This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Newsfudge! [Solved]

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My laptop has redirect virus. The most common site I get redirected to is Newsfudge. It happens both in IE and in Firefox (I recently made the move to Firefox). Also, IE in particular seems to lock up quite a bit with the standard (not responding) alert while browsing.

Help!

Here are the OTL logs:

OTL Extras logfile created on: 7/21/2012 12:05:31 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Dean\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 74.07% Memory free
4.84 Gb Paging File | 4.25 Gb Available in Paging File | 87.80% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.02 Gb Total Space | 66.74 Gb Free Space | 74.97% Space Free | Partition Type: NTFS

Computer Name: MOLESWORTH | User Name: Dean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad EasyEject Utility
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3544DED1-07DB-40C0-98F3-435A6DA195C7}" = Google SketchUp 8
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{44E9D4C2-946C-4378-9354-558803C47A68}" = Client Security - Password Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78E83B4F-7230-4F0B-B1AD-8DDF05473D6F}" = Intel® PROSet/Wireless WiFi Software
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DA0C101-5C7C-40C9-A485-68E12780232C}" = Sierra Wireless MC5720 Package for Access Connections
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{987F1753-1F42-4DF2-A5EA-0CCB777F3EB0}" = ASPCA Reminder by We-Care.com v4.0.19.1
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}" = ThinkPad 11a/b/g/n Wireless LAN Mini-PCI Express Adapter
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Power Manager
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF5737AF-8550-4546-A69B-0EA9EF5A9B55}" = ThinkVantage Productivity Center
"{D728E945-256D-4477-B377-6BBA693714AC}" = Productivity Center Supplement for ThinkPad
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"ATI Display Driver" = ATI Display Driver
"BrewMate_is1" = BrewMate
"CCleaner" = CCleaner
"CNXT_MODEM_HDA_HSF" = ThinkPad Modem
"Debenu PDF Maximus" = Debenu PDF Maximus [removed]
"Exact Audio Copy" = Exact Audio Copy 1.0beta3
"Family Tree Builder" = MyHeritage Family Tree Builder
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"LENOVO.SMIIF" = Lenovo System Interface Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSNINST" = MSN
"NeroMultiInstaller!UninstallKey" = Nero Suite
"OnScreenDisplay" = On Screen Display
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WinLiveSuite_Wave3" = Windows Live Essentials
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/16/2012 8:46:48 PM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32242515

Error - 7/19/2012 9:22:25 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 7/19/2012 9:22:25 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2781

Error - 7/19/2012 9:22:25 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2781

Error - 7/19/2012 9:22:27 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 7/19/2012 9:22:27 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4781

Error - 7/19/2012 9:22:27 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4781

Error - 7/19/2012 9:22:30 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 7/19/2012 9:22:30 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7047

Error - 7/19/2012 9:22:30 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7047

[ System Events ]
Error - 7/4/2012 11:04:56 AM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.

Error - 7/4/2012 4:43:51 PM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.

Error - 7/4/2012 5:01:49 PM | Computer Name = MOLESWORTH | Source = DCOM | ID = 10010
Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register
with DCOM within the required timeout.

Error - 7/4/2012 9:37:51 PM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.

Error - 7/9/2012 7:56:43 AM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.

Error - 7/15/2012 10:50:02 PM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.

Error - 7/16/2012 9:28:22 PM | Computer Name = MOLESWORTH | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).


< End of report >






OTL logfile created on: 7/21/2012 12:05:31 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Dean\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 74.07% Memory free
4.84 Gb Paging File | 4.25 Gb Available in Paging File | 87.80% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.02 Gb Total Space | 66.74 Gb Free Space | 74.97% Space Free | Partition Type: NTFS

Computer Name: MOLESWORTH | User Name: Dean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Dean\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
PRC - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo )
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\acs.exe (Atheros)
PRC - C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\f33e2a4d9b385234406fa2d662f78875\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\f121ccced1aa14badb316d8d9be5154d\UIAutomationProvider.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8b873631a0855fb6aa0ad25f1d9de7fe\PresentationFramework.Luna.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\6d8bef0d008389874e55c0308f0c18e5\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\ThinkPad\Utilities\US\PWRMGRRO.DLL ()
MOD - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
MOD - C:\Program Files\ThinkPad\Utilities\US\PWRMGRRT.DLL ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACAthV2MSVC6.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACNewBiosHelper.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\IconRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\GUIHlprRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\SvcHlprRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACAthV2ExtDLL.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (DozeSvc) – C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
SRV - (Power Manager DBC Service) – C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
SRV - (AcSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (AcPrfMgrSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (TPHKSVC) – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) – C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (acs) – C:\WINDOWS\system32\acs.exe (Atheros)
SRV - (ThinkVantage Registry Monitor Service) – C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (psadd) – C:\WINDOWS\system32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (DozeHDD) – C:\WINDOWS\system32\drivers\DOZEHDD.SYS (Lenovo.)
DRV - (TPPWRIF) – C:\WINDOWS\system32\drivers\TPPWRIF.SYS ()
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (Shockprf) – C:\WINDOWS\system32\drivers\ApsX86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\WINDOWS\system32\drivers\ApsHM86.sys (Lenovo.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (IBMTPCHK) – C:\WINDOWS\system32\drivers\IBMBLDID.sys ()
DRV - (lenovo.smi) – C:\WINDOWS\system32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (TVTI2C) – C:\WINDOWS\system32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (WSIMD) – C:\WINDOWS\system32\drivers\wsimd.sys (Atheros Communications, Inc.)
DRV - (swmx01) Sierra Wireless USB MUX Driver (#01) – C:\WINDOWS\system32\drivers\swmx01.sys (Sierra Wireless Corporation)
DRV - (ANC) – C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (SWNC5E01) Sierra Wireless MUX NDIS Driver (#01) – C:\WINDOWS\system32\drivers\SWNC5E01.sys (Sierra Wireless Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/08 13:42:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{89198AC7-A618-11E1-8270-B8AC6F996F26}: C:\Documents and Settings\Dean\Local Settings\Application Data\{89198AC7-A618-11E1-8270-B8AC6F996F26}\ [2012/05/24 23:20:21 | 000,000,000 | —D | M]

[2012/04/14 16:54:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dean\Application Data\Mozilla\Extensions
[2012/07/21 10:19:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dean\Application Data\Mozilla\Firefox\Profiles\iixrskxw.default\extensions
[2012/07/21 10:19:09 | 000,000,000 | —D | M] ("I Want This") – C:\Documents and Settings\Dean\Application Data\Mozilla\Firefox\Profiles\iixrskxw.default\extensions\[removed]
[2012/04/14 16:54:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/08 14:16:57 | 000,003,793 | —- | M] () (No name found) – C:\DOCUMENTS AND SETTINGS\DEAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\IIXRSKXW.DEFAULT\EXTENSIONS\{66E978CD-981F-47DF-AC42-E3CF417C1467}.XPI
[2012/05/24 23:20:21 | 000,000,000 | —D | M] (Mozilla Safe Browsing) – C:\DOCUMENTS AND SETTINGS\DEAN\LOCAL SETTINGS\APPLICATION DATA\{89198AC7-A618-11E1-8270-B8AC6F996F26}
[2012/07/08 13:42:34 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/07/08 13:42:30 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/08 13:42:30 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: We-Care Reminder = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ippkomaaonokjnfjoikaemidanojkfmm\1.0.0.25_0\
CHR - Extension: Gmail = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2008/08/21 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (IePasswordManagerHelper Class) - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Debenu PDF Maximus Watched Folder Agent] C:\Program Files\Debenu\PDF Maximus\MaximusWatchedFolders.exe (Debenu)
O4 - HKLM..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe (MyHeritage)
O4 - HKLM..\Run: [LPMailChecker] C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - Startup: C:\Documents and Settings\Dean\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Lenovo Password Manager… - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1341434498890 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9665963E-2A59-4F40-90CE-230724DBB3AC}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - (ACNotify.dll) - C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Dean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/30 14:28:30 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/21 12:02:51 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Dean\Recent
[2012/07/18 19:39:32 | 000,426,184 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/18 19:39:32 | 000,070,344 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/18 19:35:21 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/07/09 10:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\Start Menu\Programs\Debenu PDF Maximus
[2012/07/09 10:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Debenu
[2012/07/09 10:09:16 | 000,000,000 | —D | C] – C:\Program Files\Debenu
[2012/07/09 08:01:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\My Documents\Amazon MP3
[2012/07/09 08:01:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\Application Data\Amazon
[2012/07/09 08:00:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Amazon
[2012/07/09 08:00:17 | 000,000,000 | —D | C] – C:\Program Files\Amazon
[2012/07/08 13:42:36 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/07/08 13:42:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2012/07/04 20:59:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/07/04 20:59:32 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2012/07/04 20:58:48 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/07/04 20:58:44 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/07/04 20:58:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/04 20:58:27 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2012/07/04 20:58:11 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/21 12:03:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2978286325-1291239056-3539293820-1004UA.job
[2012/07/21 11:53:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/21 10:18:37 | 000,000,316 | —- | M] () – C:\WINDOWS\tasks\PMTask.job
[2012/07/21 10:18:16 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/07/21 10:17:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/07/19 09:03:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2978286325-1291239056-3539293820-1004Core.job
[2012/07/18 19:53:10 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/18 19:53:10 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/12 21:20:35 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/12 08:33:39 | 000,123,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/12 08:01:38 | 000,002,255 | —- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/07/09 08:00:18 | 000,001,852 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/07/04 20:59:33 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/07/04 11:18:29 | 000,000,024 | —- | M] () – C:\WINDOWS\AM_D7.PRF
[2012/07/03 13:46:44 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/07/01 00:10:59 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/06/30 16:44:57 | 000,001,754 | -H– | M] () – C:\Documents and Settings\Dean\My Documents\Default.rdp
[2012/06/30 16:06:13 | 000,000,468 | —- | M] () – C:\Documents and Settings\Dean\My Documents\spider.sav
[2012/06/24 12:12:06 | 000,145,383 | —- | M] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skp
[2012/06/24 12:04:08 | 000,143,985 | —- | M] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skb
[2012/06/24 01:23:50 | 000,000,151 | —- | M] () – C:\WINDOWS\PhotoSnapViewer.INI
[2012/06/22 23:49:00 | 000,139,290 | —- | M] () – C:\Documents and Settings\Dean\My Documents\entry table square.skp
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/18 19:39:33 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/09 08:00:18 | 000,001,852 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/07/04 20:59:33 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/07/04 11:18:29 | 000,000,024 | —- | C] () – C:\WINDOWS\AM_D7.PRF
[2012/06/30 16:06:13 | 000,000,468 | —- | C] () – C:\Documents and Settings\Dean\My Documents\spider.sav
[2012/06/24 12:12:06 | 000,143,985 | —- | C] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skb
[2012/06/24 12:04:08 | 000,145,383 | —- | C] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skp
[2012/06/18 22:51:07 | 000,000,417 | —- | C] () – C:\WINDOWS\MyHeritage.INI
[2012/06/18 22:47:52 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2012/06/05 23:26:47 | 000,132,302 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2978286325-1291239056-3539293820-1004-0.dat
[2012/06/05 23:26:46 | 000,132,302 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/05/17 23:14:06 | 000,073,488 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/03/18 16:28:11 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2012/03/11 01:39:47 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2012/02/15 07:28:49 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/19 00:44:13 | 007,549,704 | —- | C] () – C:\Program Files\InternationalPrimoPDF.exe
[2012/01/19 00:37:29 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2010/09/02 09:29:25 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/09/01 12:17:42 | 000,004,224 | —- | C] () – C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2010/09/01 09:15:04 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2010/09/01 09:15:04 | 000,262,216 | —- | C] () – C:\WINDOWS\System32\IPTests.dll
[2010/09/01 09:15:04 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2010/08/31 15:02:54 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/08/31 15:00:09 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/08/31 15:00:09 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/08/31 15:00:08 | 000,189,051 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/08/31 14:54:09 | 000,008,572 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/31 13:41:54 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/08/31 13:26:48 | 000,196,608 | —- | C] () – C:\WINDOWS\PWMBTHLP.EXE
[2010/08/31 13:26:47 | 000,004,442 | —- | C] () – C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2010/08/30 14:36:38 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/08/30 14:36:38 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/08/30 14:36:38 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/08/30 14:36:38 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/08/30 14:36:38 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/08/30 14:36:38 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/08/30 14:30:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/30 14:26:39 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/30 14:15:51 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/30 14:15:49 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2010/08/30 14:15:49 | 000,473,482 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/30 14:15:49 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2010/08/30 14:15:49 | 000,076,410 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/30 14:15:49 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2010/08/30 14:15:49 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2010/08/30 14:15:49 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2010/08/30 14:15:48 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2010/08/30 14:15:48 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2010/08/30 14:15:41 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2010/08/30 14:15:41 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2010/08/30 07:24:25 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/30 07:23:50 | 000,123,728 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2012/07/09 10:09:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Debenu
[2012/01/12 22:39:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lenovo
[2012/06/18 22:54:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/30 14:49:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UIB
[2012/05/28 11:01:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2012/07/04 20:59:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/09 08:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Amazon
[2012/01/12 22:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Avaya
[2012/02/25 17:47:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\EAC
[2012/06/05 11:22:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Garmin
[2010/09/01 12:59:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Lenovo
[2012/06/18 22:49:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\MyHeritage
[2012/04/14 13:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\OpenOffice.org
[2012/01/19 00:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\PrimoPDF
[2012/06/18 22:47:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\The Complete Genealogy Reporter - FTB
[2012/07/21 10:18:37 | 000,000,316 | —- | M] () – C:\WINDOWS\Tasks\PMTask.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/03/01 22:28:39 | 066,895,628 | —- | M] () – C:\01 Discovery.wav
[2012/03/02 01:00:32 | 079,591,724 | —- | M] () – C:\01 Gunslinging Bird.wav
[2012/03/02 01:02:22 | 063,163,004 | —- | M] () – C:\02 New Now Know How.wav
[2012/03/01 22:31:16 | 091,438,748 | —- | M] () – C:\02 Special Beings.wav
[2012/03/02 01:03:17 | 030,503,132 | —- | M] () – C:\03 Self-Portrait In Three Colors.wav
[2012/03/01 22:33:22 | 081,823,772 | —- | M] () – C:\03 The Fine Line.wav
[2012/03/02 01:04:51 | 061,768,268 | —- | M] () – C:\04 Birdcalls.wav
[2012/03/01 22:34:42 | 047,082,380 | —- | M] () – C:\04 Lost and Found.wav
[2012/03/02 01:06:36 | 075,555,692 | —- | M] () – C:\05 E's Flat Ah's Flat Too (Aka ''Hora Decubitus'').wav
[2012/03/01 22:36:15 | 067,326,044 | —- | M] () – C:\05 Recovery.wav
[2012/03/02 01:08:18 | 080,297,324 | —- | M] () – C:\06 Cryin' Blues.wav
[2012/03/01 22:37:46 | 069,588,668 | —- | M] () – C:\06 To the One.wav
[2012/03/02 01:09:58 | 076,251,884 | —- | M] () – C:\07 Open Letter To Duke.wav
[2012/03/02 01:11:50 | 101,415,932 | —- | M] () – C:\08 Moanin'.wav
[2012/03/02 01:12:57 | 062,062,268 | —- | M] () – C:\09 Goodbye Pork Pie Hat.wav
[2012/03/02 01:15:06 | 131,025,260 | —- | M] () – C:\10 Song With Orange.wav
[2010/08/30 14:28:30 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/01/12 22:32:27 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2006/11/02 02:53:58 | 000,438,840 | —- | M] () – C:\bootmgr
[2009/04/20 16:30:22 | 000,057,856 | —- | M] () – C:\CabExtractor.exe
[2010/08/30 14:28:30 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/06/30 13:04:06 | 000,000,839 | —- | M] () – C:\DeleteContent.bat
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/12/12 13:59:41 | 000,000,191 | —- | M] () – C:\ibminst.log
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/30 14:28:30 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/03/01 22:39:39 | 000,006,448 | —- | M] () – C:\John McLaughlin - To the One.log
[2012/03/02 08:06:23 | 000,008,086 | —- | M] () – C:\Mingus Big Band - Live At Jazz Standard.log
[2010/08/30 14:28:30 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/21 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 13:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/07/21 10:17:32 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/12/12 17:16:11 | 000,000,020 | —- | M] () – C:\SYSLEVEL.IBM
[2010/06/30 13:04:06 | 000,000,666 | —- | M] () – C:\UnattendInstallation.bat
[2012/03/01 20:03:42 | 000,011,986 | —- | M] () – C:\Unknown Artist - Unknown Title.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/08/30 14:28:13 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2012/01/19 00:44:26 | 007,549,704 | —- | M] () – C:\Program Files\InternationalPrimoPDF.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/08/30 07:23:26 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/08/30 07:23:26 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/08/30 07:23:26 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/12/12 14:00:09 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2010/08/30 14:37:00 | 000,000,000 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\rpkdriverinst.log

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/12 22:32:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/30 14:39:20 | 000,000,079 | —- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-12 11:57:19

< End of report >
Hello, I Am Alander :)

I would be glad to take a look at your log and help you with solving any malware problems.

Logs can take a while to research so please be patient while I work on your log and I will post back here with any recommendations.

As I am still training, everything that I post to you, must be checked by an Admin or Moderator.

Thus, there may be a tiny bit of a delay between posts. While it shouldn't be too long, you can be assured you will get the best possible advice.

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Hi :)

RogueKiller
  • Please download RogueKiller by Tigzy and save it to your desktop.
  • Allow the download if prompted by your security software and please close all your programs.
  • Double click on RogueKiller.exe to run it. If it does not run, please try a few times.
  • Wait for PreScan to finish, then click on Scan.
  • Once completed, a log called RKreport[1].txt will be created on the desktop. It can also be accessed via the Report button.
  • Please copy and paste the contents of that log in your next reply.
RogueKiller V7.6.4 [07/17/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Dean [Admin rights]
Mode: Scan – Date: 07/27/2012 18:47:46

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 3 ¤¤¤
[Rans.Gendarm] HKUS\S-1-5-19[…]\Run : Update (rundll32.exe "C:\Documents and Settings\Dean\Application Data\AccurateRip\AccurateRip\sgpeue.dll",DllRegisterServer) -> FOUND
[Rans.Gendarm] HKUS\S-1-5-20[…]\Run : Update (rundll32.exe "C:\Documents and Settings\Dean\Application Data\AccurateRip\AccurateRip\sgpeue.dll",DllRegisterServer) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : Rans.Gendarm ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: HTS721010G9SA00 +++++
— User —
[MBR] bed1c2467ac13042de2f41fd4d6d0c23
[BSP] 347c7937d30c603c186ce000ae21e326 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 91157 Mo
1 - [XXXXXX] UNKNOWN (0x13) [VISIBLE] Offset (sectors): 186691584 | Size: 4237 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive1: WD 5000AAKB Externa USB Device +++++
— User —
[MBR] 07886398f5223b638cfda8b3ebd2ffd6
[BSP] 96545aae4c3a8e5d84fbb99372be0652 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[1].txt >>
RKreport[1].txt
Hi :) Sorry for the delay

Step 1
Please download OTL by Old Timer and save it to your Desktop.

  • Double click on OTL.exe to run it.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When done, two Notepad files will open.
    • OTL.txt <– Will be opened
    • Extras.txt <– Will be minimized
  • Please post the contents of these 2 Notepad files in your next reply.

Step 2.
Please download aswMBR and save it to your Desktop.
  • Double click aswMBR.exe to run it.
  • Click Yes to the prompt to download Avast! virus definitions.
    (Please be patient whilst the virus definitions download)
  • With the AVscan set to Quick Scan, click the Scan button.
    (Please be patient whilst your computer is scanned.)
  • After a while when the scan reports "Scan finished successfully", click Save log & save the log to your desktop.
  • Click OK > Exit.
  • Note: Do not attempt to fix anything at this stage!
  • Two files will be created, aswMBR.txt & a file named MBR.dat.
  • MBR.dat is a backup of the MBR(master boot record), do not delete it..
  • I strongly suggest you keep a copy of this backup stored on an external device.
  • Copy & Paste the contents of aswMBR.txt into your next reply.

Step 3.
Please include in your next reply:
  • Any problem executing the instructions?
  • OTL and Extras.txt
  • ASWMBR Log
Thanks
Hello.. Thank you for your help. I will be unavailable to continue for about a week. Please keep the thread open, and I will resume as soon as I can. Thanks again!
10 Day Response
Hello…
It has been a week since my last post to you.
  • Do you still need help with this problem?
  • Do you need more time?
  • Are you having problems understanding or following my instructions?
Just let me know what's going on otherwise…
After 24 hrs., if you have not replied to this thread… it will be closed!
Hey, sorry for the delay. I've been out of the country, and just got back. Please do not lock. I will be able to continue tonight. Thanks!
OTL logfile created on: 8/9/2012 8:27:35 PM - Run 3
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Documents and Settings\Dean\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.16 Gb Available Physical Memory | 71.99% Memory free
4.84 Gb Paging File | 4.20 Gb Available in Paging File | 86.84% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.02 Gb Total Space | 66.69 Gb Free Space | 74.92% Space Free | Partition Type: NTFS

Computer Name: MOLESWORTH | User Name: Dean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Dean\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Debenu\PDF Maximus\MaximusWatchedFolders.exe (Debenu)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
PRC - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo )
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\acs.exe (Atheros)
PRC - C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (InstallShield Software Corporation)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\f33e2a4d9b385234406fa2d662f78875\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\f121ccced1aa14badb316d8d9be5154d\UIAutomationProvider.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8b873631a0855fb6aa0ad25f1d9de7fe\PresentationFramework.Luna.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\6d8bef0d008389874e55c0308f0c18e5\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\Debenu\PDF Maximus\QtGui4.dll ()
MOD - C:\Program Files\Debenu\PDF Maximus\QtNetwork4.dll ()
MOD - C:\Program Files\Debenu\PDF Maximus\QtCore4.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\ThinkPad\Utilities\US\PWRMGRRO.DLL ()
MOD - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
MOD - C:\Program Files\ThinkPad\Utilities\US\PWRMGRRT.DLL ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACAthV2MSVC6.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACNewBiosHelper.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\IconRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\GUIHlprRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\SvcHlprRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACAthV2ExtDLL.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (DozeSvc) – C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
SRV - (Power Manager DBC Service) – C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
SRV - (AcSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (AcPrfMgrSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (TPHKSVC) – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) – C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (S24EventMonitor) – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (acs) – C:\WINDOWS\system32\acs.exe (Atheros)
SRV - (ThinkVantage Registry Monitor Service) – C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (psadd) – C:\WINDOWS\system32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (DozeHDD) – C:\WINDOWS\system32\drivers\DOZEHDD.SYS (Lenovo.)
DRV - (TPPWRIF) – C:\WINDOWS\system32\drivers\TPPWRIF.SYS ()
DRV - (NETw5x32) – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (Shockprf) – C:\WINDOWS\system32\drivers\ApsX86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\WINDOWS\system32\drivers\ApsHM86.sys (Lenovo.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (IBMTPCHK) – C:\WINDOWS\system32\drivers\IBMBLDID.sys ()
DRV - (lenovo.smi) – C:\WINDOWS\system32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (TVTI2C) – C:\WINDOWS\system32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (WSIMD) – C:\WINDOWS\system32\drivers\wsimd.sys (Atheros Communications, Inc.)
DRV - (swmx01) – C:\WINDOWS\system32\drivers\swmx01.sys (Sierra Wireless Corporation)
DRV - (ANC) – C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (SWNC5E01) – C:\WINDOWS\system32\drivers\SWNC5E01.sys (Sierra Wireless Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/27 22:54:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{89198AC7-A618-11E1-8270-B8AC6F996F26}: C:\Documents and Settings\Dean\Local Settings\Application Data\{89198AC7-A618-11E1-8270-B8AC6F996F26}\ [2012/05/24 23:20:21 | 000,000,000 | —D | M]

[2012/04/14 16:54:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dean\Application Data\Mozilla\Extensions
[2012/08/08 21:07:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dean\Application Data\Mozilla\Firefox\Profiles\iixrskxw.default\extensions
[2012/08/08 21:07:43 | 000,000,000 | —D | M] ("I Want This") – C:\Documents and Settings\Dean\Application Data\Mozilla\Firefox\Profiles\iixrskxw.default\extensions\[removed]
[2012/04/14 16:54:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/08 14:16:57 | 000,003,793 | —- | M] () (No name found) – C:\DOCUMENTS AND SETTINGS\DEAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\IIXRSKXW.DEFAULT\EXTENSIONS\{66E978CD-981F-47DF-AC42-E3CF417C1467}.XPI
[2012/05/24 23:20:21 | 000,000,000 | —D | M] (Mozilla Safe Browsing) – C:\DOCUMENTS AND SETTINGS\DEAN\LOCAL SETTINGS\APPLICATION DATA\{89198AC7-A618-11E1-8270-B8AC6F996F26}
[2012/07/27 22:54:33 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/07/08 13:42:30 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/08 13:42:30 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: We-Care Reminder = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ippkomaaonokjnfjoikaemidanojkfmm\1.0.0.25_0\
CHR - Extension: Gmail = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2008/08/21 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (IePasswordManagerHelper Class) - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Debenu PDF Maximus Watched Folder Agent] C:\Program Files\Debenu\PDF Maximus\MaximusWatchedFolders.exe (Debenu)
O4 - HKLM..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe (MyHeritage)
O4 - HKLM..\Run: [LPMailChecker] C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - Startup: C:\Documents and Settings\Dean\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Lenovo Password Manager… - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1341434498890 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9665963E-2A59-4F40-90CE-230724DBB3AC}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - (ACNotify.dll) - C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Dean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/30 14:28:30 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/09 20:26:58 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dean\Desktop\OTL.exe
[2012/08/09 08:00:40 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Dean\Recent
[2012/07/27 18:46:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\Desktop\RK_Quarantine
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/08/09 20:26:58 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dean\Desktop\OTL.exe
[2012/08/09 20:03:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2978286325-1291239056-3539293820-1004UA.job
[2012/08/09 09:03:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2978286325-1291239056-3539293820-1004Core.job
[2012/08/09 08:53:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/08/09 07:55:27 | 000,000,316 | —- | M] () – C:\WINDOWS\tasks\PMTask.job
[2012/08/08 20:05:49 | 000,002,255 | —- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/08 19:23:01 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/08/08 19:22:11 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/07/21 17:30:00 | 000,079,394 | —- | M] () – C:\Documents and Settings\Dean\Desktop\jammed_truss_rod_washer.JPG
[2012/07/12 21:20:35 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/12 08:33:39 | 000,123,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/21 17:30:00 | 000,079,394 | —- | C] () – C:\Documents and Settings\Dean\Desktop\jammed_truss_rod_washer.JPG
[2012/07/18 19:39:33 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/18 22:51:07 | 000,000,417 | —- | C] () – C:\WINDOWS\MyHeritage.INI
[2012/06/18 22:47:52 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2012/06/05 23:26:47 | 000,132,302 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2978286325-1291239056-3539293820-1004-0.dat
[2012/06/05 23:26:46 | 000,132,302 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/05/17 23:14:06 | 000,073,488 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/03/18 16:28:11 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2012/03/11 01:39:47 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2012/02/15 07:28:49 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/19 00:44:13 | 007,549,704 | —- | C] () – C:\Program Files\InternationalPrimoPDF.exe
[2012/01/19 00:37:29 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2010/09/02 09:29:25 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/09/01 12:17:42 | 000,004,224 | —- | C] () – C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2010/09/01 09:15:04 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2010/09/01 09:15:04 | 000,262,216 | —- | C] () – C:\WINDOWS\System32\IPTests.dll
[2010/09/01 09:15:04 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2010/08/31 15:02:54 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/08/31 15:00:09 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/08/31 15:00:09 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/08/31 15:00:08 | 000,189,051 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/08/31 14:54:09 | 000,008,572 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/31 13:41:54 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/08/31 13:26:48 | 000,196,608 | —- | C] () – C:\WINDOWS\PWMBTHLP.EXE
[2010/08/31 13:26:47 | 000,004,442 | —- | C] () – C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2010/08/30 14:36:38 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/08/30 14:36:38 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/08/30 14:36:38 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/08/30 14:36:38 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/08/30 14:36:38 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/08/30 14:36:38 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/08/30 14:30:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/30 14:26:39 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/30 14:15:51 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/30 14:15:49 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2010/08/30 14:15:49 | 000,473,482 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/30 14:15:49 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2010/08/30 14:15:49 | 000,076,410 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/30 14:15:49 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2010/08/30 14:15:49 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2010/08/30 14:15:49 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2010/08/30 14:15:48 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2010/08/30 14:15:48 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2010/08/30 14:15:41 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2010/08/30 14:15:41 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2010/08/30 07:24:25 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/30 07:23:50 | 000,123,728 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2012/07/09 10:09:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Debenu
[2012/01/12 22:39:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lenovo
[2012/06/18 22:54:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/30 14:49:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UIB
[2012/05/28 11:01:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2012/07/04 20:59:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/09 08:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Amazon
[2012/01/12 22:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Avaya
[2012/02/25 17:47:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\EAC
[2012/06/05 11:22:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Garmin
[2010/09/01 12:59:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Lenovo
[2012/06/18 22:49:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\MyHeritage
[2012/04/14 13:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\OpenOffice.org
[2012/01/19 00:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\PrimoPDF
[2012/06/18 22:47:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\The Complete Genealogy Reporter - FTB
[2012/08/09 07:55:27 | 000,000,316 | —- | M] () – C:\WINDOWS\Tasks\PMTask.job

========== Purity Check ==========



< End of report >





* There was no Extras file minimized or saved to the desktop. In fact, no Extras.txt file was found at all by a search.






aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-09 21:02:59
—————————–
21:02:59.625 OS Version: Windows 5.1.2600 Service Pack 3
21:02:59.625 Number of processors: 2 586 0xF06
21:02:59.640 ComputerName: MOLESWORTH UserName: Dean
21:03:00.312 Initialize success
21:04:19.281 AVAST engine defs: 12080901
21:05:50.328 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
21:05:50.328 Disk 0 Vendor: HTS72101 MCZI Size: 95396MB BusType: 3
21:05:50.359 Disk 0 MBR read successfully
21:05:50.359 Disk 0 MBR scan
21:05:50.406 Disk 0 Windows VISTA default MBR code
21:05:50.421 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 91157 MB offset 2048
21:05:50.453 Disk 0 Partition 2 00 13 NTFS 4237 MB offset 186691584
21:05:50.453 Disk 0 scanning sectors +195368960
21:05:50.531 Disk 0 scanning C:\WINDOWS\system32\drivers
21:05:58.406 Service scanning
21:06:19.437 Modules scanning
21:06:26.968 Disk 0 trace - called modules:
21:06:26.984 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys
21:06:26.984 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a4af030]
21:06:26.984 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000084[0x8a4d3910]
21:06:26.984 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8a4bf030]
21:06:27.625 AVAST engine scan C:\WINDOWS
21:06:31.093 AVAST engine scan C:\WINDOWS\system32
21:08:45.625 AVAST engine scan C:\WINDOWS\system32\drivers
21:08:55.703 AVAST engine scan C:\Documents and Settings\Dean
21:10:24.078 AVAST engine scan C:\Documents and Settings\All Users
21:10:31.203 Scan finished successfully
21:23:06.328 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Dean\Desktop\MBR.dat"
21:23:06.328 The log file has been saved successfully to "C:\Documents and Settings\Dean\Desktop\aswMBR.txt"





* A file named MBR (1 kb) appeared on my desktop. It showed up as a NeroMediaPlayer media file, not a .dat file. Clicking on it resulted in Nero Media Player attempting to read or play it, and I got "Audio source plugin error: FileInvalid" I copied it to my externalHD.
Hi :)

Step 1
TDSSKiller

Please download TDSSKiller.exe and save it to your Desktop.
  • Double click on TDSSKiller.exe to launch it.
  • Click on Start Scan, the scan will run.
  • When the scan has finished, if it finds anything please click on the drop down arrow next to Cure and select Skip
  • Now click on Report to open the log file created by TDSSKiller in your root directory C:\
  • To find the log go to Start > Computer > C:
  • Post the contents of that log in your next reply please.
  • DO NOT TRY TO FIX ANYTHING AT THIS POINT

Step 2
As you have Malwarebytes' Anti-Malware installed on your computer. Could you please do a scan using these settings:

  • Launch the application, Check for Updates >> Perform Quick Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Check all items except items in the C:\System Volume Information folder… and click Remove Selected.
    Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Step 3.
Please include in your next reply:
  • Any problem executing the instructions?
  • TDSS Killer Log
  • MBAM Log
  • How is the computer behaving?
Thanks
10:31:36.0359 2112 TDSS rootkit removing tool [removed] Jul 24 2012 13:16:32 10:31:36.0609 2112 ============================================================ 10:31:36.0609 2112 Current date / time: 2012/08/12 10:31:36.0609 10:31:36.0609 2112 SystemInfo: 10:31:36.0609 2112 10:31:36.0609 2112 OS Version: 5.1.2600 ServicePack: 3.0 10:31:36.0609 2112 Product type: Workstation 10:31:36.0609 2112 ComputerName: MOLESWORTH 10:31:36.0609 2112 UserName: Dean 10:31:36.0609 2112 Windows directory: C:\WINDOWS 10:31:36.0609 2112 System windows directory: C:\WINDOWS 10:31:36.0609 2112 Processor architecture: Intel x86 10:31:36.0609 2112 Number of processors: 2 10:31:36.0609 2112 Page size: 0x1000 10:31:36.0609 2112 Boot type: Normal boot 10:31:36.0609 2112 ============================================================ 10:31:37.0296 2112 Drive \Device\Harddisk0\DR0 - Size: 0x174A446000 (93.16 Gb), SectorSize: 0x200, Cylinders: 0x3279, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050 10:31:37.0296 2112 ============================================================ 10:31:37.0296 2112 \Device\Harddisk0\DR0: 10:31:37.0296 2112 MBR partitions: 10:31:37.0296 2112 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xB20A800 10:31:37.0296 2112 ============================================================ 10:31:37.0343 2112 C: <-> \Device\Harddisk0\DR0\Partition0 10:31:37.0343 2112 ============================================================ 10:31:37.0343 2112 Initialize success 10:31:37.0343 2112 ============================================================ 10:31:45.0281 4504 ============================================================ 10:31:45.0281 4504 Scan started 10:31:45.0281 4504 Mode: Manual; 10:31:45.0281 4504 ============================================================ 10:31:45.0890 4504 Abiosdsk - ok 10:31:45.0890 4504 abp480n5 - ok 10:31:45.0953 4504 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 10:31:45.0953 4504 ACPI - ok 10:31:45.0968 4504 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 10:31:45.0968 4504 ACPIEC - ok 10:31:46.0046 4504 AcPrfMgrSvc (0001c6d053f02796d7ee29720e355cac) C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe 10:31:46.0062 4504 AcPrfMgrSvc - ok 10:31:46.0140 4504 acs (57e569b5123e984133769e287a25a819) C:\WINDOWS\system32\acs.exe 10:31:46.0140 4504 acs - ok 10:31:46.0171 4504 AcSvc (0ef384464375b84b96f05ce4c17330d0) C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe 10:31:46.0171 4504 AcSvc - ok 10:31:46.0234 4504 ADIHdAudAddService (beee84a79710f705864685b05f1bb172) C:\WINDOWS\system32\drivers\ADIHdAud.sys 10:31:46.0234 4504 ADIHdAudAddService - ok 10:31:46.0328 4504 AdobeFlashPlayerUpdateSvc (f19c98ad81d2c0e1bbfd8153d2c80ee8) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 10:31:46.0328 4504 AdobeFlashPlayerUpdateSvc - ok 10:31:46.0328 4504 adpu160m - ok 10:31:46.0343 4504 AEAudioService (358063ab6c1c4173b735525cdfa65f94) C:\WINDOWS\system32\drivers\AEAudio.sys 10:31:46.0343 4504 AEAudioService - ok 10:31:46.0406 4504 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 10:31:46.0406 4504 aec - ok 10:31:46.0437 4504 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 10:31:46.0437 4504 AFD - ok 10:31:46.0453 4504 Aha154x - ok 10:31:46.0453 4504 aic78u2 - ok 10:31:46.0453 4504 aic78xx - ok 10:31:46.0484 4504 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll 10:31:46.0484 4504 Alerter - ok 10:31:46.0500 4504 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe 10:31:46.0500 4504 ALG - ok 10:31:46.0515 4504 AliIde - ok 10:31:46.0515 4504 amsint - ok 10:31:46.0546 4504 ANC (11ab185a7af224800bbfb5b836974a17) C:\WINDOWS\system32\drivers\ANC.SYS 10:31:46.0546 4504 ANC - ok 10:31:46.0640 4504 Apple Mobile Device (f401929ee0cc92bfe7f15161ca535383) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 10:31:46.0656 4504 Apple Mobile Device - ok 10:31:46.0703 4504 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll 10:31:46.0703 4504 AppMgmt - ok 10:31:46.0843 4504 AR5416 (e0bdecf0eabd175e43df5691ad540aa1) C:\WINDOWS\system32\DRIVERS\athw.sys 10:31:46.0875 4504 AR5416 - ok 10:31:46.0890 4504 asc - ok 10:31:46.0890 4504 asc3350p - ok 10:31:46.0890 4504 asc3550 - ok 10:31:46.0984 4504 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 10:31:47.0000 4504 aspnet_state - ok 10:31:47.0015 4504 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 10:31:47.0015 4504 AsyncMac - ok 10:31:47.0046 4504 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 10:31:47.0046 4504 atapi - ok 10:31:47.0062 4504 Atdisk - ok 10:31:47.0156 4504 Ati HotKey Poller (b921d1790a8ef84b2dbdeeef4909fba1) C:\WINDOWS\system32\Ati2evxx.exe 10:31:47.0171 4504 Ati HotKey Poller - ok 10:31:47.0515 4504 ati2mtag (5a13723fb8bfdd2090defb2d0cb98a27) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 10:31:47.0546 4504 ati2mtag - ok 10:31:47.0718 4504 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 10:31:47.0718 4504 Atmarpc - ok 10:31:47.0750 4504 atmeltpm (dbf0d7e2df33b469eb55406fea759350) C:\WINDOWS\system32\DRIVERS\atmeltpm.sys 10:31:47.0750 4504 atmeltpm - ok 10:31:47.0781 4504 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll 10:31:47.0781 4504 AudioSrv - ok 10:31:47.0796 4504 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 10:31:47.0796 4504 audstub - ok 10:31:47.0812 4504 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 10:31:47.0812 4504 Beep - ok 10:31:47.0875 4504 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll 10:31:47.0890 4504 BITS - ok 10:31:48.0031 4504 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe 10:31:48.0031 4504 Bonjour Service - ok 10:31:48.0078 4504 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll 10:31:48.0078 4504 Browser - ok 10:31:48.0093 4504 BTWUSB (90078a07da643317d9de386d87cd7604) C:\WINDOWS\system32\Drivers\btwusb.sys 10:31:48.0093 4504 BTWUSB - ok 10:31:48.0125 4504 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 10:31:48.0125 4504 cbidf2k - ok 10:31:48.0125 4504 cd20xrnt - ok 10:31:48.0125 4504 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 10:31:48.0125 4504 Cdaudio - ok 10:31:48.0156 4504 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 10:31:48.0156 4504 Cdfs - ok 10:31:48.0187 4504 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 10:31:48.0187 4504 Cdrom - ok 10:31:48.0187 4504 Changer - ok 10:31:48.0218 4504 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe 10:31:48.0218 4504 CiSvc - ok 10:31:48.0234 4504 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe 10:31:48.0234 4504 ClipSrv - ok 10:31:48.0328 4504 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 10:31:48.0328 4504 clr_optimization_v2.0.50727_32 - ok 10:31:48.0390 4504 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 10:31:48.0390 4504 clr_optimization_v4.0.30319_32 - ok 10:31:48.0421 4504 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 10:31:48.0421 4504 CmBatt - ok 10:31:48.0421 4504 CmdIde - ok 10:31:48.0453 4504 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 10:31:48.0453 4504 Compbatt - ok 10:31:48.0453 4504 COMSysApp - ok 10:31:48.0468 4504 Cpqarray - ok 10:31:48.0484 4504 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll 10:31:48.0500 4504 CryptSvc - ok 10:31:48.0500 4504 dac2w2k - ok 10:31:48.0500 4504 dac960nt - ok 10:31:48.0578 4504 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll 10:31:48.0578 4504 DcomLaunch - ok 10:31:48.0625 4504 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll 10:31:48.0640 4504 Dhcp - ok 10:31:48.0640 4504 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 10:31:48.0640 4504 Disk - ok 10:31:48.0640 4504 dmadmin - ok 10:31:48.0750 4504 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 10:31:48.0765 4504 dmboot - ok 10:31:48.0796 4504 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 10:31:48.0796 4504 dmio - ok 10:31:48.0812 4504 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 10:31:48.0812 4504 dmload - ok 10:31:48.0843 4504 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll 10:31:48.0843 4504 dmserver - ok 10:31:48.0859 4504 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 10:31:48.0859 4504 DMusic - ok 10:31:48.0906 4504 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll 10:31:48.0906 4504 Dnscache - ok 10:31:49.0203 4504 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll 10:31:49.0203 4504 Dot3svc - ok 10:31:49.0234 4504 DozeHDD (e00b3ce273b17aee1259c105df5524ca) C:\WINDOWS\system32\DRIVERS\DozeHDD.sys 10:31:49.0234 4504 DozeHDD - ok 10:31:49.0343 4504 DozeSvc (003acee8650bfd49e4121289bbf59480) C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE 10:31:49.0343 4504 DozeSvc - ok 10:31:49.0359 4504 dpti2o - ok 10:31:49.0390 4504 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 10:31:49.0390 4504 drmkaud - ok 10:31:49.0453 4504 e1express (06d94f4543671b497a5f4a0aedd5e36a) C:\WINDOWS\system32\DRIVERS\e1e5132.sys 10:31:49.0453 4504 e1express - ok 10:31:49.0484 4504 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll 10:31:49.0484 4504 EapHost - ok 10:31:49.0500 4504 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll 10:31:49.0500 4504 ERSvc - ok 10:31:49.0546 4504 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 10:31:49.0546 4504 Eventlog - ok 10:31:49.0609 4504 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll 10:31:49.0625 4504 EventSystem - ok 10:31:49.0765 4504 EvtEng (8597822f0e0eaa61a9ffd18778828792) C:\Program Files\Intel\WiFi\bin\EvtEng.exe 10:31:49.0781 4504 EvtEng - ok 10:31:49.0875 4504 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 10:31:49.0875 4504 Fastfat - ok 10:31:49.0921 4504 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 10:31:49.0921 4504 FastUserSwitchingCompatibility - ok 10:31:49.0968 4504 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 10:31:49.0968 4504 Fdc - ok 10:31:49.0968 4504 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 10:31:49.0968 4504 Fips - ok 10:31:49.0984 4504 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 10:31:50.0000 4504 Flpydisk - ok 10:31:50.0000 4504 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 10:31:50.0000 4504 FltMgr - ok 10:31:50.0093 4504 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 10:31:50.0093 4504 FontCache3.0.0.0 - ok 10:31:50.0125 4504 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 10:31:50.0125 4504 Fs_Rec - ok 10:31:50.0125 4504 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 10:31:50.0140 4504 Ftdisk - ok 10:31:50.0171 4504 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 10:31:50.0171 4504 GEARAspiWDM - ok 10:31:50.0203 4504 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 10:31:50.0203 4504 Gpc - ok 10:31:50.0234 4504 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 10:31:50.0234 4504 HDAudBus - ok 10:31:50.0296 4504 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 10:31:50.0296 4504 helpsvc - ok 10:31:50.0296 4504 HidServ - ok 10:31:50.0312 4504 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 10:31:50.0312 4504 HidUsb - ok 10:31:50.0328 4504 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll 10:31:50.0343 4504 hkmsvc - ok 10:31:50.0343 4504 hpn - ok 10:31:50.0390 4504 HSFHWAZL (702a7e1b3c9263efbd6aede3b6919761) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 10:31:50.0390 4504 HSFHWAZL - ok 10:31:50.0484 4504 HSF_DPV (8d02cb68d53aa36189faf86fed438884) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 10:31:50.0484 4504 HSF_DPV - ok 10:31:50.0546 4504 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 10:31:50.0546 4504 HTTP - ok 10:31:50.0593 4504 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll 10:31:50.0593 4504 HTTPFilter - ok 10:31:50.0593 4504 i2omgmt - ok 10:31:50.0593 4504 i2omp - ok 10:31:50.0640 4504 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 10:31:50.0640 4504 i8042prt - ok 10:31:51.0187 4504 ialm (48846b31be5a4fa662ccfde7a1ba86b9) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 10:31:51.0359 4504 ialm - ok 10:31:51.0546 4504 iaStor (e5a0034847537eaee3c00349d5c34c5f) C:\WINDOWS\system32\drivers\iaStor.sys 10:31:51.0546 4504 iaStor - ok 10:31:51.0578 4504 IBMPMDRV (400d7095d5ae08970f839bcac1843106) C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys 10:31:51.0578 4504 IBMPMDRV - ok 10:31:51.0609 4504 IBMPMSVC (06af18300c5b511a3d85c3e0b7909c10) C:\WINDOWS\system32\ibmpmsvc.exe 10:31:51.0609 4504 IBMPMSVC - ok 10:31:51.0640 4504 IBMTPCHK (3a7dbe81ec5edb96a0a61c7d4af3198d) C:\WINDOWS\system32\Drivers\IBMBLDID.sys 10:31:51.0640 4504 IBMTPCHK - ok 10:31:51.0828 4504 idsvc (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 10:31:51.0859 4504 idsvc - ok 10:31:51.0875 4504 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 10:31:51.0875 4504 Imapi - ok 10:31:51.0921 4504 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe 10:31:51.0937 4504 ImapiService - ok 10:31:51.0937 4504 ini910u - ok 10:31:51.0937 4504 IntelIde - ok 10:31:51.0968 4504 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 10:31:51.0968 4504 intelppm - ok 10:31:52.0000 4504 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 10:31:52.0000 4504 Ip6Fw - ok 10:31:52.0000 4504 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 10:31:52.0000 4504 IpFilterDriver - ok 10:31:52.0015 4504 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 10:31:52.0015 4504 IpInIp - ok 10:31:52.0031 4504 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 10:31:52.0031 4504 IpNat - ok 10:31:52.0171 4504 iPod Service (e6be7a41a28d8f2db174957454d32448) C:\Program Files\iPod\bin\iPodService.exe 10:31:52.0187 4504 iPod Service - ok 10:31:52.0218 4504 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 10:31:52.0218 4504 IPSec - ok 10:31:52.0250 4504 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys 10:31:52.0250 4504 irda - ok 10:31:52.0250 4504 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 10:31:52.0250 4504 IRENUM - ok 10:31:52.0296 4504 Irmon (49cc4533ce897cb2e93c1e84a818fde5) C:\WINDOWS\System32\irmon.dll 10:31:52.0296 4504 Irmon - ok 10:31:52.0312 4504 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 10:31:52.0312 4504 isapnp - ok 10:31:52.0359 4504 IviRegMgr (213822072085b5bbad9af30ab577d817) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe 10:31:52.0375 4504 IviRegMgr - ok 10:31:52.0453 4504 JavaQuickStarterService (9aa67569d5257462e230767510b0c815) C:\Program Files\Java\jre6\bin\jqs.exe 10:31:52.0453 4504 JavaQuickStarterService - ok 10:31:52.0484 4504 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 10:31:52.0484 4504 Kbdclass - ok 10:31:52.0531 4504 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 10:31:52.0531 4504 kmixer - ok 10:31:52.0562 4504 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 10:31:52.0562 4504 KSecDD - ok 10:31:52.0578 4504 LanmanServer (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll 10:31:52.0578 4504 LanmanServer - ok 10:31:52.0609 4504 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll 10:31:52.0625 4504 lanmanworkstation - ok 10:31:52.0625 4504 lbrtfdc - ok 10:31:52.0687 4504 LENOVO.MICMUTE (c88eb33793420a79f601fb5e33e2edd9) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe 10:31:52.0687 4504 LENOVO.MICMUTE - ok 10:31:52.0718 4504 lenovo.smi (3c3f7f424e324c6971632c5de5ff458f) C:\WINDOWS\system32\DRIVERS\smiif32.sys 10:31:52.0718 4504 lenovo.smi - ok 10:31:52.0750 4504 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll 10:31:52.0750 4504 LmHosts - ok 10:31:52.0781 4504 mdmxsdk (a027de1e6c11bd2daf61f6f276b2299f) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 10:31:52.0781 4504 mdmxsdk - ok 10:31:52.0812 4504 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll 10:31:52.0812 4504 Messenger - ok 10:31:52.0859 4504 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 10:31:52.0859 4504 mnmdd - ok 10:31:52.0890 4504 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe 10:31:52.0890 4504 mnmsrvc - ok 10:31:52.0906 4504 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 10:31:52.0906 4504 Modem - ok 10:31:52.0921 4504 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 10:31:52.0921 4504 Mouclass - ok 10:31:52.0921 4504 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 10:31:52.0921 4504 mouhid - ok 10:31:52.0953 4504 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 10:31:52.0953 4504 MountMgr - ok 10:31:53.0046 4504 MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 10:31:53.0046 4504 MozillaMaintenance - ok 10:31:53.0046 4504 mraid35x - ok 10:31:53.0062 4504 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 10:31:53.0078 4504 MRxDAV - ok 10:31:53.0156 4504 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 10:31:53.0156 4504 MRxSmb - ok 10:31:53.0187 4504 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe 10:31:53.0203 4504 MSDTC - ok 10:31:53.0218 4504 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 10:31:53.0218 4504 Msfs - ok 10:31:53.0218 4504 MSIServer - ok 10:31:53.0234 4504 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 10:31:53.0234 4504 MSKSSRV - ok 10:31:53.0250 4504 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 10:31:53.0250 4504 MSPCLOCK - ok 10:31:53.0250 4504 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 10:31:53.0250 4504 MSPQM - ok 10:31:53.0281 4504 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 10:31:53.0281 4504 mssmbios - ok 10:31:53.0312 4504 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 10:31:53.0312 4504 Mup - ok 10:31:53.0359 4504 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll 10:31:53.0359 4504 napagent - ok 10:31:53.0390 4504 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 10:31:53.0406 4504 NDIS - ok 10:31:53.0437 4504 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 10:31:53.0437 4504 NdisTapi - ok 10:31:53.0453 4504 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 10:31:53.0453 4504 Ndisuio - ok 10:31:53.0484 4504 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 10:31:53.0484 4504 NdisWan - ok 10:31:53.0515 4504 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 10:31:53.0515 4504 NDProxy - ok 10:31:53.0546 4504 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 10:31:53.0546 4504 NetBIOS - ok 10:31:53.0578 4504 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 10:31:53.0578 4504 NetBT - ok 10:31:53.0609 4504 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 10:31:53.0625 4504 NetDDE - ok 10:31:53.0625 4504 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 10:31:53.0625 4504 NetDDEdsdm - ok 10:31:53.0656 4504 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 10:31:53.0656 4504 Netlogon - ok 10:31:53.0703 4504 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll 10:31:53.0703 4504 Netman - ok 10:31:53.0843 4504 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 10:31:53.0843 4504 NetTcpPortSharing - ok 10:31:54.0453 4504 NETw5x32 (e0e8dfcd98bdbe8468f0202a64541222) C:\WINDOWS\system32\DRIVERS\NETw5x32.sys 10:31:54.0640 4504 NETw5x32 - ok 10:31:54.0812 4504 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll 10:31:54.0828 4504 Nla - ok 10:31:54.0906 4504 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 10:31:54.0906 4504 Npfs - ok 10:31:54.0937 4504 NSCIRDA (2adc0ca9945c65284b3d19bc18765974) C:\WINDOWS\system32\DRIVERS\nscirda.sys 10:31:54.0937 4504 NSCIRDA - ok 10:31:55.0031 4504 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 10:31:55.0031 4504 Ntfs - ok 10:31:55.0078 4504 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 10:31:55.0093 4504 NtLmSsp - ok 10:31:55.0156 4504 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll 10:31:55.0171 4504 NtmsSvc - ok 10:31:55.0171 4504 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 10:31:55.0171 4504 Null - ok 10:31:55.0171 4504 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 10:31:55.0187 4504 NwlnkFlt - ok 10:31:55.0187 4504 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 10:31:55.0187 4504 NwlnkFwd - ok 10:31:55.0203 4504 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 10:31:55.0203 4504 Parport - ok 10:31:55.0218 4504 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 10:31:55.0218 4504 PartMgr - ok 10:31:55.0234 4504 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 10:31:55.0234 4504 ParVdm - ok 10:31:55.0250 4504 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 10:31:55.0250 4504 PCI - ok 10:31:55.0250 4504 PCIDump - ok 10:31:55.0265 4504 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 10:31:55.0265 4504 PCIIde - ok 10:31:55.0281 4504 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 10:31:55.0281 4504 Pcmcia - ok 10:31:55.0296 4504 PDCOMP - ok 10:31:55.0296 4504 PDFRAME - ok 10:31:55.0296 4504 PDRELI - ok 10:31:55.0312 4504 PDRFRAME - ok 10:31:55.0312 4504 perc2 - ok 10:31:55.0312 4504 perc2hib - ok 10:31:55.0359 4504 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 10:31:55.0359 4504 PlugPlay - ok 10:31:55.0375 4504 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 10:31:55.0375 4504 PolicyAgent - ok 10:31:55.0484 4504 Power Manager DBC Service (c84278859a8b991e4cc5af29980008e1) C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE 10:31:55.0500 4504 Power Manager DBC Service - ok 10:31:55.0515 4504 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 10:31:55.0531 4504 PptpMiniport - ok 10:31:55.0531 4504 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 10:31:55.0531 4504 ProtectedStorage - ok 10:31:55.0546 4504 psadd (f8a25f1dd8b2c332cbc663e3579566e7) C:\WINDOWS\system32\DRIVERS\psadd.sys 10:31:55.0546 4504 psadd - ok 10:31:55.0578 4504 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 10:31:55.0578 4504 PSched - ok 10:31:55.0593 4504 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 10:31:55.0593 4504 Ptilink - ok 10:31:55.0609 4504 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 10:31:55.0609 4504 PxHelp20 - ok 10:31:55.0609 4504 ql1080 - ok 10:31:55.0625 4504 Ql10wnt - ok 10:31:55.0625 4504 ql12160 - ok 10:31:55.0625 4504 ql1240 - ok 10:31:55.0640 4504 ql1280 - ok 10:31:55.0640 4504 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 10:31:55.0640 4504 RasAcd - ok 10:31:55.0687 4504 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll 10:31:55.0687 4504 RasAuto - ok 10:31:55.0703 4504 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys 10:31:55.0703 4504 Rasirda - ok 10:31:55.0703 4504 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 10:31:55.0718 4504 Rasl2tp - ok 10:31:55.0750 4504 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll 10:31:55.0750 4504 RasMan - ok 10:31:55.0750 4504 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 10:31:55.0765 4504 RasPppoe - ok 10:31:55.0765 4504 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 10:31:55.0765 4504 Raspti - ok 10:31:55.0796 4504 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 10:31:55.0796 4504 Rdbss - ok 10:31:55.0828 4504 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 10:31:55.0828 4504 RDPCDD - ok 10:31:56.0140 4504 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 10:31:56.0140 4504 rdpdr - ok 10:31:56.0187 4504 RDPWD (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys 10:31:56.0187 4504 RDPWD - ok 10:31:56.0234 4504 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe 10:31:56.0234 4504 RDSessMgr - ok 10:31:56.0281 4504 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 10:31:56.0281 4504 redbook - ok 10:31:56.0421 4504 RegSrvc (7afcbe32616e08d45e4eaadb0a1dd5cf) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 10:31:56.0421 4504 RegSrvc - ok 10:31:56.0453 4504 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll 10:31:56.0468 4504 RemoteAccess - ok 10:31:56.0500 4504 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll 10:31:56.0500 4504 RemoteRegistry - ok 10:31:56.0515 4504 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe 10:31:56.0515 4504 RpcLocator - ok 10:31:56.0593 4504 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll 10:31:56.0609 4504 RpcSs - ok 10:31:56.0640 4504 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe 10:31:56.0656 4504 RSVP - ok 10:31:56.0812 4504 S24EventMonitor (17a717278a538543c93b64cf5cb3ff31) C:\Program Files\Intel\WiFi\bin\S24EvMon.exe 10:31:56.0843 4504 S24EventMonitor - ok 10:31:56.0890 4504 s24trans (e7958e8acda7ca20127ef5f2235f25cc) C:\WINDOWS\system32\DRIVERS\s24trans.sys 10:31:56.0890 4504 s24trans - ok 10:31:56.0921 4504 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 10:31:56.0921 4504 SamSs - ok 10:31:56.0953 4504 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe 10:31:56.0968 4504 SCardSvr - ok 10:31:57.0000 4504 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll 10:31:57.0000 4504 Schedule - ok 10:31:57.0046 4504 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 10:31:57.0062 4504 Secdrv - ok 10:31:57.0062 4504 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll 10:31:57.0078 4504 seclogon - ok 10:31:57.0109 4504 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll 10:31:57.0109 4504 SENS - ok 10:31:57.0125 4504 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 10:31:57.0125 4504 Serial - ok 10:31:57.0156 4504 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 10:31:57.0156 4504 Sfloppy - ok 10:31:57.0203 4504 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll 10:31:57.0218 4504 SharedAccess - ok 10:31:57.0265 4504 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 10:31:57.0265 4504 ShellHWDetection - ok 10:31:57.0281 4504 Shockprf (486a1bd22dd66d0a8542ebb0cd792bdb) C:\WINDOWS\system32\DRIVERS\Apsx86.sys 10:31:57.0281 4504 Shockprf - ok 10:31:57.0296 4504 Simbad - ok 10:31:57.0296 4504 Sparrow - ok 10:31:57.0343 4504 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 10:31:57.0343 4504 splitter - ok 10:31:57.0390 4504 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe 10:31:57.0390 4504 Spooler - ok 10:31:57.0406 4504 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 10:31:57.0406 4504 sr - ok 10:31:57.0437 4504 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll 10:31:57.0453 4504 srservice - ok 10:31:57.0515 4504 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 10:31:57.0515 4504 Srv - ok 10:31:57.0546 4504 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll 10:31:57.0546 4504 SSDPSRV - ok 10:31:57.0625 4504 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll 10:31:57.0625 4504 stisvc - ok 10:31:57.0656 4504 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 10:31:57.0656 4504 swenum - ok 10:31:57.0671 4504 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 10:31:57.0687 4504 swmidi - ok 10:31:57.0718 4504 swmx01 (e04b2937dcddab8fe1ea413284ccabce) C:\WINDOWS\system32\DRIVERS\swmx01.sys 10:31:57.0718 4504 swmx01 - ok 10:31:57.0734 4504 SWNC5E01 (6afe9a256c21fb32f9047cde1f6f426a) C:\WINDOWS\system32\DRIVERS\SWNC5E01.sys 10:31:57.0734 4504 SWNC5E01 - ok 10:31:57.0734 4504 SwPrv - ok 10:31:57.0734 4504 symc810 - ok 10:31:57.0750 4504 symc8xx - ok 10:31:57.0750 4504 sym_hi - ok 10:31:57.0750 4504 sym_u3 - ok 10:31:57.0921 4504 SynTP (0e8676fb3bb95aa40fdf7a4a31018c8b) C:\WINDOWS\system32\DRIVERS\SynTP.sys 10:31:57.0937 4504 SynTP - ok 10:31:57.0984 4504 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 10:31:57.0984 4504 sysaudio - ok 10:31:58.0015 4504 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe 10:31:58.0031 4504 SysmonLog - ok 10:31:58.0062 4504 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll 10:31:58.0078 4504 TapiSrv - ok 10:31:58.0125 4504 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 10:31:58.0140 4504 Tcpip - ok 10:31:58.0171 4504 TcUsb (64abea4001f8eb869385e65d85bc302b) C:\WINDOWS\system32\Drivers\tcusb.sys 10:31:58.0171 4504 TcUsb - ok 10:31:58.0171 4504 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 10:31:58.0171 4504 TDPIPE - ok 10:31:58.0187 4504 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 10:31:58.0187 4504 TDTCP - ok 10:31:58.0203 4504 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 10:31:58.0203 4504 TermDD - ok 10:31:58.0250 4504 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll 10:31:58.0250 4504 TermService - ok 10:31:58.0296 4504 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 10:31:58.0296 4504 Themes - ok 10:31:58.0453 4504 ThinkVantage Registry Monitor Service (1c7b8e69bf9557a17a17f2120892acf9) C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe 10:31:58.0468 4504 ThinkVantage Registry Monitor Service - ok 10:31:58.0500 4504 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe 10:31:58.0515 4504 TlntSvr - ok 10:31:58.0515 4504 TosIde - ok 10:31:58.0546 4504 TPDIGIMN (20a439d6475d6fe1909159c0143d0466) C:\WINDOWS\system32\DRIVERS\ApsHM86.sys 10:31:58.0546 4504 TPDIGIMN - ok 10:31:58.0578 4504 TPHDEXLGSVC (3775e4aa5f72264dbab7a578dd913ecf) C:\WINDOWS\system32\TPHDEXLG.exe 10:31:58.0578 4504 TPHDEXLGSVC - ok 10:31:58.0609 4504 TPHKDRV (8aef2188630f5ecd79ad9abba630630b) C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys 10:31:58.0609 4504 TPHKDRV - ok 10:31:58.0656 4504 TPHKSVC (2cf225e19490f499528b926263fe4554) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe 10:31:58.0656 4504 TPHKSVC - ok 10:31:58.0687 4504 TPPWRIF (44672de6cea9569c21c4b7a8d2560750) C:\WINDOWS\system32\drivers\Tppwrif.sys 10:31:58.0687 4504 TPPWRIF - ok 10:31:58.0718 4504 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll 10:31:58.0718 4504 TrkWks - ok 10:31:58.0875 4504 TSSCoreService (ddd4a2c9a37b93c7d8a539f785572565) C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe 10:31:58.0890 4504 TSSCoreService - ok 10:31:58.0906 4504 TVTI2C (7e66dda1ef146bfc3a6e36e08e036602) C:\WINDOWS\system32\DRIVERS\Tvti2c.sys 10:31:58.0906 4504 TVTI2C - ok 10:31:58.0953 4504 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 10:31:58.0953 4504 Udfs - ok 10:31:58.0953 4504 ultra - ok 10:31:58.0984 4504 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 10:31:59.0000 4504 Update - ok 10:31:59.0046 4504 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll 10:31:59.0046 4504 upnphost - ok 10:31:59.0062 4504 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe 10:31:59.0062 4504 UPS - ok 10:31:59.0078 4504 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 10:31:59.0078 4504 usbehci - ok 10:31:59.0093 4504 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 10:31:59.0093 4504 usbhub - ok 10:31:59.0125 4504 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 10:31:59.0140 4504 usbscan - ok 10:31:59.0156 4504 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 10:31:59.0171 4504 USBSTOR - ok 10:31:59.0187 4504 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 10:31:59.0187 4504 usbuhci - ok 10:31:59.0187 4504 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 10:31:59.0187 4504 VgaSave - ok 10:31:59.0187 4504 ViaIde - ok 10:31:59.0234 4504 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 10:31:59.0234 4504 VolSnap - ok 10:31:59.0281 4504 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe 10:31:59.0281 4504 VSS - ok 10:31:59.0343 4504 W32Time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll 10:31:59.0343 4504 W32Time - ok 10:31:59.0375 4504 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 10:31:59.0375 4504 Wanarp - ok 10:31:59.0437 4504 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys 10:31:59.0453 4504 Wdf01000 - ok 10:31:59.0453 4504 WDICA - ok 10:31:59.0484 4504 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 10:31:59.0484 4504 wdmaud - ok 10:31:59.0500 4504 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll 10:31:59.0515 4504 WebClient - ok 10:31:59.0609 4504 winachsf (115946a53b62a6b171fd0ed197c71d52) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 10:31:59.0609 4504 winachsf - ok 10:31:59.0703 4504 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll 10:31:59.0703 4504 winmgmt - ok 10:31:59.0750 4504 WmdmPmSN (c7e39ea41233e9f5b86c8da3a9f1e4a8) C:\WINDOWS\system32\mspmsnsv.dll 10:31:59.0750 4504 WmdmPmSN - ok 10:31:59.0859 4504 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll 10:31:59.0875 4504 Wmi - ok 10:31:59.0906 4504 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe 10:31:59.0906 4504 WmiApSrv - ok 10:32:00.0140 4504 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 10:32:00.0156 4504 WPFFontCache_v0400 - ok 10:32:00.0203 4504 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll 10:32:00.0203 4504 wscsvc - ok 10:32:00.0265 4504 WSIMD (21ac4f228f3d36876a42277c76a766c0) C:\WINDOWS\system32\DRIVERS\wsimd.sys 10:32:00.0265 4504 WSIMD - ok 10:32:00.0281 4504 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll 10:32:00.0296 4504 wuauserv - ok 10:32:00.0359 4504 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll 10:32:00.0375 4504 WZCSVC - ok 10:32:00.0406 4504 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll 10:32:00.0406 4504 xmlprov - ok 10:32:00.0437 4504 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 10:32:01.0468 4504 \Device\Harddisk0\DR0 - ok 10:32:01.0484 4504 Boot (0x1200) (077a35ca4773040e0a3e910a864d0ae1) \Device\Harddisk0\DR0\Partition0 10:32:01.0484 4504 \Device\Harddisk0\DR0\Partition0 - ok 10:32:01.0484 4504 ============================================================ 10:32:01.0484 4504 Scan finished 10:32:01.0484 4504 ============================================================ 10:32:01.0500 4144 Detected object count: 0 10:32:01.0500 4144 Actual detected object count: 0 Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.12.04 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Dean :: MOLESWORTH [administrator] 8/12/2012 10:37:28 AM mbam-log-2012-08-12 (10-37-28).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 223962 Time elapsed: 3 minute(s), 53 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -> Quarantined and deleted successfully. Registry Values Detected: 1 HKCU\Software\InstalledBrowserExtensions\215 Apps|2258 (PUP.CrossFire.SA) -> Data: I Want This -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
I had no problems executing the instructions, and the machine seems to be fixed. However, this redirect virus appears relatively sporadically, so I'll report back later in the day and advise on the machine's behavior. I suspect it's cured though. :) Thanks!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI