This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware, possible Rookit and/or google redirect [Solved]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Well, they got me. Those jerks! I'm having three separate recurring ping.exe's appear in task manager, web pages will randomly popup with super long url's that seem like garbage text. Can't access my win 7 firewall anymore and can't edit it. Sometimes the page I try to access will take me to another page as described above. Sometimes it opens a new window to some weird facebook survey.

I'm running win 7 64 and firefox.

I know what gave me the virus. They all came from this webpage:

http://www.crackinn.com/n/r/n/sibelius+7/

I'm sure everyone says this, but I really did buy Sibelius 7, the box is in front of me right now. It wouldn't accept my previous siblius 5 serial, which yes I did buy legit, and I couldn't return 7 after purchase. After spending all day, I found out that there is no real live person in customer support, only computers. So, that's why I went to this site. I wasn't about to lose the hundreds I paid for this software. I downloaded and ran the executables, and the exe files just disappeared after running. I did this for three different versions, thinking it was a win.rar problem or something I did wrong.
;-(
Busted, they got me.

Here's my OTL:

OTL .txt:

OTL logfile created on: 5/18/2012 10:42:22 PM - Run 2
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Users\Boosh\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.12 Gb Available Physical Memory | 68.61% Memory free
11.99 Gb Paging File | 10.24 Gb Available in Paging File | 85.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 878.09 Gb Free Space | 94.27% Space Free | Partition Type: NTFS
Drive G: | 2794.52 Gb Total Space | 2021.09 Gb Free Space | 72.32% Space Free | Partition Type: NTFS
Drive H: | 2.93 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SUCKA | User Name: Boosh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Boosh\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
PRC - C:\Windows\SysWOW64\PING.EXE (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (RichVideo64) Cyberlink RichVideo64 Service(CRVS) – C:\Program Files\CyberLink\Shared files\RichVideo64.exe ()
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (simptcp) – C:\Windows\SysNative\TCPSVCS.EXE (Microsoft Corporation)
SRV:64bit: - (SNMP) – C:\Windows\SysNative\snmp.exe (Microsoft Corporation)
SRV - (Application Updater) – C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (simptcp) – C:\Windows\SysWOW64\TCPSVCS.EXE (Microsoft Corporation)
SRV - (SNMP) – C:\Windows\SysWOW64\snmp.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (SCDEmu) – C:\Windows\SysWow64\drivers\scdemu.sys (PowerISO Computing, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=971163"
FF - prefs.js..browser.startup.homepage: "google.com"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/04/30 05:09:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 10:28:56 | 000,000,000 | —D | M]

[2012/04/30 05:07:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Boosh\AppData\Roaming\Mozilla\Extensions
[2012/05/17 22:21:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Boosh\AppData\Roaming\Mozilla\Firefox\Profiles\hu34jv9o.default\extensions
[2012/04/30 05:11:24 | 000,000,000 | —D | M] (LavaFox V2) – C:\Users\Boosh\AppData\Roaming\Mozilla\Firefox\Profiles\hu34jv9o.default\extensions\[removed]
[2012/04/30 05:18:18 | 000,000,000 | —D | M] (SpeedFox) – C:\Users\Boosh\AppData\Roaming\Mozilla\Firefox\Profiles\hu34jv9o.default\extensions\jid1-uabu5A9hduqzCw@jetpack
[2012/04/30 05:09:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/04/30 05:18:23 | 000,020,628 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\{0C8FBD76-BDEB-4C52-9B24-D587CE7B9DC3}.XPI
[2012/04/30 05:18:23 | 000,108,965 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\{1280606B-2510-4FE0-97EF-9B5A22EAFE80}.XPI
[2012/04/30 05:18:23 | 000,079,135 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\{1A2D0EC4-75F5-4C91-89C4-3656F6E44B68}.XPI
[2012/04/30 05:15:16 | 000,097,169 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\{3D7EB24F-2740-49DF-8937-200B1CC08F8A}.XPI
[2012/04/30 05:15:16 | 000,039,512 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\{B1DF372D-8B32-4C7D-B6B4-9C5B78CF6FB1}.XPI
[2012/04/30 05:15:16 | 000,634,964 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/04/30 05:18:23 | 000,434,392 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
[2012/04/30 05:18:23 | 000,013,152 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\{E6C1199F-E687-42DA-8C24-E7770CC3AE66}.XPI
[2012/04/30 05:15:16 | 000,035,733 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\[removed]
[2012/04/30 05:15:16 | 000,018,146 | —- | M] () (No name found) – C:\USERS\BOOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HU34JV9O.DEFAULT\EXTENSIONS\[removed]
[2012/04/20 18:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/04/20 18:18:25 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/04/20 18:18:25 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4 - HKLM..\Run: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{430B0340-D95E-4381-B70B-6BD6761D0A44}: DhcpNameServer = [removed] [removed] [removed]
O18:64bit: - Protocol\Handler\cdo - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\SYSTEM32\Userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/04 09:47:18 | 000,000,097 | R— | M] () - H:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{5255b7a4-9e10-11e1-9e14-bcaec54cee55}\Shell - "" = AutoRun
O33 - MountPoints2\{5255b7a4-9e10-11e1-9e14-bcaec54cee55}\Shell\AutoRun\command - "" = D:\setup.exe -a
O33 - MountPoints2\{f2dae624-92b1-11e1-a90e-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f2dae624-92b1-11e1-a90e-806e6f6e6963}\Shell\AutoRun\command - "" = H:\start.exe – [2011/07/04 09:47:18 | 002,360,503 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\divx.dll (DivXNetworks, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/05/18 19:22:41 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\Boosh\Desktop\OTL.exe
[2012/05/18 19:20:31 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2012/05/18 19:19:02 | 004,499,090 | R— | C] (Swearware) – C:\Users\Boosh\Desktop\ComboFix.exe
[2012/05/18 00:37:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid
[2012/05/18 00:36:51 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Sibelius Example Scores
[2012/05/18 00:16:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Doomsday
[2012/05/17 23:20:18 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\yang
[2012/05/17 23:12:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Duke3D
[2012/05/17 21:46:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebKeySoft
[2012/05/17 21:46:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\WebKeySoft
[2012/05/17 20:07:55 | 000,000,000 | —D | C] – C:\ProgramData\comodo
[2012/05/17 20:07:55 | 000,000,000 | —D | C] – C:\Program Files\Comodo
[2012/05/17 15:57:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2012/05/17 14:50:30 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/05/17 14:36:48 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\%APPDATA%
[2012/05/17 13:29:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Avid
[2012/05/17 12:59:45 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Sibelius Software
[2012/05/17 12:54:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sibelius Software
[2012/05/15 17:54:18 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PowerISO
[2012/05/15 17:54:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
[2012/05/15 17:54:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\PowerISO
[2012/05/15 17:51:23 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Utilities
[2012/05/15 13:41:08 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\Easy CD-DA Extractor
[2012/05/15 13:41:05 | 000,000,000 | —D | C] – C:\ProgramData\Easy CD-DA Extractor
[2012/05/15 13:41:04 | 000,000,000 | —D | C] – C:\Windows\Easy CD-DA Extractor 12.0
[2012/05/15 13:41:04 | 000,000,000 | —D | C] – C:\Program Files\Easy CD-DA Extractor 12
[2012/05/14 18:17:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hardware
[2012/05/14 18:16:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Multimedia
[2012/05/14 18:16:45 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities
[2012/05/10 19:02:47 | 001,568,768 | —- | C] (Pegasus Imaging Corp.) – C:\Windows\SysWow64\ImagX7.dll
[2012/05/10 19:02:47 | 000,476,320 | —- | C] (Pegasus Imaging Corp.) – C:\Windows\SysWow64\ImagXpr7.dll
[2012/05/10 19:02:47 | 000,471,040 | —- | C] (Pegasus Imaging Corp.) – C:\Windows\SysWow64\ImagXRA7.dll
[2012/05/10 19:02:47 | 000,262,144 | —- | C] (Pegasus Imaging Corp.) – C:\Windows\SysWow64\ImagXR7.dll
[2012/05/10 19:02:47 | 000,155,648 | —- | C] (Ahead Software Gmbh) – C:\Windows\SysWow64\NeroCheck.exe
[2012/05/10 19:02:47 | 000,106,496 | —- | C] (Pegasus Software) – C:\Windows\SysWow64\TwnLib20.dll
[2012/05/10 19:02:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Ahead
[2012/05/10 19:02:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ahead
[2012/05/09 01:24:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Digidesign
[2012/05/08 12:59:26 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\AdobeUM
[2012/05/07 23:17:50 | 000,419,488 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/07 23:17:50 | 000,070,304 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/05/07 23:17:49 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/05/07 17:38:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Vstplugins
[2012/05/07 17:38:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony
[2012/05/07 17:34:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony Setup
[2012/05/07 17:02:58 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Publish Providers
[2012/05/07 16:55:15 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2012/05/04 00:04:31 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Adobe
[2012/05/04 00:04:31 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\Adobe
[2012/05/03 23:48:10 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\ElevatedDiagnostics
[2012/05/03 19:16:38 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2012/05/02 16:01:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\uTorrent
[2012/05/02 16:01:09 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\uTorrent
[2012/05/02 01:31:36 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\dvdcss
[2012/04/30 16:49:01 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\vlc
[2012/04/30 16:47:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2012/04/30 12:10:39 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2012/04/30 12:07:30 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\Oblivion
[2012/04/30 06:41:00 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Macromedia
[2012/04/30 06:10:22 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Apple Computer
[2012/04/30 06:10:22 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\Apple Computer
[2012/04/30 06:10:08 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2012/04/30 06:10:08 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2012/04/30 06:10:08 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2012/04/30 06:09:57 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/04/30 06:09:56 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/04/30 06:09:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/04/30 06:09:56 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/04/30 06:09:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2012/04/30 06:08:58 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/04/30 06:08:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2012/04/30 05:52:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bethesda Softworks
[2012/04/30 05:51:58 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2012/04/30 05:51:58 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2012/04/30 05:51:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2012/04/30 05:31:41 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Kyle's jury
[2012/04/30 05:31:41 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Invoices
[2012/04/30 05:31:41 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Excel
[2012/04/30 05:31:41 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Codemasters
[2012/04/30 05:31:41 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Budget
[2012/04/30 05:31:41 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\band Bios
[2012/04/30 05:31:39 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Writings
[2012/04/30 05:31:37 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\word docs
[2012/04/30 05:31:36 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Taxes
[2012/04/30 05:31:33 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\school
[2012/04/30 05:31:33 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Scanned Music
[2012/04/30 05:31:33 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\resume
[2012/04/30 05:31:33 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Pet care
[2012/04/30 05:31:33 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Pdf's
[2012/04/30 05:31:33 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\patent
[2012/04/30 05:31:33 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Nero Projects
[2012/04/30 05:31:32 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\My Games
[2012/04/30 05:31:30 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\My eBooks
[2012/04/30 05:31:30 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\my book
[2012/04/30 05:31:30 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Ligos
[2012/04/30 05:26:27 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\Scores
[2012/04/30 05:25:19 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Avid
[2012/04/30 05:25:19 | 000,000,000 | —D | C] – C:\ProgramData\Avid
[2012/04/30 05:25:19 | 000,000,000 | —D | C] – C:\Program Files\Avid
[2012/04/30 05:23:51 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\start
[2012/04/30 05:21:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mpeg2Decoder
[2012/04/30 05:21:13 | 000,000,000 | —D | C] – C:\Users\Boosh\Desktop\Spigot-Suspect
[2012/04/30 05:21:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\pdfforge Toolbar
[2012/04/30 05:21:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Application Updater
[2012/04/30 05:20:50 | 000,662,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSCOMCT2.OCX
[2012/04/30 05:20:50 | 000,137,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSMAPI32.OCX
[2012/04/30 05:20:49 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSMPIDE.DLL
[2012/04/30 05:20:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\PDFCreator
[2012/04/30 05:09:31 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/04/30 05:09:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2012/04/30 05:07:24 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Mozilla
[2012/04/30 05:07:24 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\Mozilla
[2012/04/30 05:07:05 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2012/04/30 05:06:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/04/30 05:06:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2012/04/30 05:06:01 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2012/04/30 05:05:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2012/04/30 05:05:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Transcribe!
[2012/04/30 05:02:03 | 000,086,016 | —- | C] (MindVision Software) – C:\Windows\unvise32.exe
[2012/04/30 05:02:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\DivX
[2012/04/30 04:58:11 | 000,000,000 | —D | C] – C:\Users\Boosh\Documents\CyberLink
[2012/04/30 04:57:21 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\CyberLink
[2012/04/30 04:57:21 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2012/04/30 04:55:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012/04/30 04:55:55 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2012/04/30 04:55:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2012/04/30 04:55:34 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\Apple
[2012/04/30 04:55:33 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2012/04/30 04:55:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Cyberlink
[2012/04/30 04:54:11 | 000,000,000 | —D | C] – C:\Program Files\CyberLink
[2012/04/30 04:53:28 | 000,000,000 | —D | C] – C:\ProgramData\Temp
[2012/04/30 04:49:33 | 000,000,000 | —D | C] – C:\Windows\Easy CD-DA Extractor
[2012/04/30 04:47:04 | 000,000,000 | —D | C] – C:\Windows\Panther
[2012/04/30 04:46:49 | 000,000,000 | -HSD | C] – C:\Boot
[2012/04/30 04:42:23 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Sony
[2012/04/30 04:42:23 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\Sony
[2012/04/30 04:36:06 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2012/04/30 04:36:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinZip
[2012/04/30 04:35:27 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/04/30 04:35:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2012/04/30 04:27:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
[2012/04/30 04:27:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft ActiveSync
[2012/04/30 04:27:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Designer
[2012/04/30 04:27:14 | 000,000,000 | —D | C] – C:\Windows\ShellNew
[2012/04/30 04:27:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2012/04/30 04:21:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Renesas Electronics
[2012/04/30 04:19:57 | 000,333,928 | —- | C] (Realtek ) – C:\Windows\SysNative\drivers\Rt64win7.sys
[2012/04/30 04:19:57 | 000,107,552 | —- | C] (Realtek Semiconductor Corporation) – C:\Windows\SysNative\RTNUninst64.dll
[2012/04/30 04:19:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2012/04/30 04:19:28 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2012/04/30 04:18:16 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2012/04/30 04:18:13 | 000,038,456 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\usbfilter.sys
[2012/04/30 04:18:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012/04/30 04:18:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD
[2012/04/30 04:18:09 | 000,016,440 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\SysNative\drivers\AtiPcie.sys
[2012/04/30 04:17:42 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2012/04/30 04:17:41 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2012/04/30 04:16:47 | 000,000,000 | —D | C] – C:\Program Files\ATI Technologies
[2012/04/30 03:57:49 | 000,000,000 | R–D | C] – C:\Users\Boosh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/04/30 03:57:49 | 000,000,000 | R–D | C] – C:\Users\Boosh\Searches
[2012/04/30 03:57:49 | 000,000,000 | R–D | C] – C:\Users\Boosh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/04/30 03:57:48 | 000,000,000 | -H-D | C] – C:\Users\Boosh\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/04/30 03:57:36 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Identities
[2012/04/30 03:57:30 | 000,000,000 | R–D | C] – C:\Users\Boosh\Contacts
[2012/04/30 03:57:28 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\VirtualStore
[2012/04/30 03:57:13 | 000,000,000 | –SD | C] – C:\Users\Boosh\AppData\Roaming\Microsoft
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\Videos
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\Saved Games
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\Pictures
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\Music
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\Links
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\Favorites
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\Downloads
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\Documents
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\Desktop
[2012/04/30 03:57:13 | 000,000,000 | R–D | C] – C:\Users\Boosh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\AppData\Local\Temporary Internet Files
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\Templates
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\Start Menu
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\SendTo
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\Recent
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\PrintHood
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\NetHood
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\Documents\My Videos
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\Documents\My Pictures
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\Documents\My Music
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\My Documents
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\Local Settings
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\AppData\Local\History
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\Cookies
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\Application Data
[2012/04/30 03:57:13 | 000,000,000 | -HSD | C] – C:\Users\Boosh\AppData\Local\Application Data
[2012/04/30 03:57:13 | 000,000,000 | -H-D | C] – C:\Users\Boosh\AppData
[2012/04/30 03:57:13 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\Temp
[2012/04/30 03:57:13 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Local\Microsoft
[2012/04/30 03:57:13 | 000,000,000 | —D | C] – C:\Users\Boosh\AppData\Roaming\Media Center Programs
[2012/04/30 03:50:53 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2012/04/30 03:48:41 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2012/04/30 01:57:56 | 000,000,000 | -HSD | C] – C:\Recovery
[2012/04/30 01:50:59 | 000,000,000 | -HSD | C] – C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2012/05/18 22:33:54 | 000,625,664 | —- | M] () – C:\Users\Boosh\Desktop\dds.scr
[2012/05/18 20:17:44 | 000,000,933 | —- | M] () – C:\Users\Public\Desktop\Sibelius 7.lnk
[2012/05/18 19:22:42 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\Boosh\Desktop\OTL.exe
[2012/05/18 19:19:08 | 004,499,090 | R— | M] (Swearware) – C:\Users\Boosh\Desktop\ComboFix.exe
[2012/05/18 17:41:39 | 000,016,944 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/18 17:41:39 | 000,016,944 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/18 17:40:13 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/05/18 17:40:13 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/05/18 17:40:13 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/05/18 17:34:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/18 17:34:23 | 535,437,311 | -HS- | M] () – C:\hiberfil.sys
[2012/05/18 10:29:21 | 000,400,744 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/05/18 00:16:20 | 000,001,162 | —- | M] () – C:\Users\Boosh\Desktop\Doomsday Engine.lnk
[2012/05/17 23:18:19 | 000,001,163 | —- | M] () – C:\Users\Boosh\Desktop\yang.exe - Shortcut.lnk
[2012/05/17 23:12:50 | 000,001,407 | —- | M] () – C:\Users\Boosh\Desktop\eduke32.exe - Shortcut.lnk
[2012/05/17 15:57:45 | 000,002,975 | —- | M] () – C:\Users\Boosh\Desktop\HiJackThis.lnk
[2012/05/17 14:35:35 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/17 14:35:35 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/05/17 13:17:51 | 018,076,701 | —- | M] () – C:\Users\Boosh\Desktop\songsforinternationalsunday52012.zip
[2012/05/15 17:56:04 | 000,001,019 | —- | M] () – C:\Users\Boosh\Desktop\PowerISO.lnk
[2012/05/15 13:41:05 | 000,001,812 | —- | M] () – C:\Users\Public\Desktop\Easy CD-DA Extractor.lnk
[2012/05/14 18:52:54 | 000,000,837 | —- | M] () – C:\Users\Boosh\Desktop\DMA.lnk
[2012/05/14 17:40:06 | 000,001,791 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/05/10 13:35:03 | 000,232,506 | —- | M] () – C:\Users\Boosh\Documents\PDR.dmp
[2012/05/08 12:47:17 | 000,000,604 | -H– | M] () – C:\Program Files (x86)\_Z2
[2012/05/08 12:34:57 | 000,000,750 | —- | M] () – C:\Users\Boosh\Desktop\Lessons.lnk
[2012/05/07 17:49:51 | 000,001,629 | —- | M] () – C:\Users\Boosh\Desktop\Forge90.exe - Shortcut.lnk
[2012/05/07 17:23:29 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\CyberLink PowerDirector.lnk
[2012/05/05 14:44:31 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/05 14:42:09 | 000,000,644 | —- | M] () – C:\Users\Boosh\Desktop\Charts.lnk
[2012/05/05 11:57:53 | 000,000,000 | RHS- | M] () – C:\winx.ld
[2012/05/05 11:57:52 | 000,203,836 | RHS- | M] () – C:\grldr
[2012/05/04 16:45:56 | 000,000,023 | —- | M] () – C:\Windows\BlendSettings.ini
[2012/05/03 19:16:46 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/05/03 13:15:38 | 000,000,635 | —- | M] () – C:\Users\Boosh\Desktop\Tunes.lnk
[2012/05/02 01:40:33 | 000,002,055 | —- | M] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2012/05/02 01:26:55 | 000,095,536 | —- | M] () – C:\Users\Boosh\Documents\Hava Nagila - Axxotle Edit.mp3.sfk
[2012/04/30 16:47:27 | 000,000,770 | —- | M] () – C:\Users\Boosh\Desktop\TV Shows.lnk
[2012/04/30 05:09:33 | 000,002,056 | —- | M] () – C:\Users\Boosh\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/04/30 05:09:33 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/30 05:05:15 | 000,000,980 | —- | M] () – C:\Users\Boosh\Desktop\Transcribe!.lnk
[2012/04/30 04:46:52 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/04/30 04:27:59 | 000,000,376 | —- | M] () – C:\Windows\ODBC.INI
[2012/04/30 04:20:17 | 000,001,769 | —- | M] () – C:\Windows\Language_trs.ini
[2012/04/30 04:15:12 | 000,029,192 | —- | M] () – C:\Windows\Ascd_tmp.ini
[2012/04/30 03:51:43 | 000,042,045 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2012/04/30 03:51:43 | 000,042,045 | —- | M] () – C:\Windows\SysNative\license.rtf

========== Files Created - No Company Name ==========

[2012/05/18 22:33:53 | 000,625,664 | —- | C] () – C:\Users\Boosh\Desktop\dds.scr
[2012/05/18 00:37:55 | 000,000,933 | —- | C] () – C:\Users\Public\Desktop\Sibelius 7.lnk
[2012/05/18 00:16:20 | 000,001,162 | —- | C] () – C:\Users\Boosh\Desktop\Doomsday Engine.lnk
[2012/05/17 23:18:19 | 000,001,163 | —- | C] () – C:\Users\Boosh\Desktop\yang.exe - Shortcut.lnk
[2012/05/17 23:12:50 | 000,001,407 | —- | C] () – C:\Users\Boosh\Desktop\eduke32.exe - Shortcut.lnk
[2012/05/17 15:57:45 | 000,002,975 | —- | C] () – C:\Users\Boosh\Desktop\HiJackThis.lnk
[2012/05/17 14:47:06 | 018,076,701 | —- | C] () – C:\Users\Boosh\Desktop\songsforinternationalsunday52012.zip
[2012/05/15 17:54:18 | 000,001,019 | —- | C] () – C:\Users\Boosh\Desktop\PowerISO.lnk
[2012/05/15 13:41:05 | 000,001,812 | —- | C] () – C:\Users\Public\Desktop\Easy CD-DA Extractor.lnk
[2012/05/14 18:52:54 | 000,000,837 | —- | C] () – C:\Users\Boosh\Desktop\DMA.lnk
[2012/05/08 12:47:17 | 000,000,604 | -H– | C] () – C:\Program Files (x86)\_Z2
[2012/05/08 12:34:57 | 000,000,750 | —- | C] () – C:\Users\Boosh\Desktop\Lessons.lnk
[2012/05/08 01:10:50 | 000,232,506 | —- | C] () – C:\Users\Boosh\Documents\PDR.dmp
[2012/05/07 17:49:51 | 000,001,629 | —- | C] () – C:\Users\Boosh\Desktop\Forge90.exe - Shortcut.lnk
[2012/05/07 17:23:29 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\CyberLink PowerDirector.lnk
[2012/05/05 14:44:31 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/05 14:42:09 | 000,000,644 | —- | C] () – C:\Users\Boosh\Desktop\Charts.lnk
[2012/05/05 11:57:53 | 000,000,000 | RHS- | C] () – C:\winx.ld
[2012/05/05 11:57:52 | 000,203,836 | RHS- | C] () – C:\grldr
[2012/05/03 19:16:46 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/05/03 13:15:38 | 000,000,635 | —- | C] () – C:\Users\Boosh\Desktop\Tunes.lnk
[2012/05/02 01:40:33 | 000,002,055 | —- | C] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2012/05/02 01:26:51 | 000,095,536 | —- | C] () – C:\Users\Boosh\Documents\Hava Nagila - Axxotle Edit.mp3.sfk
[2012/04/30 17:53:29 | 000,000,023 | —- | C] () – C:\Windows\BlendSettings.ini
[2012/04/30 16:47:27 | 000,000,770 | —- | C] () – C:\Users\Boosh\Desktop\TV Shows.lnk
[2012/04/30 06:10:20 | 000,001,791 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/04/30 05:31:41 | 000,289,258 | —- | C] () – C:\Users\Boosh\Documents\gr_intent_to_graduate_form.pdf
[2012/04/30 05:31:41 | 000,026,360 | —- | C] () – C:\Users\Boosh\Documents\Azusa Light & Water _ Online Billing and Payment.pdf
[2012/04/30 05:31:41 | 000,012,158 | —- | C] () – C:\Users\Boosh\Documents\grad program.enl
[2012/04/30 05:31:41 | 000,009,639 | —- | C] () – C:\Users\Boosh\Documents\Jazz Instrument Ranges.gif
[2012/04/30 05:31:41 | 000,003,918 | —- | C] () – C:\Users\Boosh\Documents\Primo Bill Evans.nra
[2012/04/30 05:31:41 | 000,003,359 | —- | C] () – C:\Users\Boosh\Documents\Primo Shorter.nra
[2012/04/30 05:31:41 | 000,003,352 | —- | C] () – C:\Users\Boosh\Documents\Primo Tyner.nra
[2012/04/30 05:31:41 | 000,002,560 | —- | C] () – C:\Users\Boosh\Documents\Register Sound Forge.htm
[2012/04/30 05:31:41 | 000,000,000 | —- | C] () – C:\Users\Boosh\Documents\PDVD_MediaDisc.PlayList
[2012/04/30 05:31:41 | 000,000,000 | —- | C] () – C:\Users\Boosh\Documents\My EndNote Library.enl
[2012/04/30 05:31:39 | 156,312,576 | —- | C] () – C:\Users\Boosh\Documents\AlexOnBass.npp
[2012/04/30 05:31:39 | 000,147,968 | —- | C] () – C:\Users\Boosh\Documents\Alex Schedule.atw
[2012/04/30 05:31:39 | 000,018,758 | —- | C] () – C:\Users\Boosh\Documents\5 Star Jazz Data CD.nri
[2012/04/30 05:31:39 | 000,002,564 | —- | C] () – C:\Users\Boosh\Documents\Activate MP3 Plug-In.htm
[2012/04/30 05:20:50 | 000,087,040 | —- | C] () – C:\Windows\SysNative\pdfcmnnt.dll
[2012/04/30 05:06:48 | 000,002,056 | —- | C] () – C:\Users\Boosh\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/04/30 05:06:48 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/30 05:05:15 | 000,000,980 | —- | C] () – C:\Users\Boosh\Desktop\Transcribe!.lnk
[2012/04/30 04:46:52 | 000,008,192 | RHS- | C] () – C:\BOOTSECT.BAK
[2012/04/30 04:46:50 | 000,383,562 | RHS- | C] () – C:\bootmgr
[2012/04/30 04:27:59 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2012/04/30 04:19:57 | 000,074,272 | —- | C] () – C:\Windows\SysNative\RtNicProp64.dll
[2012/04/30 04:14:53 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2012/04/30 04:14:50 | 000,029,192 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2012/04/30 03:57:13 | 000,000,290 | —- | C] () – C:\Users\Boosh\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/04/30 03:57:13 | 000,000,272 | —- | C] () – C:\Users\Boosh\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/04/30 01:50:59 | 535,437,311 | -HS- | C] () – C:\hiberfil.sys

========== LOP Check ==========

[2012/05/09 01:24:55 | 000,000,000 | —D | M] – C:\Users\Boosh\AppData\Roaming\Avid
[2012/05/07 17:02:58 | 000,000,000 | —D | M] – C:\Users\Boosh\AppData\Roaming\Publish Providers
[2012/04/30 04:42:23 | 000,000,000 | —D | M] – C:\Users\Boosh\AppData\Roaming\Sony
[2012/05/18 20:14:45 | 000,000,000 | —D | M] – C:\Users\Boosh\AppData\Roaming\uTorrent
[2012/05/18 00:41:28 | 000,000,000 | —D | M] – C:\Users\Boosh\AppData\Roaming\yang
[2009/07/13 22:08:49 | 000,013,624 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2012/04/30 04:46:52 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/05/05 11:57:52 | 000,203,836 | RHS- | M] () – C:\grldr
[2012/05/18 17:34:23 | 535,437,311 | -HS- | M] () – C:\hiberfil.sys
[2012/05/18 17:34:24 | 2145,574,911 | -HS- | M] () – C:\pagefile.sys
[2012/05/05 11:57:53 | 000,000,000 | RHS- | M] () – C:\winx.ld

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2012/05/08 12:47:17 | 000,000,604 | -H– | M] () – C:\Program Files (x86)\_Z2

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/07/13 21:49:38 | 000,000,146 | -HS- | M] () – C:\Users\Boosh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/05/18 19:19:08 | 004,499,090 | R— | M] (Swearware) – C:\Users\Boosh\Desktop\ComboFix.exe
[2012/05/18 19:22:42 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\Boosh\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:C8B8CEBD

< End of report >



OTL Extras.txt:

OTL Extras logfile created on: 5/18/2012 7:24:44 PM - Run 1
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Users\Boosh\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.56 Gb Available Physical Memory | 75.97% Memory free
11.99 Gb Paging File | 10.61 Gb Available in Paging File | 88.47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 881.14 Gb Free Space | 94.59% Space Free | Partition Type: NTFS
Drive G: | 2794.52 Gb Total Space | 2020.48 Gb Free Space | 72.30% Space Free | Partition Type: NTFS
Drive H: | 2.93 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SUCKA | User Name: Boosh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl[@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html[@ = htmlfile] – Reg Error: Key error. File not found
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{64555D45-1F57-BF1D-1A5E-BFD4C8C0ADB4}" = ATI Catalyst Install Manager
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CF8FFD12-602B-422D-AF1D-511B411E7632}" = iTunes
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"Sibelius 7.0.0.23_is1" = Sibelius 7.0.0.23

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0743122B-5C12-4F99-A92F-9DCDBF7EE221}" = WebKeySoft Process Manager 2 Lite
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6842DCCB-2840-4E46-8AF3-BEA9CFF3455B}" = Sony Sound Forge 9.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{971CD5D9-FF9E-474F-8364-704DF9B4FCA6}" = pdfforge Toolbar v5.6
"{987B04C4-B5AC-4AD6-A7E9-8D681085B850}" = AMD USB Filter Driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{D533C9D4-ED96-4191-B9C3-279C0DD6BABA}" = Sony Noise Reduction Plug-In 2.0e
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{FBE64702-E893-4D55-BA5C-514AAF11CCC4}" = Sibelius 7 OpenType Fonts
"DivX Codec" = DivX Pro 5.0.3 Bundle
"Doomsday Engine_is1" = Doomsday Engine 1.9.8
"Easy CD-DA Extractor 12" = Easy CD-DA Extractor 12
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"Mozilla Firefox 12.0 (x86 en-US)" = Mozilla Firefox 12.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Mpeg2Decoder_is1" = Mpeg2Decoder 1.3
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"PowerISO" = PowerISO
"Transcribe!_is1" = Transcribe! 7.32
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.1
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/17/2012 6:05:12 PM | Computer Name = Sucka | Source = Application Error | ID = 1000
Description = Faulting application name: ping.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc964 Faulting module name: mshtml.dll, version: 8.0.7600.16385, time
stamp: 0x4a5bda8a Exception code: 0xc00000fd Fault offset: 0x000d6691 Faulting process
id: 0xb20 Faulting application start time: 0x01cd3478f8379fd9 Faulting application
path: C:\Windows\SysWOW64\ping.exe Faulting module path: C:\Windows\SysWOW64\mshtml.dll
Report
Id: 5f8c3f7c-a06c-11e1-9a5f-bcaec54cee55

Error - 5/17/2012 6:56:54 PM | Computer Name = Sucka | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "G:\Software\Programs\SoftonicDownloader_for_hijackthis.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 5/17/2012 6:57:02 PM | Computer Name = Sucka | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "G:\Software\Programs\SoftonicDownloader_for_hijackthis.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 5/17/2012 11:00:10 PM | Computer Name = Sucka | Source = Application Error | ID = 1000
Description = Faulting application name: ping.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc964 Faulting module name: mshtml.dll, version: 8.0.7600.16385, time
stamp: 0x4a5bda8a Exception code: 0xc00000fd Fault offset: 0x000d3a1b Faulting process
id: 0x24e0 Faulting application start time: 0x01cd34a2309f7cf9 Faulting application
path: C:\Windows\SysWOW64\ping.exe Faulting module path: C:\Windows\SysWOW64\mshtml.dll
Report
Id: 93ed68c6-a095-11e1-88bd-bcaec54cee55

Error - 5/18/2012 12:41:32 AM | Computer Name = Sucka | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "G:\Software\Programs\SoftonicDownloader_for_hijackthis.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 5/18/2012 12:43:25 AM | Computer Name = Sucka | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Boosh\Downloads\SoftonicDownloader_for_process-manager.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 5/18/2012 12:43:27 AM | Computer Name = Sucka | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Boosh\Downloads\SoftonicDownloader_for_process-manager.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 5/18/2012 12:43:33 AM | Computer Name = Sucka | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Boosh\Downloads\SoftonicDownloader_for_process-manager.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 5/18/2012 12:45:32 AM | Computer Name = Sucka | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "G:\Software\Programs\SoftonicDownloader_for_process-manager.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 5/18/2012 9:07:56 PM | Computer Name = Sucka | Source = Application Error | ID = 1000
Description = Faulting application name: ping.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc964 Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc00000fd Fault offset: 0x0002dd7e Faulting process
id: 0x134 Faulting application start time: 0x01cd355b58271916 Faulting application
path: C:\Windows\SysWOW64\ping.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report
Id: 10bb4b13-a14f-11e1-b8c9-bcaec54cee55

[ System Events ]
Error - 5/18/2012 1:32:12 AM | Computer Name = Sucka | Source = Service Control Manager | ID = 7034
Description = The Spybot S&D 2 Live Protection Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 5/18/2012 1:42:04 AM | Computer Name = Sucka | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\SCDEmu.SYS has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 5/18/2012 1:42:28 AM | Computer Name = Sucka | Source = SNMP | ID = 16713180
Description = The SNMP Service encountered an error while accessing the registry
key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.

Error - 5/18/2012 1:42:28 AM | Computer Name = Sucka | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SCDEmu

Error - 5/18/2012 1:28:49 PM | Computer Name = Sucka | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\SCDEmu.SYS has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 5/18/2012 1:29:33 PM | Computer Name = Sucka | Source = SNMP | ID = 16713180
Description = The SNMP Service encountered an error while accessing the registry
key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.

Error - 5/18/2012 1:29:33 PM | Computer Name = Sucka | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SCDEmu

Error - 5/18/2012 8:34:18 PM | Computer Name = Sucka | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\SCDEmu.SYS has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 5/18/2012 8:34:34 PM | Computer Name = Sucka | Source = SNMP | ID = 16713180
Description = The SNMP Service encountered an error while accessing the registry
key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.

Error - 5/18/2012 8:34:37 PM | Computer Name = Sucka | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SCDEmu


< End of report >


Hijackthis.log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:33:38 PM, on 5/18/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

–
End of file - 3772 bytes


DDS.txt:

.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 22:46:06.38 on Fri 05/18/2012
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.6142.3960 [GMT -7:00]
.
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\CyberLink\Shared files\RichVideo64.exe
C:\Windows\System32\tcpsvcs.exe
C:\Windows\System32\snmp.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\ping.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\ping.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\ping.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Boosh\Desktop\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
mRun: []
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
LSP: mswsock.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\microsoft shared\Web Folders\PKMCDO.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Boosh\AppData\Roaming\Mozilla\Firefox\Profiles\hu34jv9o.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS);C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2012-5-7 386344]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-4-26 83080]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-4-26 184968]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-4-30 333928]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2012-4-30 38456]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-30 129976]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-2-15 52736]
S4 Application Updater;Application Updater;C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe [2012-4-23 785304]
.
=============== Created Last 30 ================
.
2012-05-18 07:16:17 ——– d—–w- C:\Program Files (x86)\Doomsday
2012-05-18 06:20:18 ——– d—–w- C:\Users\Boosh\AppData\Roaming\yang
2012-05-18 06:12:42 ——– d—–w- C:\Program Files (x86)\Duke3D
2012-05-18 04:46:48 ——– d—–w- C:\Program Files (x86)\WebKeySoft
2012-05-18 03:07:55 ——– d—–w- C:\Program Files\Comodo
2012-05-18 03:07:55 ——– d—–w- C:\PROGRA~3\comodo
2012-05-17 22:57:45 388096 —-a-r- C:\Users\Boosh\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-05-17 22:57:45 ——– d—–w- C:\Program Files (x86)\Trend Micro
2012-05-17 21:50:30 ——– d—–w- C:\PROGRA~3\Spybot - Search & Destroy
2012-05-17 21:36:48 ——– d-sh–w- C:\Windows\SysWow64\%APPDATA%
2012-05-17 20:29:04 ——– d—–w- C:\Program Files (x86)\Avid
2012-05-17 19:59:45 ——– d—–w- C:\Users\Boosh\AppData\Roaming\Sibelius Software
2012-05-17 19:54:43 ——– d—–w- C:\Program Files (x86)\Sibelius Software
2012-05-16 00:54:18 ——– d—–w- C:\Program Files (x86)\PowerISO
2012-05-15 20:41:08 ——– d—–w- C:\Users\Boosh\AppData\Local\Easy CD-DA Extractor
2012-05-15 20:41:05 ——– d—–w- C:\PROGRA~3\Easy CD-DA Extractor
2012-05-15 20:41:04 ——– d—–w- C:\Windows\Easy CD-DA Extractor 12.0
2012-05-15 20:41:04 ——– d—–w- C:\Program Files\Easy CD-DA Extractor 12
2012-05-11 02:02:47 476320 ——w- C:\Windows\SysWow64\ImagXpr7.dll
2012-05-11 02:02:47 471040 ——w- C:\Windows\SysWow64\ImagXRA7.dll
2012-05-11 02:02:47 262144 ——w- C:\Windows\SysWow64\ImagXR7.dll
2012-05-11 02:02:47 1568768 ——w- C:\Windows\SysWow64\ImagX7.dll
2012-05-11 02:02:47 155648 —-a-w- C:\Windows\SysWow64\NeroCheck.exe
2012-05-11 02:02:47 106496 —-a-w- C:\Windows\SysWow64\TwnLib20.dll
2012-05-09 08:24:57 ——– d—–w- C:\Program Files\Common Files\Digidesign
2012-05-08 06:17:50 70304 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-08 06:17:50 419488 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-08 00:38:21 ——– d—–w- C:\Program Files (x86)\Vstplugins
2012-05-08 00:38:15 ——– d—–w- C:\Program Files (x86)\Sony
2012-05-08 00:34:19 ——– d—–w- C:\Program Files (x86)\Sony Setup
2012-05-07 23:55:15 ——– d—–w- C:\Windows\System32\appmgmt
2012-05-04 07:04:31 ——– d—–w- C:\Users\Boosh\AppData\Local\Adobe
2012-05-04 06:48:10 ——– d—–w- C:\Users\Boosh\AppData\Local\ElevatedDiagnostics
2012-05-04 02:16:37 230400 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\hpzppw71.dll
2012-05-02 23:01:54 ——– d—–w- C:\Program Files (x86)\uTorrent
2012-05-02 23:01:09 ——– d—–w- C:\Users\Boosh\AppData\Roaming\uTorrent
2012-05-02 08:39:09 77824 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2012-05-02 08:39:09 32768 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2012-05-02 08:39:09 225280 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\IScript\iscript.dll
2012-05-02 08:39:09 176128 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2012-04-30 23:47:02 ——– d—–w- C:\Program Files (x86)\VideoLAN
2012-04-30 19:07:30 ——– d—–w- C:\Users\Boosh\AppData\Local\Oblivion
2012-04-30 13:10:22 ——– d—–w- C:\Users\Boosh\AppData\Local\Apple Computer
2012-04-30 13:10:08 34152 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-04-30 13:10:08 126312 —-a-w- C:\Windows\System32\GEARAspi64.dll
2012-04-30 13:10:08 107368 —-a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-04-30 13:09:57 ——– d—–w- C:\Program Files\iPod
2012-04-30 13:09:56 ——– d—–w- C:\Program Files\iTunes
2012-04-30 13:09:56 ——– d—–w- C:\Program Files (x86)\iTunes
2012-04-30 13:09:56 ——– d—–w- C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-04-30 13:08:58 ——– d—–w- C:\Program Files\Bonjour
2012-04-30 13:08:58 ——– d—–w- C:\Program Files (x86)\Bonjour
2012-04-30 12:52:26 ——– d—–w- C:\Program Files (x86)\Bethesda Softworks
2012-04-30 12:51:23 69714 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2012-04-30 12:51:23 63488 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2012-04-30 12:51:23 5632 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2012-04-30 12:51:23 32768 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2012-04-30 12:51:23 274432 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2012-04-30 12:51:23 184320 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2012-04-30 12:51:22 753664 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2012-04-30 12:51:22 331908 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2012-04-30 12:51:22 200836 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2012-04-30 12:25:19 ——– d—–w- C:\Users\Boosh\AppData\Roaming\Avid
2012-04-30 12:25:19 ——– d—–w- C:\Program Files\Avid
2012-04-30 12:25:19 ——– d—–w- C:\PROGRA~3\Avid
2012-04-30 12:23:51 ——– d—–w- C:\Users\Boosh\AppData\Local\start
2012-04-30 12:21:42 ——– d—–w- C:\Program Files (x86)\Mpeg2Decoder
2012-04-30 12:21:13 ——– d—–w- C:\Program Files (x86)\pdfforge Toolbar
2012-04-30 12:21:13 ——– d—–w- C:\Program Files (x86)\Application Updater
2012-04-30 12:20:50 87040 —-a-w- C:\Windows\System32\pdfcmnnt.dll
2012-04-30 12:20:50 662288 —-a-w- C:\Windows\SysWow64\MSCOMCT2.OCX
2012-04-30 12:20:50 137000 —-a-w- C:\Windows\SysWow64\MSMAPI32.OCX
2012-04-30 12:20:49 23552 —-a-w- C:\Windows\SysWow64\MSMPIDE.DLL
2012-04-30 12:20:49 ——– d—–w- C:\Program Files (x86)\PDFCreator
2012-04-30 12:07:24 ——– d—–w- C:\Users\Boosh\AppData\Local\Mozilla
2012-04-30 12:05:52 8917360 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{3E3FB6D9-13E5-4E3F-9C39-F9F234593CA1}\mpengine.dll
2012-04-30 12:05:51 279656 ——w- C:\Windows\System32\MpSigStub.exe
2012-04-30 12:05:14 ——– d—–w- C:\Program Files (x86)\Transcribe!
2012-04-30 12:02:03 86016 —-a-w- C:\Windows\unvise32.exe
2012-04-30 12:02:02 ——– d—–w- C:\Program Files (x86)\DivX
2012-04-30 11:55:34 ——– d—–w- C:\Users\Boosh\AppData\Local\Apple
2012-04-30 11:49:33 ——– d—–w- C:\Windows\Easy CD-DA Extractor
2012-04-30 11:47:04 ——– d—–w- C:\Windows\Panther
2012-04-30 11:46:49 ——– d-sh–w- C:\Boot
2012-04-30 11:42:23 ——– d—–w- C:\Users\Boosh\AppData\Local\Sony
2012-04-30 11:27:41 ——– d—–w- C:\Program Files (x86)\Microsoft ActiveSync
2012-04-30 11:27:14 ——– d—–w- C:\Windows\ShellNew
2012-04-30 11:21:05 ——– d—–w- C:\Program Files (x86)\Renesas Electronics
2012-04-30 11:19:57 74272 —-a-w- C:\Windows\System32\RtNicProp64.dll
2012-04-30 11:19:57 333928 —-a-w- C:\Windows\System32\drivers\Rt64win7.sys
2012-04-30 11:19:57 107552 —-a-w- C:\Windows\System32\RTNUninst64.dll
2012-04-30 11:19:29 ——– d—–w- C:\Program Files (x86)\Realtek
2012-04-30 11:18:13 38456 —-a-w- C:\Windows\System32\drivers\usbfilter.sys
2012-04-30 11:18:13 ——– d—–w- C:\Program Files (x86)\AMD
2012-04-30 11:18:09 16440 —-a-w- C:\Windows\System32\drivers\AtiPcie.sys
2012-04-30 11:17:42 ——– d-sh–w- C:\Windows\Installer
2012-04-30 11:17:41 ——– d—–w- C:\Program Files\ATI
2012-04-30 11:16:47 ——– d—–w- C:\Program Files\ATI Technologies
2012-04-30 08:57:56 ——– d-sh–w- C:\Recovery
.
==================== Find3M ====================
.
.
============= FINISH: 22:46:15.60 ===============

Thanks for your help. I ran Combofix, but it just went to dos prompt, did it's thing, then closed without giving me the option of saving a log anywhere.
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

When you ran ComboFix you say there was no log created? Did you look in C:\ for ComboFix.txt?

If you look and it is not there, run ComboFix again and post the new log created.
I just looked in C: for combofix.txt and couldn't find it. I ran it again as administrator and even did a system search but didn't find it. To be honest, combofix seems to run normally till about of a third of the way in, then it just skips to the end and closes. I think I will reformat. :-( Thanks for your advice and help.
Hi, Ok thank you for letting me know. With the ZeroAccess rootkit on board your system that is the route that I would follow as well.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI