 ——– d—–w- c:\users\gordon\AppData\Local\temp
2012-05-12 03:43 . 2012-03-20 23:28 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys
2012-05-12 03:43 . 2012-03-30 12:39 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-05-12 03:43 . 2012-02-01 15:11 1218048 —-a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-05-12 03:43 . 2012-02-01 15:10 1404928 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2012-05-12 03:43 . 2012-02-01 15:10 983040 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-05-12 03:43 . 2012-02-01 15:10 964608 —-a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-05-12 03:43 . 2012-02-01 15:10 936960 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-12 03:43 . 2012-02-01 13:58 47104 —-a-w- c:\program files\Windows Journal\PDIALOG.exe
2012-05-12 03:42 . 2012-03-01 14:46 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-05-12 03:42 . 2012-02-29 13:41 1069056 —-a-w- c:\windows\system32\DWrite.dll
2012-05-12 03:42 . 2012-02-29 14:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-05-12 03:42 . 2012-03-01 14:46 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-05-12 03:42 . 2012-02-29 13:44 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-05-12 03:42 . 2012-04-03 08:16 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-12 03:42 . 2012-04-03 08:16 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-12 03:42 . 2012-04-02 13:36 2044928 —-a-w- c:\windows\system32\win32k.sys
2012-04-27 12:56 . 2012-04-27 12:56 ——– d—–w- c:\program files\Common Files\Skype
2012-04-16 20:04 . 2012-02-29 15:11 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-16 20:04 . 2012-02-29 15:11 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-04-16 20:04 . 2012-02-29 15:09 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-16 20:04 . 2012-02-29 13:32 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-05 13:41 . 2012-04-07 05:37 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-05 13:41 . 2011-05-17 18:56 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-07 18:53 . 2012-01-05 15:47 16400 —-a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-02-28 15:26 . 2012-04-10 22:21 834048 —-a-w- c:\windows\system32\wininet.dll
2012-02-28 14:21 . 2012-04-10 22:21 389632 —-a-w- c:\windows\system32\html.iec
2012-02-28 13:56 . 2012-04-10 22:21 1383424 —-a-w- c:\windows\system32\mshtml.tlb
2012-03-13 04:39 . 2012-04-15 07:34 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-15 2407184]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-08 206088]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WN121T Smart Wizard.lnk - c:\program files\NETGEAR\WN121T\wn121t.exe [2007-8-10 1691648]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk
backup=c:\windows\pss\Snapfish Media Detector.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotDeletingC6572]
del [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotDeletingD9029]
del [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-04-20 19:48 58656 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-11-02 07:25 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
2008-07-11 22:50 19968 —-a-w- c:\windows\System32\Ctxfihlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 06:33 125952 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
2011-10-07 09:40 1387288 —-a-w- c:\program files\Logitech\SetPointP\SetPoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
2006-09-28 13:42 65536 —-a-w- c:\hp\support\hpsysdrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-24 23:06 1840424 —-a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-01-17 01:22 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2009-06-17 16:55 55824 —-a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon]
2007-12-14 00:43 2051096 —-a-w- c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LGDCore]
2007-12-14 00:57 2095640 —-a-w- c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2008-08-15 00:11 565008 —-a-w- c:\program files\Common Files\Logishrd\LComMgr\Communications_Helper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxMenuMgr]
2009-03-27 22:53 181544 —-a-w- c:\program files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-06-08 16:31 2221352 —-a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2012-02-10 03:02 3881792 —-a-w- c:\windows\System32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2012-02-10 03:00 108352 —-a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2012-02-10 03:00 2719040 —-a-w- c:\windows\System32\nvsvc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 22:28 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SnapfishMediaDetector]
2007-03-02 21:55 1441792 —-a-w- c:\program files\Snapfish Media Detector\SnapfishMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotDeletingA5836]
2006-11-02 07:09 50648 —-a-w- c:\windows\System32\COMMAND.COM
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 18:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiSpywareOverride"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
S0 Achernar;Achernar - SCSI Command Filter Drivers;c:\windows\System32\Drivers\Achernar.sys [2007-02-05 18432]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ldlcserv
lfsfilt
us30service
O2SCBUS
SE2Bobex
dnetc
ATKFUSService
jsdaemon
iaantmon
Accelerometer
vaiomediaplatform-videoserver-appserver
Intels51
isamsmt
inorpc
fsaua
ltmodem5
fsaa
websenserealtimeanalyzer
lcs
clientservice
BCMModem
spcstb
s117obex
USIUDF
ipcsvc
Cinemsup
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 13:41]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = 10.0.0.1
FF - ProfilePath - c:\users\gordon\AppData\Roaming\Mozilla\Firefox\Profiles\mn9yqrg3.default\
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{96AFBE69-C3B0-4b00-8578-D933D2896EE2} - (no file)
MSConfigStartUp-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\FlashUtil10k_Plugin.exe
MSConfigStartUp-HPAdvisor - c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
MSConfigStartUp-VeohPlugin - c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
AddRemove-Veoh Web Player Beta - c:\program files\Veoh Networks\VeohWebPlayer\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-15 10:29
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\windows\system32\wbem\Performance\WmiApRpl_new.ini 25494 bytes
c:\users\gordon\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 2
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1891602936-3168947478-3105343759-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:3a,36,e7,b3,cb,11,d1,e4,f2,15,5e,ba,2e,45,c5,e7,a5,81,54,9a,39,f9,0c,
c5,88,e7,72,6b,40,db,14,b7,1a,dc,10,8a,f9,d5,9c,ca,1c,f5,ba,ca,5d,22,9e,ca,\
"??"=hex:d2,8a,3d,7f,d6,ee,ff,ab,38,51,7b,8c,dc,d7,d2,0c
.
[HKEY_USERS\S-1-5-21-1891602936-3168947478-3105343759-1000\Software\SecuROM\License information*]
"datasecu"=hex:08,8f,8b,c7,9a,fe,86,50,2f,ea,d6,9a,ff,d6,ad,e7,2b,b7,54,cd,c0,
21,d1,d5,b0,d2,e3,4a,41,a9,05,f7,60,42,ba,fa,1e,89,d1,e5,0e,5b,d6,ac,8f,52,\
"rkeysecu"=hex:91,10,40,14,21,50,eb,12,66,05,84,60,6e,52,b2,d9
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(8792)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Completion time: 2012-05-15 10:32:29 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-15 17:32
.
Pre-Run: 17,477,414,912 bytes free
Post-Run: 17,152,045,056 bytes free
.
- - End Of File - - 45985C2ECEE4DB5BCA6F940F2B953CC1
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_21 Run by [removed] at 10:51:29 on 2012-05-15 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3070.1896 [GMT -7:00] . SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\Dwm.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\NETGEAR\WN121T\wn121t.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Windows\system32\IoctlSvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\mobsync.exe C:\Windows\System32\alg.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe C:\Windows\Explorer.exe C:\Windows\system32\notepad.exe C:\Program Files\Logitech\SetPointP\SetPoint.exe C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop uInternet Settings,ProxyOverride = *.local BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: {CA4520F3-AE13-4FB1-A513-58E23991C86D} - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wn121t\wn121t.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Download with &Media Finder - c:\program files\media finder\hook.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: intuit.com\ttlc DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab TCP: DhcpNameServer = 10.0.0.1 TCP: Interfaces\{3912B7E4-8932-4AFA-87AA-471DD2C676A0} : DhcpNameServer = 75.75.75.75 75.75.76.76 TCP: Interfaces\{7B5A7321-11B0-464D-BA23-3A74381B731E} : DhcpNameServer = 192.168.1.1 192.168.1.1 TCP: Interfaces\{BEF6FFD8-3996-406E-992D-5DAE7FA63F59} : DhcpNameServer = 192.168.1.1 192.168.1.1 TCP: Interfaces\{D7B99119-827F-49EC-9FD9-45D246F6F4FD} : DhcpNameServer = 10.0.0.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: klogon - c:\windows\system32\klogon.dll AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd.dll c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll c:\progra~1\kasper~1\kasper~1\adialhk.dll c:\progra~1\kasper~1\kasper~1\kloehk.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\gordon\appdata\roaming\mozilla\firefox\profiles\mn9yqrg3.default\ FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\users\gordon\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll FF - plugin: c:\windows\system32\npmproxy.dll FF - plugin: c:\windows\system32\npOGPPlugin.dll . ============= SERVICES / DRIVERS =============== . R0 Achernar;Achernar - SCSI Command Filter Drivers;c:\windows\system32\drivers\Achernar.sys [2009-4-10 18432] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2008-7-9 20496] R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe [2008-7-29 206088] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-16 21504] R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-3-27 165160] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-2-22 2348352] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-2-9 382272] R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640] S2 clientservice;Ccproxy;c:\windows\system32\svchost.exe -k netsvcs [2008-9-16 21504] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 lfsfilt;MREMP50;c:\windows\system32\svchost.exe -k netsvcs [2008-9-16 21504] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-2-29 158856] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-6 257696] S3 CoachVid;CoachVid;c:\windows\system32\drivers\CoachVid.sys [2009-4-6 45344] S3 Linksys_adapter;Linksys Adapter Network Driver;c:\windows\system32\drivers\AE2500vista.sys [2011-12-21 1073216] S3 MRV6X32U;Marvell TOPDOG 802.11n WLAN Driver for Vista x86 (USB8x);c:\windows\system32\drivers\MRVW24B.sys [2008-3-19 310016] S3 USB_RNDIS_VISTA;Westell WireSpeed Dual Connect Modem;c:\windows\system32\drivers\usb8023.sys [2009-10-20 15872] S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648] S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-05-15 17:32:31 ——– d—–w- c:\users\gordon\appdata\local\temp 2012-05-15 17:24:55 ——– d—–w- C:\$RECYCLE.BIN 2012-05-15 17:00:22 ——– d—–w- C:\ComboFix 2012-05-15 16:37:09 98816 —-a-w- c:\windows\sed.exe 2012-05-15 16:37:09 518144 —-a-w- c:\windows\SWREG.exe 2012-05-15 16:37:09 256000 —-a-w- c:\windows\PEV.exe 2012-05-15 16:37:09 208896 —-a-w- c:\windows\MBR.exe 2012-05-12 03:43:15 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys 2012-05-12 03:43:12 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-05-12 03:43:09 1404928 —-a-w- c:\program files\common files\microsoft shared\ink\InkObj.dll 2012-05-12 03:43:09 1218048 —-a-w- c:\program files\windows journal\NBDoc.DLL 2012-05-12 03:43:08 983040 —-a-w- c:\program files\windows journal\JNTFiltr.dll 2012-05-12 03:43:08 964608 —-a-w- c:\program files\windows journal\JNWDRV.dll 2012-05-12 03:43:08 936960 —-a-w- c:\program files\common files\microsoft shared\ink\journal.dll 2012-05-12 03:43:07 47104 —-a-w- c:\program files\windows journal\PDIALOG.exe 2012-05-12 03:42:57 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-05-12 03:42:57 1069056 —-a-w- c:\windows\system32\DWrite.dll 2012-05-12 03:42:56 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2012-05-12 03:42:55 683008 —-a-w- c:\windows\system32\d2d1.dll 2012-05-12 03:42:55 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2012-05-12 03:42:23 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-12 03:42:22 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-05-12 03:42:22 2044928 —-a-w- c:\windows\system32\win32k.sys 2012-04-16 20:04:54 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-16 20:04:54 172032 —-a-w- c:\windows\system32\wintrust.dll 2012-04-16 20:04:54 157696 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-16 20:04:54 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys . ==================== Find3M ==================== . 2012-05-05 13:41:55 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-05-05 13:41:55 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-03-07 18:53:26 16400 —-a-w- c:\windows\system32\drivers\LNonPnP.sys 2012-02-28 15:26:16 834048 —-a-w- c:\windows\system32\wininet.dll 2012-02-28 14:21:25 389632 —-a-w- c:\windows\system32\html.iec 2012-02-28 13:56:50 1383424 —-a-w- c:\windows\system32\mshtml.tlb . ============= FINISH: 10:51:48.51 ===============

Attachments:

Blade81 thank you for all your help so far. During this cleaning process I have noticed several Desktop.ini files in different places. 2 are on my desktop where as they were not there before so my attention got peaked and asking you should I be concerned?
Hi again,

During this cleaning process I have noticed several Desktop.ini files in different places. 2 are on my desktop where as they were not there before so my attention got peaked and asking you should I be concerned?

No need to be concerned about those :)


Open notepad and then copy and paste the bolded lines below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop.
@ECHO OFF
SWREG QUERY "HKLM\SYSTEM\CurrentControlSet\Services\ldlcserv" /s >Logit.txt
SWREG QUERY "HKLM\SYSTEM\CurrentControlSet\Services\lfsfilt" /s >>Logit.txt
SWREG QUERY "HKLM\SYSTEM\CurrentControlSet\Services\us30service" /s >>Logit.txt
START Logit.txt
DEL %0


Double-click on fixes.bat file to execute it. Notepad should open up. Post back its contents, please.
SteelWerX Registry Console Tool 2.0 Written by Bobbi Flekman 2006 © HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ldlcserv Type REG_DWORD 32 (0x20) Start REG_DWORD 2 (0x2) ErrorControl REG_DWORD 0 (0x0) ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs DisplayName REG_SZ Flashpnt ObjectName REG_SZ LocalSystem Description REG_EXPAND_SZ Flashpnt HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ldlcserv\Parameters ServiceDll REG_EXPAND_SZ %systemroot%\system32\AFGMp50.dll ServiceDllUnloadOnStop REG_DWORD 1 (0x1) SteelWerX Registry Console Tool 2.0 Written by Bobbi Flekman 2006 © HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lfsfilt Type REG_DWORD 32 (0x20) Start REG_DWORD 2 (0x2) ErrorControl REG_DWORD 0 (0x0) ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs DisplayName REG_SZ MREMP50 ObjectName REG_SZ LocalSystem Description REG_EXPAND_SZ MREMP50 HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lfsfilt\Parameters ServiceDll REG_EXPAND_SZ %systemroot%\system32\prepdrvr.dll ServiceDllUnloadOnStop REG_DWORD 1 (0x1) SteelWerX Registry Console Tool 2.0 Written by Bobbi Flekman 2006 © HKEY_LOCAL_MACHINE\system\currentcontrolset\services\us30service Type REG_DWORD 32 (0x20) Start REG_DWORD 2 (0x2) ErrorControl REG_DWORD 0 (0x0) ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs DisplayName REG_SZ USBMN1X1 ObjectName REG_SZ LocalSystem Description REG_EXPAND_SZ USBMN1X1 HKEY_LOCAL_MACHINE\system\currentcontrolset\services\us30service\Parameters ServiceDll REG_EXPAND_SZ %systemroot%\system32\wmiaprpl.dll ServiceDllUnloadOnStop REG_DWORD 1 (0x1)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI