This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Audio Ads and Browser Redirector and freezes/crashes [Solved]

67 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I am having some problems with my PC that seem to have staerted after a friend plugged in his flash drive. I have done multiple scans with malwarebytes and superantispyware, but the symptoms remain.

I would really appreciate any help you guys could provide. TYIA! Here are my recent OTL logs:

OTL logfile created on: 7/15/2012 12:52:42 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\John\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.56 Gb Available Physical Memory | 27.79% Memory free
4.00 Gb Paging File | 1.73 Gb Available in Paging File | 43.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 111.81 Gb Total Space | 47.23 Gb Free Space | 42.24% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 465.65 Gb Free Space | 99.98% Space Free | Partition Type: NTFS
Drive F: | 442.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 1862.36 Gb Total Space | 795.17 Gb Free Space | 42.70% Space Free | Partition Type: NTFS

Computer Name: JOHN-PC | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\John\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Users\John\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Air Mouse\Air Mouse\Air Mouse.exe ()
PRC - C:\Program Files (x86)\Air Mouse\Air Mouse\Mobile Mouse Service.exe (RPA Technology)
PRC - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Users\John\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe ()
PRC - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Users\John\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
MOD - C:\Program Files (x86)\Air Mouse\Air Mouse\Air Mouse.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Air Mouse\Air Mouse\BonjourService.dll ()
MOD - C:\Users\John\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe ()
MOD - C:\Users\John\AppData\Local\Autobahn\rt\jetrt\baseline720.dll ()
MOD - C:\Users\John\AppData\Local\Autobahn\rt\bin\zip.dll ()
MOD - C:\Users\John\AppData\Local\Autobahn\rt\bin\java.dll ()
MOD - C:\Users\John\AppData\Local\Autobahn\rt\bin\jetvm\jvm.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\ramaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe (Symantec Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (TeamViewer6) – C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NMSAccess) – C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe ()
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NISx64\1307010.005\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1307010.005\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1307010.005\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1307010.005\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1307010.005\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (ccSet_NIS) – C:\Windows\SysNative\drivers\NISx64\1307010.005\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1307010.005\symds64.sys (Symantec Corporation)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (ATI Technologies, Inc.)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (StarOpen) – C:\Windows\SysNative\drivers\StarOpen.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120714.017\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120714.017\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120711.002\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120713.001\IDSviA64.sys (Symantec Corporation)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - (StarOpen) – C:\Windows\SysWow64\drivers\StarOpen.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8C 3E 3B 21 52 62 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {12857533-D18A-4F1E-BBCC-A75F0EA531FE}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{12857533-D18A-4F1E-BBCC-A75F0EA531FE}: "URL" = http://www.google.com/search?q={searchTerm…age={startPage}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…o=US&ver=19
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.2
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:5.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:3.9.1.14019


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\John\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\fbphotozoom\fbphotozoom14.xpi [2012/03/22 01:52:43 | 000,102,505 | —- | M] ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn\ [2012/03/22 13:59:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2012/07/15 12:30:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/19 10:53:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/19 20:48:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/19 10:53:56 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/19 20:48:39 | 000,000,000 | —D | M]

[2010/11/08 00:52:18 | 000,000,000 | —D | M] (No name found) – C:\Users\John\AppData\Roaming\Mozilla\Extensions
[2012/07/14 21:54:41 | 000,000,000 | —D | M] (No name found) – C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\extensions
[2012/05/18 13:48:19 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/06/01 14:33:39 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2012/07/14 21:54:41 | 000,000,000 | —D | M] ("Timeline") – C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\extensions\[removed]
[2012/03/23 01:36:29 | 000,002,464 | —- | M] () – C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\searchplugins\safesearch.xml
[2011/11/09 02:55:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/03/26 17:07:18 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/07/15 12:30:09 | 000,000,000 | —D | M] (Norton Toolbar) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN
[2012/03/22 13:59:37 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPLGN
[2012/05/23 17:04:01 | 000,102,890 | —- | M] () (No name found) – C:\USERS\JOHN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q50RELBX.DEFAULT\EXTENSIONS\[removed]
[2012/04/29 01:20:54 | 000,004,733 | —- | M] () (No name found) – C:\USERS\JOHN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q50RELBX.DEFAULT\EXTENSIONS\[removed]
[2012/06/19 10:53:56 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/11/14 02:47:08 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/14 19:15:58 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/02/14 19:15:58 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\John\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [FileHippo.com] C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\John\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MLB.TV NexDef Plug-in.lnk = C:\Users\John\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F86E9B87-6D9B-43DA-8D18-EE7E9B824E07}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27:64bit: - HKLM IFEO\ehshell.exe: Debugger - C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O27 - HKLM IFEO\ehshell.exe: Debugger - C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/01/28 16:00:27 | 000,000,088 | —- | M] () - F:\autorun.inf – [ UDF ]
O33 - MountPoints2\{be632404-ebc1-11df-8541-0018f3be7845}\Shell - "" = AutoRun
O33 - MountPoints2\{be632404-ebc1-11df-8541-0018f3be7845}\Shell\AutoRun\command - "" = F:\WD SmartWare.exe – [2010/01/21 20:13:40 | 003,330,848 | —- | M] (Western Digital)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/15 12:49:48 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\John\Desktop\OTL.exe
[2012/07/15 02:26:04 | 000,000,000 | —D | C] – C:\Users\John\AppData\Roaming\SUPERAntiSpyware.com
[2012/07/15 02:25:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012/07/15 02:25:02 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2012/07/15 02:25:02 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/07/15 01:46:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2012/07/15 01:46:03 | 000,000,000 | —D | C] – C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/07/15 00:48:12 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\svchost.exe
[2012/07/13 15:52:14 | 000,000,000 | —D | C] – C:\Users\John\AppData\Roaming\Malwarebytes
[2012/07/13 15:51:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/13 15:51:52 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/07/13 15:51:51 | 000,024,904 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/07/13 15:51:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/13 00:20:40 | 000,955,840 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012/07/13 00:20:40 | 000,268,720 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012/07/13 00:19:25 | 000,189,360 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012/07/13 00:19:25 | 000,188,840 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012/07/12 18:34:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
[2012/07/11 03:38:34 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2012/07/11 03:38:34 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2012/07/11 03:37:04 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2012/07/11 03:37:02 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2012/07/11 03:36:43 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/07/11 03:36:15 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/07/11 03:36:11 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/07/11 03:28:52 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/07/11 03:28:52 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/07/11 03:28:50 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/07/11 03:28:50 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/07/11 03:28:49 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/07/11 03:28:48 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/07/11 03:28:47 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/07/11 03:28:47 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/07/11 03:28:45 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/07/11 03:28:44 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/07/11 03:28:44 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/07/11 03:28:44 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/07/11 03:28:44 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/07/10 16:09:00 | 000,000,000 | —D | C] – C:\Users\John\AppData\Roaming\Systweak
[2012/07/10 16:08:48 | 000,018,856 | —- | C] (Systweak Inc., (www.systweak.com)) – C:\Windows\SysNative\roboot64.exe
[2012/07/10 16:08:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
[2012/07/10 16:08:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\RegClean Pro
[2012/06/24 16:03:30 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/24 16:03:30 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/24 16:03:30 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/24 16:03:16 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/24 16:03:16 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/24 16:03:15 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/24 16:02:55 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/24 16:02:55 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/19 18:15:57 | 000,000,000 | —D | C] – C:\Users\John\AppData\Roaming\Yahoo!
[2012/06/19 18:10:38 | 000,439,704 | —- | C] (Yahoo! Inc.) – C:\Users\John\Documents\msgr11us.exe
[2012/06/17 01:17:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/06/17 01:17:09 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/06/17 01:17:08 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/06/17 01:17:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/06/15 14:59:05 | 000,000,000 | —D | C] – C:\Users\John\AppData\Local\Macromedia
[1 C:\Users\John\Documents\*.tmp files -> C:\Users\John\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/15 12:49:49 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\John\Desktop\OTL.exe
[2012/07/15 12:39:38 | 000,017,168 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/15 12:39:38 | 000,017,168 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/15 12:29:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/15 12:29:03 | 1609,424,896 | -HS- | M] () – C:\hiberfil.sys
[2012/07/15 12:04:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/15 11:58:02 | 000,000,924 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1823708585-3903857545-908119466-1000UA.job
[2012/07/15 02:25:13 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/07/15 01:46:03 | 000,002,971 | —- | M] () – C:\Users\John\Desktop\HiJackThis.lnk
[2012/07/13 18:52:59 | 780,045,066 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/07/13 17:58:53 | 000,000,902 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1823708585-3903857545-908119466-1000Core.job
[2012/07/13 15:51:53 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/13 03:05:26 | 000,087,488 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIRfsClientNP.dll
[2012/07/13 03:05:26 | 000,080,800 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIinit.dll
[2012/07/13 03:05:26 | 000,034,720 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIport.dll
[2012/07/13 00:18:04 | 000,955,840 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012/07/13 00:18:04 | 000,839,096 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2012/07/13 00:18:04 | 000,268,720 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012/07/13 00:18:04 | 000,189,360 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012/07/13 00:18:04 | 000,188,840 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012/07/12 22:21:12 | 000,054,335 | —- | M] () – C:\Users\John\Documents\nugster.aspx
[2012/07/12 20:14:38 | 001,145,786 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/12 20:14:38 | 000,624,162 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/07/12 20:14:38 | 000,361,676 | —- | M] () – C:\Windows\SysNative\perfh00D.dat
[2012/07/12 20:14:38 | 000,106,538 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/07/12 20:14:38 | 000,069,244 | —- | M] () – C:\Windows\SysNative\perfc00D.dat
[2012/07/12 15:01:23 | 000,000,274 | —- | M] () – C:\Windows\tasks\RegClean Pro_DEFAULT.job
[2012/07/11 16:38:31 | 000,413,312 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/11 16:10:00 | 000,000,282 | —- | M] () – C:\Windows\tasks\RegClean Pro_UPDATES.job
[2012/07/11 16:04:43 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/07/11 16:04:43 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/07/11 03:45:06 | 000,000,129 | —- | M] () – C:\Windows\SysNative\MRT.INI
[2012/07/10 16:41:03 | 000,001,652 | —- | M] () – C:\Windows\SysNative\ASOROSet.bin
[2012/07/10 16:08:47 | 000,001,050 | —- | M] () – C:\Users\Public\Desktop\RegClean Pro.lnk
[2012/07/10 16:04:12 | 000,018,856 | —- | M] (Systweak Inc., (www.systweak.com)) – C:\Windows\SysNative\roboot64.exe
[2012/07/10 15:59:54 | 000,001,079 | —- | M] () – C:\Users\John\Desktop\SpywareBlaster.lnk
[2012/07/03 13:46:44 | 000,024,904 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/07/02 14:06:47 | 000,029,765 | —- | M] () – C:\Users\John\Documents\bria and i wedding.jpg
[2012/06/21 17:53:09 | 000,001,126 | —- | M] () – C:\Users\Public\Desktop\Foxit Reader.lnk
[2012/06/19 18:10:41 | 000,439,704 | —- | M] (Yahoo! Inc.) – C:\Users\John\Documents\msgr11us.exe
[2012/06/17 01:17:54 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[1 C:\Users\John\Documents\*.tmp files -> C:\Users\John\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/15 02:25:11 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/07/15 01:46:03 | 000,002,971 | —- | C] () – C:\Users\John\Desktop\HiJackThis.lnk
[2012/07/13 15:51:53 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/12 22:21:09 | 000,054,335 | —- | C] () – C:\Users\John\Documents\nugster.aspx
[2012/07/10 16:31:44 | 000,001,652 | —- | C] () – C:\Windows\SysNative\ASOROSet.bin
[2012/07/10 16:09:12 | 000,000,274 | —- | C] () – C:\Windows\tasks\RegClean Pro_DEFAULT.job
[2012/07/10 16:09:10 | 000,000,282 | —- | C] () – C:\Windows\tasks\RegClean Pro_UPDATES.job
[2012/07/10 16:08:47 | 000,001,050 | —- | C] () – C:\Users\Public\Desktop\RegClean Pro.lnk
[2012/07/10 03:04:34 | 780,045,066 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/07/02 14:06:37 | 000,029,765 | —- | C] () – C:\Users\John\Documents\bria and i wedding.jpg
[2012/06/21 17:53:08 | 000,001,126 | —- | C] () – C:\Users\Public\Desktop\Foxit Reader.lnk
[2012/06/17 01:17:52 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/03/26 12:51:21 | 000,060,304 | —- | C] () – C:\Users\John\g2mdlhlpx.exe
[2011/08/22 22:34:39 | 000,005,120 | —- | C] () – C:\Users\John\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/22 22:13:40 | 000,153,600 | —- | C] () – C:\Windows\SysWow64\IS_ContextMenu.dll
[2011/03/23 02:00:02 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/12/16 02:02:33 | 000,000,397 | —- | C] () – C:\Users\John\AppData\Roaming\ZinioReader4_state.xml
[2010/11/14 03:09:03 | 000,001,041 | —- | C] () – C:\Users\John\AppData\Roaming\vso_ts_preview.xml
[2010/11/14 02:53:30 | 000,007,168 | —- | C] () – C:\Windows\SysWow64\drivers\StarOpen.sys
[2010/11/08 03:43:14 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin

========== LOP Check ==========

[2010/11/19 14:15:44 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\acccore
[2010/11/14 02:53:42 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\Canneverbe Limited
[2011/09/20 19:38:02 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\ContentGuard
[2011/11/03 18:48:05 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\DVDVideoSoft
[2012/06/21 17:53:39 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\Foxit Software
[2012/02/22 21:32:25 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\redsn0w
[2012/06/01 03:12:30 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\Spotify
[2012/07/10 16:09:00 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\Systweak
[2011/03/30 21:05:39 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\Tific
[2011/03/14 03:06:08 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\Uniblue
[2012/07/13 03:37:02 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\uTorrent
[2012/05/20 01:18:29 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\Vso
[2010/11/09 01:49:15 | 000,000,000 | —D | M] – C:\Users\John\AppData\Roaming\ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1
[2012/07/13 17:58:53 | 000,000,902 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1823708585-3903857545-908119466-1000Core.job
[2012/07/15 11:58:02 | 000,000,924 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1823708585-3903857545-908119466-1000UA.job
[2012/07/12 15:01:23 | 000,000,274 | —- | M] () – C:\Windows\Tasks\RegClean Pro_DEFAULT.job
[2012/07/11 16:10:00 | 000,000,282 | —- | M] () – C:\Windows\Tasks\RegClean Pro_UPDATES.job
[2012/06/17 01:00:55 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2010/11/08 09:41:48 | 000,001,024 | —- | M] () – C:\.rnd
[2010/11/20 08:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2010/11/08 03:39:03 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/07/15 12:29:03 | 1609,424,896 | -HS- | M] () – C:\hiberfil.sys
[2012/06/13 20:01:59 | 000,001,125 | -H– | M] () – C:\IPH.PH
[2012/07/15 12:29:11 | 2145,902,592 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/06 17:31:42 | 000,000,221 | -HS- | M] () – C:\Users\John\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/05/21 14:40:45 | 028,841,000 | —- | M] () – C:\Users\John\Desktop\KMPlayer_EN_3.2.0.0.exe
[2012/07/15 12:49:49 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\John\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >


OTL Extras logfile created on: 7/15/2012 12:52:42 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\John\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.56 Gb Available Physical Memory | 27.79% Memory free
4.00 Gb Paging File | 1.73 Gb Available in Paging File | 43.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 111.81 Gb Total Space | 47.23 Gb Free Space | 42.24% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 465.65 Gb Free Space | 99.98% Space Free | Partition Type: NTFS
Drive F: | 442.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 1862.36 Gb Total Space | 795.17 Gb Free Space | 42.70% Space Free | Partition Type: NTFS

Computer Name: JOHN-PC | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{106A2B51-7B49-48D3-A784-FA5EE7CE257D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{26D5FDBE-04B0-480B-8A86-9AB721F8FA24}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{31EA63F6-9C4F-4777-A114-6051FE5CA2F2}" = rport=10243 | protocol=6 | dir=out | app=system |
"{34A332BD-A540-41DF-B0AD-EA87EC35588F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{46D84D9E-9FD8-4ADD-AE1A-C9700695CCD5}" = lport=10243 | protocol=6 | dir=in | app=system |
"{490B7296-3F53-4198-964E-2A7130D51014}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5DD45AA5-E32E-43E2-A469-D23CCA689BA8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5E910AB3-95B3-4EF3-A99E-5825D8B8FAFE}" = lport=137 | protocol=17 | dir=in | app=system |
"{64DB0E7F-5853-47D5-AC29-ED3FDD321A56}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{7BDF36B9-83CF-4C43-9848-C43985B1CD1B}" = rport=445 | protocol=6 | dir=out | app=system |
"{87B169E4-513F-4F0D-8F4D-83BD2445739F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{895D7E65-3BEC-4282-9FB6-CBC18D45F898}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{916C375F-929B-4878-94E0-0B4002699427}" = rport=139 | protocol=6 | dir=out | app=system |
"{96B898FA-FED8-4819-8EB9-6143EDAB2A5A}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{9739D07C-491F-41B1-82DC-F665BBCA8816}" = lport=138 | protocol=17 | dir=in | app=system |
"{9C2CFC46-7AC1-45EF-A4A9-B8E77840FFD0}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A0513196-A240-44B9-959A-517F9A5D40B6}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{B8A226B0-A8C2-4003-941B-F71DE6E660D7}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BA5BE986-D34C-4504-8B52-D83262DD1E06}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{BFBD648E-8841-4AC9-A74D-2C8E29D0F17E}" = rport=138 | protocol=17 | dir=out | app=system |
"{C39DF3E3-375C-4A6B-85D2-3BADC6136862}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{C720EAB0-0B97-4350-83E0-01550E04AC6C}" = rport=137 | protocol=17 | dir=out | app=system |
"{D093C88D-59D2-4432-8F16-7EEA6DB9A760}" = lport=139 | protocol=6 | dir=in | app=system |
"{E3E96FD5-8A74-427F-A395-9DAB17663C8A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E4F5E2EF-6956-4A5A-8B4F-F918BB0EC419}" = lport=445 | protocol=6 | dir=in | app=system |
"{FEE6A2F9-E82C-45D8-BF1C-30A06AA28F53}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F8F2D9-A460-4F98-B75B-5CF48BA113CE}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{02DD3EF4-E632-4D83-8AAC-01CE5DB0EDE1}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0488574A-2A2E-48F0-8D76-B0297F0745F1}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{0DCA572D-EACD-4DB8-A70F-29B3AC59DD89}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe |
"{10D33E22-702B-4A08-AF78-4CC12CC06C29}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{1782A0E0-EE72-4731-A94A-D6394D09E359}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{1FDD7A8B-077D-422A-BDEC-3B13C0AC6DFD}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{20D2E368-300A-40D1-8403-680386D61AC0}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{2267C821-DAAC-4762-B3D6-13495F049D40}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{32F14B47-2ABF-43F4-92AE-83EB090CA984}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{34A802C3-21AF-439E-BAAD-9F51E4CDEABD}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3616CC79-37F9-4F06-A951-FC97C2CE3E60}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{38CB80F0-85EC-4825-8CA3-B2AD9D7E5B63}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3B78D5D9-89F9-44D6-869C-C64F50283B6C}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{3ECE30AB-70FE-4EA4-BE50-82EAD7D47F1A}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{3EE5B4E3-3F27-47F0-A273-C4456A77DE8E}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{4B37C867-3384-4587-BC4F-B25DA609BA7C}" = protocol=6 | dir=out | app=system |
"{52F2F4F8-A3BD-4212-9613-23887D3695C3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5B8A4A75-E997-41D4-A2E5-BCDCA4AC4979}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5E946AE1-7D04-4AFF-9481-3C2ED9BB6F79}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{6057FC69-A247-467A-BE86-90873B39DB99}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{624A5AF0-4D5E-49D3-99B1-E5175128BCAE}" = protocol=6 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{6688732A-1663-4180-8A75-ACE8075BA9DB}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{679925D8-B301-4068-ADAF-5CFA5F2B40CA}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{6886BB0D-7FE7-4D11-AFB0-1F2476D45A7B}" = dir=in | app=c:\users\john\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{75E4803F-152C-405D-AF8A-8ECB37F2166C}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe |
"{79FEFFDB-9CA0-4C67-879A-AD3A4102D18D}" = protocol=17 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{82298248-8208-4E20-893A-E8C3AE37248B}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{86F1963B-3E5F-4B0C-ABDB-95BEC4D1575C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{88D6EACC-106C-41D2-AA8E-CAC81F7FB495}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{89B08ECA-EB93-4E19-8D41-DD100BC70F1D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8DE49596-0D28-42B5-8C2D-8E0552E7F12B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{8FAE6DE6-59E4-4527-AEFA-9775E70A1A22}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9C3A98CC-36B7-478F-9B91-0AD36889064A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{9C8E7C0E-1CB0-4C0E-9C06-6EDBB6343D1D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{ADB48E12-D343-459B-A81B-76AB080558F4}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{B151D7DC-BE8E-4584-A67E-D13B9909D8FB}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{B2DF54EA-4340-4C86-AE0F-BD1C7DFA7E36}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{BFEB1D45-FFD0-49B3-8AB6-D04BCA4F6E59}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe |
"{C0A926DB-5359-4383-9752-B591A144A000}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CCB3A00B-6637-4DBD-9268-1F51AD8C5D7A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CFD0487E-C2EE-435D-AFFF-23394D22174E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D5386891-0110-4208-87B7-FB0C0441E120}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe |
"{D56A608F-4E5E-4873-B800-03DB7582DA41}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{D95F1D7A-6A11-4A27-A7F1-B66AFFC75709}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{DAD93140-00F5-4113-8BBC-C91B5AE5BB6B}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{DE0476E7-0B9B-4416-9B4F-EC2EE2A84FF6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E12B398B-D8D3-46C5-AC74-1FA2B804DA7D}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E4FCE4ED-F2A1-421D-A17E-04E3E9204940}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{0EA09B19-3C43-4D14-A132-BC5C117BAC08}C:\program files (x86)\air mouse\air mouse\air mouse.exe" = protocol=6 | dir=in | app=c:\program files (x86)\air mouse\air mouse\air mouse.exe |
"TCP Query User{1DFCD2EA-0ED1-4FCD-808E-AAAA77B23665}C:\program files (x86)\air mouse\air mouse\air mouse.exe" = protocol=6 | dir=in | app=c:\program files (x86)\air mouse\air mouse\air mouse.exe |
"TCP Query User{9CB78234-D246-4A16-ABB3-459C244EABBB}C:\program files (x86)\air mouse\air mouse\mobile mouse service.exe" = protocol=6 | dir=in | app=c:\program files (x86)\air mouse\air mouse\mobile mouse service.exe |
"TCP Query User{AEBFF525-F1A0-4CBF-A4C6-AFE861CFDC28}C:\users\john\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\john\appdata\roaming\spotify\spotify.exe |
"TCP Query User{AFBEAD3A-7E51-4202-BF65-D8915A3EFA9E}C:\program files (x86)\1clickdownload\1clickdownload.exe" = protocol=6 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownload.exe |
"TCP Query User{B5411E28-1C7D-4F55-A13C-D3BF79889DF6}C:\users\john\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\john\appdata\roaming\spotify\spotify.exe |
"TCP Query User{F5395E5F-8E9C-47E8-B8CD-0BF79CC9339E}C:\program files (x86)\air mouse\air mouse\mobile mouse service.exe" = protocol=6 | dir=in | app=c:\program files (x86)\air mouse\air mouse\mobile mouse service.exe |
"UDP Query User{13B5C040-7594-4C42-9D8D-8434326114F3}C:\program files (x86)\air mouse\air mouse\mobile mouse service.exe" = protocol=17 | dir=in | app=c:\program files (x86)\air mouse\air mouse\mobile mouse service.exe |
"UDP Query User{15C9B96F-1ED1-4A0E-9186-19E83D4C2ED6}C:\users\john\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\john\appdata\roaming\spotify\spotify.exe |
"UDP Query User{19CA8390-F97B-4CDE-85C2-76BA15C9CC52}C:\program files (x86)\air mouse\air mouse\air mouse.exe" = protocol=17 | dir=in | app=c:\program files (x86)\air mouse\air mouse\air mouse.exe |
"UDP Query User{3BA8E0FD-57FD-45C4-B7D3-548F6E3D5B14}C:\program files (x86)\1clickdownload\1clickdownload.exe" = protocol=17 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownload.exe |
"UDP Query User{53A6C13D-7502-4ED0-8B6F-DA793CC5F499}C:\program files (x86)\air mouse\air mouse\air mouse.exe" = protocol=17 | dir=in | app=c:\program files (x86)\air mouse\air mouse\air mouse.exe |
"UDP Query User{70550B58-EC34-4410-983D-B6A863618F12}C:\users\john\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\john\appdata\roaming\spotify\spotify.exe |
"UDP Query User{E5930283-4CF7-4ABA-AC16-3AD688E53E71}C:\program files (x86)\air mouse\air mouse\mobile mouse service.exe" = protocol=17 | dir=in | app=c:\program files (x86)\air mouse\air mouse\mobile mouse service.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java™ 7 Update 5 (64-bit)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{80C27FE9-C6C4-F5C8-EAD3-09E7E0102E78}" = ATI Stream SDK v2 Developer
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud
"{8DF9D3DF-6D03-A04F-217F-F2577D973DBE}" = ATI Catalyst Install Manager
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{AE0D971F-5430-8874-B09E-3F1C76E2F8FF}" = WMV9/VC-1 Video Playback
"{CC7D4CC8-FE90-17E2-FAC6-3D14C93DCE09}" = AMD Drag and Drop Transcoding
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D29E5E5F-47CA-087E-DCBF-FB75171D5B2E}" = ccc-utility64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MyDefrag v4.3.1_is1" = MyDefrag v4.3.1
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{135F49F2-9071-F45A-4263-DF7D42FBF7DD}" = CCC Help English
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{3F66C4BF-4BD9-FF9C-FA9F-4579F60A33B3}" = Catalyst Control Center Graphics Previews Vista
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{5D112C61-C8D0-4718-8DD7-B9115EB9AF90}" = LogMeIn
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6BD602A4-43C1-441A-3B73-91C5B019128F}" = Zinio Reader 4
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FCA0420-CB8D-4D05-B5B0-905063930DE4}" = Mobile Mouse Server
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A914AE85-1A36-0575-714C-BF996BDA20C7}" = ccc-core-static
"{AE249BA3-2421-3996-5E9A-DF4A9F3551FC}" = Catalyst Control Center InstallProxy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.4.338
"{DB8B49A9-7CF1-34DB-6DF2-1EC41C0FE5E1}" = Catalyst Control Center Graphics Previews Common
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AIM_7" = AIM 7
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FileHippo.com" = FileHippo.com Update Checker
"Foxit PDF Editor" = Foxit PDF Editor
"Foxit Reader_is1" = Foxit Reader
"Free DVD Decrypter_is1" = Free DVD Decrypter version 1.5.6.804
"Free DVD Video Burner_is1" = Free DVD Video Burner version 3.1.2.920
"iSkysoft iMedia Converter_is1" = iSkysoft iMedia Converter(Build 3.0.3.0)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NIS" = Norton Internet Security
"Picasa 3" = Picasa 3
"RegClean Pro_is1" = RegClean Pro
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SpywareBlaster_is1" = SpywareBlaster 4.6
"TeamViewer 6" = TeamViewer 6
"The KMPlayer" = The KMPlayer (remove only)
"uTorrent" = µTorrent
"Yahoo! Messenger" = Yahoo! Messenger
"ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1" = Zinio Reader 4

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Binfer" = Binfer
"GoToMeeting" = GoToMeeting 5.1.0.880
"Progress Bar" = Progress Bar
"Spotify" = Spotify

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/12/2012 6:30:00 PM | Computer Name = John-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\John\Downloads\SoftonicDownloader_for_kmplayer
(2).exe".Error in manifest or policy file "" on line . A component version required
by the application conflicts with another component version already active. Conflicting
components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 7/12/2012 6:30:00 PM | Computer Name = John-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\John\Downloads\SoftonicDownloader_for_utorrent.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 7/12/2012 6:31:05 PM | Computer Name = John-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\John\Downloads\SoftonicDownloader_for_kmplayer.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 7/12/2012 6:31:06 PM | Computer Name = John-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\John\Downloads\SoftonicDownloader_for_utorrent
(2).exe".Error in manifest or policy file "" on line . A component version required
by the application conflicts with another component version already active. Conflicting
components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 7/13/2012 2:05:39 PM | Computer Name = John-PC | Source = LogMeIn Guardian | ID = 131176
Description = LogMeIn Guardian has detected a problem with the LogMeIn software
installed on this machine. The problem is locally identified by the following reference
ID: '5a9d49fb5d286d93d0c9b593900b3cd3'.

Error - 7/13/2012 2:11:15 PM | Computer Name = John-PC | Source = LogMeIn Guardian | ID = 131176
Description = LogMeIn Guardian has detected a problem with the LogMeIn software
installed on this machine. The problem is locally identified by the following reference
ID: '75b2846135a9869d9df375220776334c'.

Error - 7/13/2012 2:30:14 PM | Computer Name = John-PC | Source = LogMeIn Guardian | ID = 131176
Description = LogMeIn Guardian has detected a problem with the LogMeIn software
installed on this machine. The problem is locally identified by the following reference
ID: '09c706292c7ee0807d585124a9e75a3f'.

Error - 7/13/2012 2:35:03 PM | Computer Name = John-PC | Source = LogMeIn Guardian | ID = 131176
Description = LogMeIn Guardian has detected a problem with the LogMeIn software
installed on this machine. The problem is locally identified by the following reference
ID: 'b32f7f8f8f637af6ebc3941237207aac'.

Error - 7/13/2012 3:17:22 PM | Computer Name = John-PC | Source = LogMeIn Guardian | ID = 131176
Description = LogMeIn Guardian has detected a problem with the LogMeIn software
installed on this machine. The problem is locally identified by the following reference
ID: 'dc366ed6696279253d857a12fc2ebf28'.

Error - 7/15/2012 8:57:37 AM | Computer Name = John-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc3c5 Faulting module name: jscript9.dll, version: 9.0.8112.16447, time
stamp: 0x4fc9cfc6 Exception code: 0xc0000005 Fault offset: 0x000adc5d Faulting process
id: 0xd34 Faulting application start time: 0x01cd62595e80b0e0 Faulting application
path: \\.\globalroot\systemroot\svchost.exe Faulting module path: C:\Windows\SysWOW64\jscript9.dll
Report
Id: a65a5d00-ce7c-11e1-80a4-0018f3be7845

[ System Events ]
Error - 7/15/2012 2:30:53 AM | Computer Name = John-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\DR1, has a bad block.

Error - 7/15/2012 3:14:44 AM | Computer Name = John-PC | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 7/15/2012 11:09:10 AM | Computer Name = John-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\DR1, has a bad block.

Error - 7/15/2012 11:09:11 AM | Computer Name = John-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\DR1, has a bad block.

Error - 7/15/2012 12:06:34 PM | Computer Name = John-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\DR1, has a bad block.

Error - 7/15/2012 12:06:35 PM | Computer Name = John-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\DR1, has a bad block.

Error - 7/15/2012 12:06:36 PM | Computer Name = John-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\DR1, has a bad block.

Error - 7/15/2012 12:06:37 PM | Computer Name = John-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\DR1, has a bad block.

Error - 7/15/2012 12:06:38 PM | Computer Name = John-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\DR1, has a bad block.

Error - 7/15/2012 12:06:39 PM | Computer Name = John-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\DR1, has a bad block.


< End of report >
Hi jonk1,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
Hello NoodleTech! TY so much for responding so quickly.

Here are the logs requested:

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 17:29:06 on 2012-07-15
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.685 [GMT -4:00]
.
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe
C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
-netsvcs
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
C:\Users\John\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\Air Mouse\Air Mouse\Air Mouse.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\John\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe
C:\Program Files (x86)\Air Mouse\Air Mouse\Mobile Mouse Service.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\coIEPlg.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\IPS\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\coIEPlg.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
uRun: [Facebook Update] "C:\Users\John\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
uRun: [Spotify Web Helper] "C:\Users\John\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\John\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MLBTVN~1.LNK - C:\Users\John\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AIRMOU~1.LNK - C:\Program Files (x86)\Air Mouse\Air Mouse\Air Mouse.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{F86E9B87-6D9B-43DA-8D18-EE7E9B824E07} : DhcpNameServer = 192.168.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
IFEO: ehshell.exe - "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect
BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-X64: 0x1 - No File
BHO-X64: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\coIEPlg.dll
BHO-X64: Norton Identity Protection - No File
BHO-X64: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\IPS\IPSBHO.DLL
BHO-X64: Norton Vulnerability Protection - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\coIEPlg.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
IFEO-X64: ehshell.exe - "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\components\coFFPlgn.dll
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: C:\Users\John\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\plugins\np-mswmp.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\NISx64\1307010.005\SYMDS64.SYS –> C:\Windows\system32\drivers\NISx64\1307010.005\SYMDS64.SYS [?]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\NISx64\1307010.005\SYMEFA64.SYS –> C:\Windows\system32\drivers\NISx64\1307010.005\SYMEFA64.SYS [?]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120711.002\BHDrvx64.sys [2012-7-12 1161376]
R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\system32\drivers\NISx64\1307010.005\ccSetx64.sys –> C:\Windows\system32\drivers\NISx64\1307010.005\ccSetx64.sys [?]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120713.001\IDSviA64.sys [2012-7-13 509088]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\NISx64\1307010.005\Ironx64.SYS –> C:\Windows\system32\drivers\NISx64\1307010.005\Ironx64.SYS [?]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\NISx64\1307010.005\SYMNETS.SYS –> C:\Windows\system32\Drivers\NISx64\1307010.005\SYMNETS.SYS [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-9-27 375208]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2010-5-31 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\Windows\system32\drivers\LMIRfsDriver.sys –> C:\Windows\system32\drivers\LMIRfsDriver.sys [?]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-13 655944]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\ccsvchst.exe [2012-5-17 138232]
R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-3-23 2271608]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys –> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-7-10 138912]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 EraserSvc11210;Symantec Eraser Service;C:\Program Files (x86)\Norton Internet Security\Engine\19.7.1.5\ccsvchst.exe [2012-5-17 138232]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-15 250056]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-26 113120]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys –> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\system32\DRIVERS\wdcsam64.sys –> C:\Windows\system32\DRIVERS\wdcsam64.sys [?]
.
=============== Created Last 30 ================
.
2012-07-15 06:26:04 ——– d—–w- C:\Users\John\AppData\Roaming\SUPERAntiSpyware.com
2012-07-15 06:25:02 ——– d—–w- C:\ProgramData\SUPERAntiSpyware.com
2012-07-15 06:25:02 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2012-07-15 05:46:03 388096 —-a-r- C:\Users\John\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-07-15 05:46:03 ——– d—–w- C:\Program Files (x86)\Trend Micro
2012-07-15 04:48:12 20480 —-a-w- C:\Windows\svchost.exe
2012-07-13 19:52:14 ——– d—–w- C:\Users\John\AppData\Roaming\Malwarebytes
2012-07-13 19:51:52 ——– d—–w- C:\ProgramData\Malwarebytes
2012-07-13 19:51:51 24904 —-a-w- C:\Windows\System32\drivers\mbam.sys
2012-07-13 19:51:51 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-13 04:20:40 955840 —-a-w- C:\Windows\System32\npDeployJava1.dll
2012-07-11 19:22:09 3148800 —-a-w- C:\Windows\System32\win32k.sys
2012-07-11 07:38:35 2004480 —-a-w- C:\Windows\System32\msxml6.dll
2012-07-11 07:38:35 1390080 —-a-w- C:\Windows\SysWow64\msxml6.dll
2012-07-11 07:38:34 2048 —-a-w- C:\Windows\SysWow64\msxml3r.dll
2012-07-11 07:38:34 2048 —-a-w- C:\Windows\System32\msxml3r.dll
2012-07-11 07:38:34 1881600 —-a-w- C:\Windows\System32\msxml3.dll
2012-07-11 07:38:34 1236992 —-a-w- C:\Windows\SysWow64\msxml3.dll
2012-07-11 07:36:44 458704 —-a-w- C:\Windows\System32\drivers\cng.sys
2012-07-10 20:31:44 1652 —-a-w- C:\Windows\System32\ASOROSet.bin
2012-07-10 20:09:00 ——– d—–w- C:\Users\John\AppData\Roaming\Systweak
2012-07-10 20:08:48 18856 —-a-w- C:\Windows\System32\roboot64.exe
2012-07-10 20:08:43 ——– d—–w- C:\Program Files (x86)\RegClean Pro
2012-07-01 08:03:24 113664 —-a-w- C:\ProgramData\Microsoft\Windows\DRM\FB07.tmp.dat
2012-06-24 20:03:30 2622464 —-a-w- C:\Windows\System32\wucltux.dll
2012-06-24 20:03:16 99840 —-a-w- C:\Windows\System32\wudriver.dll
2012-06-24 20:02:55 36864 —-a-w- C:\Windows\System32\wuapp.exe
2012-06-24 20:02:55 186752 —-a-w- C:\Windows\System32\wuwebv.dll
2012-06-17 05:17:09 ——– d—–w- C:\Program Files\iPod
2012-06-17 05:17:08 ——– d—–w- C:\Program Files\iTunes
2012-06-17 05:17:08 ——– d—–w- C:\Program Files (x86)\iTunes
.
==================== Find3M ====================
.
2012-07-13 07:05:26 87488 —-a-w- C:\Windows\System32\LMIRfsClientNP.dll
2012-07-13 07:05:26 80800 —-a-w- C:\Windows\System32\LMIinit.dll
2012-07-13 07:05:26 34720 —-a-w- C:\Windows\System32\LMIport.dll
2012-07-13 04:18:04 839096 —-a-w- C:\Windows\System32\deployJava1.dll
2012-07-11 20:04:43 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-11 20:04:43 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-06 06:02:54 1133568 —-a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:03:06 805376 —-a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 12:12:17 2311680 —-a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:48:16 95600 —-a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 —-a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 —-a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 —-a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 —-a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 —-a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll
2012-05-22 01:25:30 87456 —-a-w- C:\Windows\System32\LMIRfsClientNP.dll.000.bak
2012-05-04 11:06:22 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-04-28 05:32:05 1112064 —-a-w- C:\Windows\System32\rdpcorets.dll
2012-04-28 03:55:21 210944 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 —-a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 —-a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 —-a-w- C:\Windows\System32\rdrmemptylst.exe
2012-04-24 05:37:37 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 —-a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 —-a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 —-a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
.
============= FINISH: 17:30:36.83 ===============


aswMBR log:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-15 17:38:52
—————————–
17:38:52.933 OS Version: Windows x64 6.1.7601 Service Pack 1
17:38:52.933 Number of processors: 2 586 0x4302
17:38:52.934 ComputerName: JOHN-PC UserName: John
17:38:53.491 Initialize success
17:39:00.064 AVAST engine defs: 12071501
17:39:17.385 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-4
17:39:17.389 Disk 0 Vendor: ST3500641AS 3.AAJ Size: 476940MB BusType: 3
17:39:17.394 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-1
17:39:17.398 Disk 1 Vendor: SAMSUNG_SP1213N TL100-30 Size: 114498MB BusType: 3
17:39:17.402 Device \Driver\atapi -> MajorFunction fffffa800334c5e8
17:39:17.406 Disk 1 MBR read successfully
17:39:17.413 Disk 1 MBR scan
17:39:17.420 Disk 1 Windows 7 default MBR code
17:39:17.425 Disk 1 MBR hidden
17:39:17.433 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 114494 MB offset 63
17:39:17.444 Disk 1 scanning C:\Windows\system32\drivers
17:39:31.061 Service scanning
17:40:00.562 Modules scanning
17:40:00.564 Disk 1 trace - called modules:
17:40:00.565 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa800334c5e8]<<
17:40:00.566 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa8002409550]
17:40:00.566 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa80022cb520]
17:40:00.567 5 ACPI.sys[fffff88000f287a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa80022d1060]
17:40:00.567 \Driver\atapi[0xfffffa80031ad060] -> IRP_MJ_CREATE -> 0xfffffa800334c5e8
17:40:01.442 AVAST engine scan C:\Windows
17:40:03.249 AVAST engine scan C:\Windows\system32
17:44:20.881 AVAST engine scan C:\Windows\system32\drivers
17:44:47.050 AVAST engine scan C:\Users\John
17:45:46.625 Disk 1 MBR has been saved successfully to "C:\Users\John\Desktop\MBR.dat"
17:45:46.636 The log file has been saved successfully to "C:\Users\John\Desktop\aswMBR.txt"
Hi jonk1,

No problem :)

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————


NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
did combofix and followed the steps here are the log results…… ComboFix 12-07-16.01 - John 07/16/2012 23:33:44.2.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.910 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\svchost.exe . —- Previous Run ——- . c:\users\John\AppData\Roaming\vso_ts_preview.xml c:\users\John\Documents\~WRL1901.tmp c:\users\John\g2mdlhlpx.exe c:\windows\svchost.exe G:\install.exe . . ((((((((((((((((((((((((( Files Created from 2012-06-17 to 2012-07-17 ))))))))))))))))))))))))))))))) . . 2012-07-17 03:46 . 2012-07-17 03:46 ——– d—–w- c:\users\LogMeInRemoteUser\AppData\Local\temp 2012-07-17 03:46 . 2012-07-17 03:46 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-17 02:35 . 2012-07-17 02:36 ——– d—–w- c:\users\John\AppData\Local\CutePDF Writer 2012-07-17 02:34 . 2012-07-17 02:34 ——– d—–w- c:\program files (x86)\GPLGS 2012-07-17 02:33 . 2012-03-11 18:56 86608 —-a-w- c:\windows\system32\cpwmon64.dll 2012-07-17 02:33 . 2012-07-17 02:33 ——– d—–w- c:\program files (x86)\Acro Software 2012-07-15 06:26 . 2012-07-15 06:26 ——– d—–w- c:\users\John\AppData\Roaming\SUPERAntiSpyware.com 2012-07-15 06:25 . 2012-07-15 06:26 ——– d—–w- c:\program files\SUPERAntiSpyware 2012-07-15 06:25 . 2012-07-15 06:25 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2012-07-15 05:46 . 2012-07-15 05:46 388096 —-a-r- c:\users\John\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-07-15 05:46 . 2012-07-15 05:46 ——– d—–w- c:\program files (x86)\Trend Micro 2012-07-13 19:52 . 2012-07-13 19:52 ——– d—–w- c:\users\John\AppData\Roaming\Malwarebytes 2012-07-13 19:51 . 2012-07-13 19:51 ——– d—–w- c:\programdata\Malwarebytes 2012-07-13 19:51 . 2012-07-13 19:51 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-07-13 19:51 . 2012-07-03 17:46 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-07-13 04:20 . 2012-07-13 04:18 955840 —-a-w- c:\windows\system32\npDeployJava1.dll 2012-07-11 19:22 . 2012-06-12 03:08 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-11 07:38 . 2012-06-06 06:06 2004480 —-a-w- c:\windows\system32\msxml6.dll 2012-07-11 07:38 . 2012-06-06 05:05 1390080 —-a-w- c:\windows\SysWow64\msxml6.dll 2012-07-11 07:38 . 2012-06-06 06:06 1881600 —-a-w- c:\windows\system32\msxml3.dll 2012-07-11 07:38 . 2012-06-06 05:05 1236992 —-a-w- c:\windows\SysWow64\msxml3.dll 2012-07-11 07:38 . 2010-06-26 03:55 2048 —-a-w- c:\windows\system32\msxml3r.dll 2012-07-11 07:38 . 2010-06-26 03:24 2048 —-a-w- c:\windows\SysWow64\msxml3r.dll 2012-07-11 07:36 . 2012-06-02 05:50 458704 —-a-w- c:\windows\system32\drivers\cng.sys 2012-07-10 20:31 . 2012-07-10 20:41 1652 —-a-w- c:\windows\system32\ASOROSet.bin 2012-07-10 20:09 . 2012-07-10 20:09 ——– d—–w- c:\users\John\AppData\Roaming\Systweak 2012-07-10 20:08 . 2012-07-10 20:04 18856 —-a-w- c:\windows\system32\roboot64.exe 2012-07-10 20:08 . 2012-07-10 20:08 ——– d—–w- c:\program files (x86)\RegClean Pro 2012-07-01 08:03 . 2012-07-01 08:03 113664 —-a-w- c:\programdata\Microsoft\Windows\DRM\FB07.tmp.dat 2012-06-24 20:03 . 2012-06-02 22:19 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-24 20:03 . 2012-06-02 22:19 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-24 20:03 . 2012-06-02 22:19 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-24 20:03 . 2012-06-02 22:15 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-24 20:03 . 2012-06-02 22:19 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-24 20:03 . 2012-06-02 22:15 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-24 20:03 . 2012-06-02 22:19 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-24 20:02 . 2012-06-02 19:19 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-24 20:02 . 2012-06-02 19:15 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-19 22:15 . 2012-06-19 22:15 ——– d—–w- c:\users\John\AppData\Roaming\Yahoo! 2012-06-17 05:17 . 2012-06-17 05:17 ——– d—–w- c:\program files\iPod 2012-06-17 05:17 . 2012-06-17 05:17 ——– d—–w- c:\program files\iTunes 2012-06-17 05:17 . 2012-06-17 05:17 ——– d—–w- c:\program files (x86)\iTunes . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-13 07:05 . 2010-11-08 13:41 34720 —-a-w- c:\windows\system32\LMIport.dll 2012-07-13 07:05 . 2010-11-08 13:41 87488 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-07-13 07:05 . 2010-11-08 13:41 80800 —-a-w- c:\windows\system32\LMIinit.dll 2012-07-13 04:18 . 2011-10-05 22:45 839096 —-a-w- c:\windows\system32\deployJava1.dll 2012-07-11 20:04 . 2012-04-15 04:53 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-11 20:04 . 2011-05-21 03:38 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-22 01:25 . 2010-11-08 13:41 87456 —-a-w- c:\windows\system32\LMIRfsClientNP.dll.000.bak 2012-05-04 11:06 . 2012-06-13 01:50 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-13 01:50 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-13 01:50 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-04-28 05:32 . 2012-06-13 01:49 1112064 —-a-w- c:\windows\system32\rdpcorets.dll 2012-04-28 03:55 . 2012-06-13 01:49 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-13 01:50 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-13 01:50 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-13 01:50 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="c:\users\John\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096] "MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240] "Spotify Web Helper"="c:\users\John\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-04 932528] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-10-01 98304] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-07 421776] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] . c:\users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ MLB.TV NexDef Plug-in.lnk - c:\users\John\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe [2011-3-16 15502336] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Air Mouse.lnk - c:\program files (x86)\Air Mouse\Air Mouse\Air Mouse.exe [2011-8-22 1106432] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-11 250056] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-19 113120] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-11-08 1255736] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1307010.005\SYMDS64.SYS [2011-07-26 451192] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1307010.005\SYMEFA64.SYS [2012-03-29 1092728] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120711.002\BHDrvx64.sys [2012-06-19 1161376] S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1307010.005\ccSetx64.sys [2011-11-29 167048] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120715.001\IDSvia64.sys [2012-06-14 509088] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1307010.005\Ironx64.SYS [2012-03-29 190072] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1307010.005\SYMNETS.SYS [2012-03-29 405624] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-07-13 375208] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-05-31 15928] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944] S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe [2012-03-27 138232] S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-18 2271608] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-08-16 116240] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-07-11 138912] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904] . . Contents of the 'Scheduled Tasks' folder . 2012-07-17 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 20:04] . 2012-07-16 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1823708585-3903857545-908119466-1000Core.job - c:\users\John\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-24 21:53] . 2012-07-17 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1823708585-3903857545-908119466-1000UA.job - c:\users\John\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-24 21:53] . 2012-07-16 c:\windows\Tasks\RegClean Pro_DEFAULT.job - c:\program files (x86)\RegClean Pro\RegCleanPro.exe [2012-07-10 20:04] . 2012-07-11 c:\windows\Tasks\RegClean Pro_UPDATES.job - c:\program files (x86)\RegClean Pro\RegCleanPro.exe [2012-07-10 20:04] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2010-05-31 57928] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false . - - - - ORPHANS REMOVED - - - - . WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS] "ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.7.1.5\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,38,12,11,7f,11, d0,78,5b,08,05,de,bb,01,03,dd,4c,30,54 "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"=hex:51,66,7a,6c,4c,1d,38,12,8d,ec,f8, 7b,2b,25,27,06,e7,c4,bc,f0,98,15,0d,de "{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}"=hex:51,66,7a,6c,4c,1d,38,12,60,d8,39, 64,cd,04,79,07,f5,b7,d6,9a,c1,81,e0,1c "{6D53EC84-6AAE-4787-AEEE-F4628F01010C}"=hex:51,66,7a,6c,4c,1d,38,12,ea,ef,40, 69,9c,24,e9,02,d1,f8,b7,22,8a,5f,45,18 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93, aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:90,dd,7f,90,ef,5e,cd,01 . [HKEY_USERS\S-1-5-21-1823708585-3903857545-908119466-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-1823708585-3903857545-908119466-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe c:\program files (x86)\CDBurnerXP\NMSAccessU.exe c:\program files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe c:\\.\globalroot\systemroot\svchost.exe . ************************************************************************** . Completion time: 2012-07-17 00:11:48 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-17 04:11 . Pre-Run: 51,721,719,808 bytes free Post-Run: 51,575,468,032 bytes free . - - End Of File - - 467FF260B23182BE54043C836061D745
Hi jonk1,

How is your computer behaving now?

Please run Malwarebytes' Anti-Malware.
  • Click the Update tab, then click Check for Updates.
  • If an update is found, download and install the latest version.
  • Next, click Scanner, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
i am still hearing sound ads in background. i just finished the malware bytes scan and am posting the results here its asking me to restart so im going to restart and then do the next step you posted with the eset scan thanks again. Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.17.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 John :: JOHN-PC [administrator] Protection: Disabled 7/17/2012 11:30:26 AM mbam-log-2012-07-17 (11-30-26).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 231061 Time elapsed: 26 minute(s), 55 second(s) Memory Processes Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> 2348 -> Delete on reboot. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot. (end)
heres the ESET results hopes this all helps. C:\ProgramData\Microsoft\Windows\DRM\FB07.tmp.dat a variant of Win32/Kryptik.AHTD trojan C:\Users\All Users\Microsoft\Windows\DRM\FB07.tmp.dat a variant of Win32/Kryptik.AHTD trojan C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\extensions\[removed] JS/Redirector.NBX trojan C:\Users\John\Downloads\registrybooster (2).exe Win32/RegistryBooster application C:\Users\John\Downloads\registrybooster.exe Win32/RegistryBooster application C:\Users\John\Downloads\SoftonicDownloader_for_kmplayer (2).exe a variant of Win32/SoftonicDownloader.A application C:\Users\John\Downloads\SoftonicDownloader_for_utorrent (2).exe a variant of Win32/SoftonicDownloader.A application C:\Users\John\Downloads\SoftonicDownloader_for_utorrent.exe a variant of Win32/SoftonicDownloader.A application G:\JOHN-PC\Backup Set 2011-06-17 190301\Backup Files 2011-06-17 190301\Backup files 13.zip multiple threats G:\JOHN-PC\Backup Set 2011-08-08 022352\Backup Files 2011-08-08 022352\Backup files 26.zip Win32/RegistryBooster application G:\JOHN-PC\Backup Set 2011-08-08 022352\Backup Files 2011-08-08 022352\Backup files 27.zip a variant of Win32/SoftonicDownloader.A application G:\JOHN-PC\Backup Set 2011-08-08 022352\Backup Files 2011-08-21 190006\Backup files 2.zip HTML/ScrInject.B.Gen virus G:\JOHN-PC\Backup Set 2011-08-08 022352\Backup Files 2011-08-21 190006\Backup files 4.zip HTML/ScrInject.B.Gen virus G:\JOHN-PC\Backup Set 2011-08-08 022352\Backup Files 2011-10-09 190012\Backup files 4.zip HTML/ScrInject.B.Gen virus G:\JOHN-PC\Backup Set 2011-10-16 192009\Backup Files 2011-10-16 192009\Backup files 22.zip Win32/RegistryBooster application G:\JOHN-PC\Backup Set 2011-10-16 192009\Backup Files 2011-10-16 192009\Backup files 23.zip a variant of Win32/SoftonicDownloader.A application G:\JOHN-PC\Backup Set 2011-10-16 192009\Backup Files 2012-02-12 190114\Backup files 8.zip HTML/ScrInject.B.Gen virus G:\JOHN-PC\Backup Set 2011-10-16 192009\Backup Files 2012-02-12 190114\Backup files 9.zip HTML/ScrInject.B.Gen virus G:\JOHN-PC\Backup Set 2012-02-19 190009\Backup Files 2012-02-19 190009\Backup files 25.zip Win32/RegistryBooster application G:\JOHN-PC\Backup Set 2012-02-19 190009\Backup Files 2012-02-19 190009\Backup files 26.zip a variant of Win32/SoftonicDownloader.A application G:\JOHN-PC\Backup Set 2012-02-19 190009\Backup Files 2012-03-25 190009\Backup files 2.zip multiple threats G:\JOHN-PC\Backup Set 2012-02-19 190009\Backup Files 2012-04-01 190010\Backup files 1.zip multiple threats G:\JOHN-PC\Backup Set 2012-02-19 190009\Backup Files 2012-04-11 234740\Backup files 12.zip multiple threats G:\JOHN-PC\Backup Set 2012-04-29 190020\Backup Files 2012-04-29 190020\Backup files 20.zip multiple threats G:\JOHN-PC\Backup Set 2012-04-29 190020\Backup Files 2012-04-29 190020\Backup files 21.zip multiple threats G:\JOHN-PC\Backup Set 2012-04-29 190020\Backup Files 2012-04-29 190020\Backup files 25.zip multiple threats G:\JOHN-PC\Backup Set 2012-04-29 190020\Backup Files 2012-04-29 190020\Backup files 30.zip multiple threats G:\JOHN-PC\Backup Set 2012-04-29 190020\Backup Files 2012-05-06 190015\Backup files 2.zip Win32/Boaxxe.C trojan G:\JOHN-PC\Backup Set 2012-04-29 190020\Backup Files 2012-05-29 140123\Backup files 2.zip Win32/SoftonicDownloader.D application G:\Jonathan\Music\iTunes\iTunes\daniel\Norton Internet Security & Antivirus2012 19.1.1.3 Final-CRACKED-P2P+NTR.V4.02\Norton Internet Security 2012 v19.1.1.13.rar Win32/Packed.Autoit.E.Gen application G:\Jonathan\Music\iTunes\iTunes\daniel\Norton Internet Security & Antivirus2012 19.1.1.3 Final-CRACKED-P2P+NTR.V4.02\Norton Internet Security 2012 v19.1.1.13\1BOX_NTR2012_v4.02\1BOX_NTR2012.exe Win32/Packed.Autoit.E.Gen application
Hi jonk1,

Looks like you have various infections on your backup drive. These should be OK as long as you don't open or restore the backups. I also see a cracked version of Norton Internet Security. Are you aware of the threats that come from downloading cracked software, especially anti-virus software? There are many free and effective antivirus programs on the market such as Microsoft Security Essentials which I prefer over Norton. You shouldn't have to resort to cracked software to protect your system.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/index.php?s=&showtopic=123766&view=findpost&p=791198

Collect::
C:\ProgramData\Microsoft\Windows\DRM\FB07.tmp.dat
C:\Users\All Users\Microsoft\Windows\DRM\FB07.tmp.dat
C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\q50relbx.default\extensions\[removed]
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe



Then post the results log using Copy / Paste
i just noticed by the way a redirect just now i guess that not solved. also i dont use the cracked one i have bought and am using an official version of norton i will do what you are saying
it was working restearted started to get the log and then a mesage came up and said Combofix needs to submit malware files for furthur analysis. Please ensure that you're connected to the internet before clicking ok…. should i click ok?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI