This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About:Blank homepage Removal [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I run Win7 64bit. I recognize redirect trojans and viruses. Thats why a couple days ago when i opened IE and it went to an about:Blank homepage..I knew it had gotten me. Especially when WinPatrol warned me of the attempt to change the homepage and even though I denied it, it would do it any way and after i reset the homepage it'd go back to blank page.. I did a scan with Spyware Doctor, MalwareBytes and Spyhunter, it warns me of the infection cleans it and i can set my homepage to igoogle again and it works fine, but a short time later it starts over again with the about:blank homepage, the internet is awfully sluggish and crashes often, i work remotely from home so this situation is becoming more worriesome by the minute.

Im usually pretty good at cleanig up a virus or such, but this one has me stumped.

While I ran Hijack this, it warned my that it could not access my host file and i might have to do the changes by hand. Thank u in advance for your help.

Here is my Hijack This log.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:13:17 PM, on 8/9/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16447)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe
C:\DLautoR.exe
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10o_ActiveX.exe
C:\Users\Blanca\Desktop\malware fixes\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Guard BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [runfile] C:\Program Files (x86)\DisplayLink\DLsetup\NoConsoleExe.exe
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [{90120000-0030-0000-0000-0000000FF1CE}] C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [{90120000-0030-0000-0000-0000000FF1CE}] C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H (User 'Default user')
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
O8 - Extra context menu item: Free YouTube Download - C:\Users\Blanca\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Add to Wish List - {76c5fb99-dd0a-4186-9e75-65d1bf3da283} - C:\Program Files (x86)\Amazon\Add to Wish List IE Extension\run.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Download with YouTube Clip Extractor - {9f31204d-6ed9-4489-a8c6-9310de31aa59} - F:\PROGRAMS\MEDIA\Clip Extractor\ClipExtractor.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://novastor.cleverreach.com
O15 - Trusted Zone: http://*.google-analytics.com
O15 - Trusted Zone: http://*.novastor.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com//activex/ractrl.cab?lmi=928
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: Agent - Unknown owner - C:\Windows\agent_x64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - SOURCENEXT - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: CrossLoop Service (CrossLoopService) - CrossLoop Inc - C:\Users\Blanca\AppData\Local\CrossLoop\CrossLoopService.exe
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TightVNC Server (tvnserver) - GlavSoft LLC. - C:\Users\Blanca\AppData\Local\CrossLoop\tvnserver.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: BitDefender Update Server v2 (Update Server) - BitDefender - C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe
O23 - Service: BitDefender Desktop Update Service (UPDATESRV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12341 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, Queenbavalos

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hello there,

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.com
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
DDS log
aswMBR log
Checkup log

Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
📎Attach.txtHi there, thanks for getting back so soon. Here are the logs u requested:

DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 22:33:10 on 2012-08-09
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4030.1188 [GMT -7:00]
.
AV: Bitdefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: PC Tools Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
SP: Bitdefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
FW: Bitdefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe
C:\Windows\agent_x64.exe
C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\Windows\SysWOW64\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
C:\Users\Blanca\AppData\Local\CrossLoop\CrossLoopService.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Photodex\ProShowGold\ScsiAccess.exe
C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe
C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe
C:\DLautoR.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Program Files (x86)\Browny02\BrYNSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10o_ActiveX.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/ig/
uSearch Bar =
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
BHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
{555d4d79-4bd2-4094-a395-cfc534424a05}
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
uRun: [AdobeBridge]
uRun: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
mRun: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [runfile] C:\Program Files (x86)\DisplayLink\DLsetup\NoConsoleExe.exe
mRun: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
mRun: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [ISTray] "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI
dRunOnce: [{90120000-0030-0000-0000-0000000FF1CE}] C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
dRunOnce: [{90120000-001A-0409-0000-0000000FF1CE}] C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
StartupFolder: C:\Users\Blanca\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Free YouTube Download - C:\Users\Blanca\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: {76c5fb99-dd0a-4186-9e75-65d1bf3da283} - C:\Program Files (x86)\Amazon\Add to Wish List IE Extension\run.htm
IE: {9f31204d-6ed9-4489-a8c6-9310de31aa59} - F:\PROGRAMS\MEDIA\Clip Extractor\ClipExtractor.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
LSP: C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
Trusted Zone: cleverreach.com\novastor
Trusted Zone: google-analytics.com
Trusted Zone: novastor.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com//activex/ractrl.cab?lmi=928
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{0025A17D-5665-4FDB-962E-BFD3519C28B1} : DhcpNameServer = 192.168.1.1 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: PC Tools Browser Guard BHO: {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
BHO-X64: Browser Guard BHO - No File
BHO-X64: PlusIEEventHelper Class: {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
TB-X64: PC Tools Browser Guard: {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB-X64: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [runfile] C:\Program Files (x86)\DisplayLink\DLsetup\NoConsoleExe.exe
mRun-x64: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
mRun-x64: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [ISTray] "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI
IE-X64: {76c5fb99-dd0a-4186-9e75-65d1bf3da283} - C:\Program Files (x86)\Amazon\Add to Wish List IE Extension\run.htm
IE-X64: {9f31204d-6ed9-4489-a8c6-9310de31aa59} - F:\PROGRAMS\MEDIA\Clip Extractor\ClipExtractor.exe
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
R0 avc3;avc3;C:\Windows\system32\DRIVERS\avc3.sys –> C:\Windows\system32\DRIVERS\avc3.sys [?]
R0 dlkmdldr;dlkmdldr;C:\Windows\system32\drivers\dlkmdldr.sys –> C:\Windows\system32\drivers\dlkmdldr.sys [?]
R0 PCTCore;PCTools KDS;C:\Windows\system32\drivers\PCTCore64.sys –> C:\Windows\system32\drivers\PCTCore64.sys [?]
R0 pctDS;PC Tools Data Store;C:\Windows\system32\drivers\pctDS64.sys –> C:\Windows\system32\drivers\pctDS64.sys [?]
R0 pctEFA;PC Tools Extended File Attributes;C:\Windows\system32\drivers\pctEFA64.sys –> C:\Windows\system32\drivers\pctEFA64.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);C:\Windows\system32\DRIVERS\tdrpm273.sys –> C:\Windows\system32\DRIVERS\tdrpm273.sys [?]
R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\BitDefender\Bitdefender Firewall\bdfwfpf.sys [2011-11-14 103504]
R1 BDVEDISK;BDVEDISK;C:\Windows\system32\DRIVERS\bdvedisk.sys –> C:\Windows\system32\DRIVERS\bdvedisk.sys [?]
R1 pctgntdi;pctgntdi;\??\C:\Windows\System32\drivers\pctgntdi64.sys –> C:\Windows\System32\drivers\pctgntdi64.sys [?]
R1 PCTSD;PC Tools Spyware Doctor Driver;C:\Windows\system32\Drivers\PCTSD64.sys –> C:\Windows\system32\Drivers\PCTSD64.sys [?]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/09/03 15:40:14];F:\PROGRAMS\MEDIA\PowerDVD10\NavFilter\000.fcl [2010-4-2 146928]
R2 afcdpsrv;Acronis Nonstop Backup Service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2011-10-3 3246040]
R2 Agent;Agent;C:\Windows\agent_x64.exe [2012-8-1 102912]
R2 Browser Defender Update Service;Browser Defender Update Service;C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-8-6 575448]
R2 CrossLoopService;CrossLoop Service;C:\Users\Blanca\AppData\Local\CrossLoop\CrossLoopService.exe [2011-3-26 560848]
R2 DisplayLinkService;DisplayLinkManager;C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [2012-2-8 8454064]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP;C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-3-9 144672]
R2 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe [2012-8-6 402368]
R2 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe [2012-8-6 1118680]
R2 SpyHunter 4 Service;SpyHunter 4 Service;C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2012-7-11 1019328]
R2 UPDATESRV;BitDefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe [2012-3-13 66096]
R3 afcdp;afcdp;C:\Windows\system32\DRIVERS\afcdp.sys –> C:\Windows\system32\DRIVERS\afcdp.sys [?]
R3 avchv;avchv Function Driver;C:\Windows\system32\DRIVERS\avchv.sys –> C:\Windows\system32\DRIVERS\avchv.sys [?]
R3 BrSerIb;Brother Serial Interface Driver(WDM);C:\Windows\system32\DRIVERS\BrSerIb.sys –> C:\Windows\system32\DRIVERS\BrSerIb.sys [?]
R3 BrUsbSIb;Brother Serial USB Driver(WDM);C:\Windows\system32\DRIVERS\BrUsbSIb.sys –> C:\Windows\system32\DRIVERS\BrUsbSIb.sys [?]
R3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2012-4-25 245760]
R3 DisplayLinkUsbPort;DisplayLink USB Device;C:\Windows\system32\DRIVERS\DisplayLinkUsbPort_6.1.36484.0.sys –> C:\Windows\system32\DRIVERS\DisplayLinkUsbPort_6.1.36484.0.sys [?]
R3 dlkmd;dlkmd;C:\Windows\system32\drivers\dlkmd.sys –> C:\Windows\system32\drivers\dlkmd.sys [?]
R3 esgiguard;esgiguard;C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [2011-3-2 13088]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\system32\DRIVERS\LEqdUsb.Sys –> C:\Windows\system32\DRIVERS\LEqdUsb.Sys [?]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\system32\DRIVERS\LHidEqd.Sys –> C:\Windows\system32\DRIVERS\LHidEqd.Sys [?]
R3 PCTBD;PC Tools Browser Defender Driver;C:\Windows\system32\Drivers\PCTBD64.sys –> C:\Windows\system32\Drivers\PCTBD64.sys [?]
R3 pctplsg;pctplsg;\??\C:\Windows\System32\drivers\pctplsg64.sys –> C:\Windows\System32\drivers\pctplsg64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 avckf;avckf;C:\Windows\system32\DRIVERS\avckf.sys –> C:\Windows\system32\DRIVERS\avckf.sys [?]
S3 BDSandBox;BDSandBox;\??\C:\Windows\system32\drivers\bdsandbox.sys –> C:\Windows\system32\drivers\bdsandbox.sys [?]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys –> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys –> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-6-12 1120752]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys –> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys –> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys –> C:\Windows\system32\drivers\tsusbhub.sys [?]
S3 tvnserver;TightVNC Server;C:\Users\Blanca\AppData\Local\CrossLoop\tvnserver.exe [2011-3-26 814080]
S3 Update Server;BitDefender Update Server v2;C:\Program Files\Common Files\BitDefender\Bitdefender Arrakis Server\bin\arrakis3.exe [2011-10-14 466736]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-08-08 22:05:15 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B8BD43FD-7D88-4EBF-8566-C2F7F8559EAE}\offreg.dll
2012-08-08 22:01:30 839152 —-a-w- C:\Windows\System32\deployJava1.dll
2012-08-08 22:01:29 955888 —-a-w- C:\Windows\System32\npDeployJava1.dll
2012-08-08 10:56:25 34816 —-a-w- C:\Windows\System32\drivers\terminpt.sys
2012-08-08 10:56:25 31232 —-a-w- C:\Windows\System32\drivers\TsUsbGD.sys
2012-08-08 10:56:25 117248 —-a-w- C:\Windows\System32\drivers\tsusbhub.sys
2012-08-08 10:56:24 88960 —-a-w- C:\Windows\System32\drivers\Synth3dVsc.sys
2012-08-08 10:56:20 71168 —-a-w- C:\Windows\System32\drivers\dmvsc.sys
2012-08-08 10:56:20 145792 —-a-w- C:\Windows\System32\drivers\E1G6032E.sys
2012-08-08 10:56:18 33280 —-a-w- C:\Windows\System32\dmvscres.dll
2012-08-08 07:57:25 9728 —-a-w- C:\Windows\System32\Native.exe
2012-08-08 07:57:14 ——– d—–w- C:\ReimageUndo
2012-08-08 07:48:22 ——– d—–w- C:\Users\Blanca\AppData\Local\Threat Expert
2012-08-08 07:38:08 ——– d—–w- C:\rei
2012-08-08 07:38:02 ——– d—–w- C:\Program Files\Reimage
2012-08-06 20:54:14 85224 —-a-w- C:\Windows\System32\drivers\PCTBD64.sys
2012-08-06 20:54:13 767960 —-a-w- C:\Windows\BDTSupport.dll
2012-08-06 20:54:13 2267096 —-a-w- C:\Windows\PCTBDCore.dll
2012-08-06 20:54:13 149464 —-a-w- C:\Windows\SGDetectionTool.dll
2012-08-06 20:54:12 1689560 —-a-w- C:\Windows\PCTBDRes.dll
2012-08-06 20:52:33 341200 —-a-w- C:\Windows\System32\drivers\pctgntdi64.sys
2012-08-06 20:52:33 145464 —-a-w- C:\Windows\System32\drivers\pctwfpfilter64.sys
2012-08-06 20:52:24 14808 —-a-w- C:\Windows\System32\drivers\pctBTFix64.sys
2012-08-06 20:52:18 92928 —-a-w- C:\Windows\System32\drivers\pctplsg64.sys
2012-08-06 20:39:48 1096176 —-a-w- C:\Windows\System32\drivers\pctEFA64.sys
2012-08-06 20:39:47 453896 —-a-w- C:\Windows\System32\drivers\pctDS64.sys
2012-08-06 20:39:44 426616 —-a-w- C:\Windows\System32\drivers\PCTCore64.sys
2012-08-06 20:28:44 ——– d—–w- C:\ProgramData\GFI Software
2012-08-06 19:17:55 ——– dc—-w- C:\Program Files (x86)\Ad-Aware Antivirus
2012-08-06 19:14:55 ——– d—–w- C:\Users\Blanca\AppData\Roaming\Ad-Aware Antivirus
2012-08-06 17:23:36 ——– dc—-w- C:\Program Files (x86)\Trojan Remover
2012-08-06 17:23:36 ——– d—–w- C:\ProgramData\Simply Super Software
2012-08-05 20:44:45 ——– dc—-w- C:\Program Files (x86)\Common Files\Comscan
2012-08-05 20:32:30 ——– d—–w- C:\Users\Blanca\AppData\Local\The Neat Company
2012-08-05 20:30:57 ——– d—–w- C:\Windows\twain_64
2012-08-05 04:11:46 ——– d—–w- C:\Users\Blanca\AppData\Roaming\avidemux
2012-08-01 23:04:04 102912 —-a-w- C:\Windows\agent_x64.exe
2012-08-01 23:04:01 ——– d—–w- C:\Program Files\Send To Neat
2012-08-01 23:03:58 52224 —-a-w- C:\Windows\System32\sdtnpm.dll
2012-08-01 22:45:35 ——– dc—-w- C:\Program Files (x86)\Common Files\NeatReceipts
2012-08-01 22:45:35 ——– d—–w- C:\Program Files\Common Files\NeatReceipts
2012-08-01 22:43:22 ——– dc—-w- C:\Program Files (x86)\Common Files\Intuit
2012-08-01 22:41:49 ——– d—–w- C:\ProgramData\The Neat Company
2012-08-01 22:41:22 ——– dc—-w- C:\Program Files (x86)\Common Files\The Neat Company
2012-08-01 22:41:22 ——– d—–w- C:\Program Files\Common Files\The Neat Company
2012-08-01 22:29:31 ——– dc—-w- C:\Program Files (x86)\Neat
2012-08-01 22:24:06 ——– d—–w- C:\Program Files\Microsoft Synchronization Services
2012-08-01 22:24:06 ——– d—–w- C:\Program Files\Microsoft SQL Server Compact Edition
2012-08-01 22:23:12 ——– dc—-w- C:\Program Files (x86)\Microsoft Synchronization Services
2012-08-01 22:23:12 ——– dc—-w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2012-07-30 23:42:32 53248 —-a-r- C:\Users\Blanca\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-07-30 23:42:15 18960 —-a-w- C:\Windows\System32\drivers\LNonPnP.sys
2012-07-27 06:20:41 ——– d—–w- C:\Users\Blanca\Incomplete
2012-07-27 06:19:16 ——– d—–w- C:\Users\Blanca\AppData\Roaming\Logishrd
2012-07-12 16:44:07 110080 —-a-r- C:\Users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconF7A21AF7.exe
2012-07-12 16:44:07 110080 —-a-r- C:\Users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconD7F16134.exe
2012-07-12 16:44:07 110080 —-a-r- C:\Users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\Icon5B4E0377.exe
2012-07-12 16:43:47 ——– d—–w- C:\Windows\3F97FA2CC160469697F9EDB23D106E21.TMP
2012-07-12 16:40:02 ——– d—–w- C:\Windows\7289B0CCBC414C7EA2C7DB1259E8E47A.TMP
2012-07-12 15:11:04 3148800 —-a-w- C:\Windows\System32\win32k.sys
2012-07-11 06:42:32 2004480 —-a-w- C:\Windows\System32\msxml6.dll
.
==================== Find3M ====================
.
2012-08-10 01:01:32 99384 —-a-w- C:\Users\Blanca\AppData\Roaming\inst.exe
2012-08-10 01:01:32 82816 —-a-w- C:\Users\Blanca\AppData\Roaming\pcouffin.sys
2012-08-08 09:04:15 5120 —-a-w- C:\Windows\SysWow64\wmi.dll
2012-08-08 09:04:15 172032 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-08-08 09:04:13 73728 ——w- C:\Windows\SysWow64\fsutil.exe
2012-08-08 09:04:13 1698816 ——w- C:\Windows\SysWow64\esent.dll
2012-08-08 09:04:13 155136 —-a-w- C:\Windows\SysWow64\imagehlp.dll
2012-08-08 08:58:43 75136 —-a-w- C:\Windows\System32\drivers\partmgr.sys
2012-08-08 08:58:43 410496 —-a-w- C:\Windows\System32\drivers\iaStorV.sys
2012-08-08 08:58:43 27008 —-a-w- C:\Windows\System32\drivers\amdxata.sys
2012-08-08 08:58:43 23104 —-a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-08-08 08:58:43 166272 —-a-w- C:\Windows\System32\drivers\nvstor.sys
2012-08-08 08:58:43 1659776 ——w- C:\Windows\System32\drivers\ntfs.sys
2012-08-08 08:58:43 148352 —-a-w- C:\Windows\System32\drivers\nvraid.sys
2012-07-03 20:46:44 24904 —-a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-25 23:04:24 1394248 —-a-w- C:\Windows\SysWow64\msxml4.dll
2012-06-22 22:35:00 251560 —-a-w- C:\Windows\System32\drivers\PCTSD64.sys
2012-06-17 19:57:41 476936 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-06-17 19:57:41 472840 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-06-06 06:06:16 1881600 —-a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 —-a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 —-a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 —-a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 —-a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 20:40:33 82816 —-a-w- C:\Windows\System32\drivers\pcouffin.sys
2012-06-02 12:12:17 2311680 —-a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:50:10 458704 —-a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 —-a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 —-a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 —-a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 —-a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 —-a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 —-a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll
2010-03-30 01:40:20 100256 ——w- C:\Program Files\Common Files\LinkInstaller.exe
.
============= FINISH: 22:35:05.08 ===============



aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-09 22:39:06
—————————–
22:39:06.822 OS Version: Windows x64 6.1.7601 Service Pack 1
22:39:06.823 Number of processors: 2 586 0x605
22:39:06.824 ComputerName: MYPCWIN7 UserName: Blanca
22:39:09.481 Initialize success
22:44:08.859 AVAST engine defs: 12080901
22:47:52.021 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
22:47:52.026 Disk 0 Vendor: WDC_WD800JD-75MSA3 10.01E04 Size: 76293MB BusType: 3
22:47:52.031 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-2
22:47:52.036 Disk 1 Vendor: ST3500320AS SD15 Size: 476940MB BusType: 3
22:47:52.051 Disk 0 MBR read successfully
22:47:52.056 Disk 0 MBR scan
22:47:52.282 Disk 0 Windows 7 default MBR code
22:47:52.307 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
22:47:52.404 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 76191 MB offset 206848
22:47:52.470 Disk 0 scanning C:\Windows\system32\drivers
22:48:08.756 Service scanning
22:48:40.759 Modules scanning
22:48:40.773 Disk 0 trace - called modules:
22:48:41.127 ntoskrnl.exe CLASSPNP.SYS disk.sys PCTCore64.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
22:48:41.135 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80048da060]
22:48:41.145 3 CLASSPNP.SYS[fffff880019c843f] -> nt!IofCallDriver -> [0xfffffa80048d9040]
22:48:41.153 5 PCTCore64.sys[fffff8800121b720] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004334680]
22:48:41.794 AVAST engine scan C:\Windows
22:48:46.478 AVAST engine scan C:\Windows\system32
22:53:42.777 AVAST engine scan C:\Windows\system32\drivers
22:54:13.078 AVAST engine scan C:\Users\Blanca
23:07:34.104 AVAST engine scan C:\ProgramData
23:14:20.269 Scan finished successfully
23:14:45.317 Disk 0 MBR has been saved successfully to "C:\Users\Blanca\Desktop\MBR.dat"
23:14:45.326 The log file has been saved successfully to "C:\Users\Blanca\Desktop\aswMBR.txt"



Results of screen317's Security Check version 0.99.43
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Bitdefender Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
PC Tools Spyware Doctor 9.0
Malwarebytes Anti-Malware version 1.62.0.1300
Adobe Reader X 10.0.1 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Blanca Desktop malware fixes SecurityCheck.exe
Bitdefender Bitdefender 2012 vsserv.exe
Bitdefender Bitdefender 2012 bdagent.exe
Bitdefender Bitdefender 2012 updatesrv.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````


📎Attach.txt
📎MBR.zip
Hi

You have ( uTorrent ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


===================================================

Please read through these instructions to familiarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Hi, Thank you for the P2P advice. Although I believe the infection was caused by a freeware video splitting software I downloaded over the weekend for my daughter to use on a school project…I've read all the information you provided completely, and agree with the saftey issues involved with using this type of software. Therefore, I did chooose to uninstall it from my computer. I very much appreciate your input and the time you are taking to help. Please find the Combofix log here: Combofix did warn that there was an error and it was not able to create a restore point. I have a few registry back ups on file and Acronic Nonstop Back up on all the time… ComboFix 12-08-09.01 - Blanca 08/10/2012 15:22:00.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4030.1731 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Bitdefender Antivirus *Disabled/Updated* {50909708-FF80-02AF-F814-B28405891E92} FW: Bitdefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9} SP: Bitdefender Antispyware *Disabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F} SP: PC Tools Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\1332791535.bdinstall.bin c:\programdata\1332795302.bdinstall.bin c:\programdata\1332901305.bdinstall.bin c:\programdata\1333490855.364.bin c:\programdata\1333490855.4892.bin c:\programdata\1333490855.5304.bin c:\programdata\1333490855.5860.bin c:\programdata\1333494334.bdinstall.bin c:\programdata\1333495913.bdinstall.bin c:\programdata\1333496093.bdinstall.bin c:\programdata\36a1cd18 c:\programdata\Amazon.ico c:\programdata\MercadoLivre.ico c:\users\Blanca\AppData\Local\Temp\7zS1D27\HPSLPSVC64.DLL c:\users\Blanca\AppData\Roaming\inst.exe c:\users\Blanca\AppData\Roaming\vso_ts_preview.xml c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\pthreadVC.dll c:\windows\SysWow64\Windows Update c:\windows\SysWow64\wpcap.dll H:\autorun.inf . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_NPF ——-\Service_HPSLPSVC . . ((((((((((((((((((((((((( Files Created from 2012-07-10 to 2012-08-10 ))))))))))))))))))))))))))))))) . . 2012-08-10 22:35 . 2012-08-10 22:35 ——– d—–w- c:\users\Laura\AppData\Local\temp 2012-08-08 22:05 . 2012-08-09 07:10 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B8BD43FD-7D88-4EBF-8566-C2F7F8559EAE}\offreg.dll 2012-08-08 22:01 . 2012-08-08 22:00 839152 —-a-w- c:\windows\system32\deployJava1.dll 2012-08-08 22:01 . 2012-08-08 22:00 955888 —-a-w- c:\windows\system32\npDeployJava1.dll 2012-08-08 22:01 . 2012-08-08 22:00 268784 —-a-w- c:\windows\system32\javaws.exe 2012-08-08 22:00 . 2012-08-08 22:00 189424 —-a-w- c:\windows\system32\javaw.exe 2012-08-08 22:00 . 2012-08-08 22:00 188912 —-a-w- c:\windows\system32\java.exe 2012-08-08 22:00 . 2012-08-08 22:00 ——– d—–w- c:\program files\Java 2012-08-08 10:59 . 2012-08-08 10:59 ——– d—–w- c:\program files\Uninstall Information 2012-08-08 10:59 . 2012-08-08 10:59 ——– d—–w- c:\users\Laura\AppData\Roaming\Media Center Programs 2012-08-08 10:59 . 2012-08-08 10:59 ——– d—–w- c:\users\Frank.mypcwin7\AppData\Roaming\Media Center Programs 2012-08-08 10:59 . 2012-08-08 10:59 ——– d—–w- c:\users\Blanca\AppData\Roaming\Media Center Programs 2012-08-08 10:58 . 2012-08-08 10:58 ——– d—–w- c:\users\Default\AppData\Roaming\Media Center Programs 2012-08-08 10:56 . 2010-11-20 11:07 117248 —-a-w- c:\windows\system32\drivers\tsusbhub.sys 2012-08-08 10:56 . 2010-11-20 11:07 31232 —-a-w- c:\windows\system32\drivers\TsUsbGD.sys 2012-08-08 10:56 . 2010-11-20 11:03 34816 —-a-w- c:\windows\system32\drivers\terminpt.sys 2012-08-08 10:56 . 2010-11-20 13:33 88960 —-a-w- c:\windows\system32\drivers\Synth3dVsc.sys 2012-08-08 10:56 . 2010-11-20 09:57 71168 —-a-w- c:\windows\system32\drivers\dmvsc.sys 2012-08-08 10:56 . 2009-06-10 20:35 145792 —-a-w- c:\windows\system32\drivers\E1G6032E.sys 2012-08-08 10:56 . 2010-11-20 12:45 33280 —-a-w- c:\windows\system32\dmvscres.dll 2012-08-08 07:57 . 2012-08-08 07:57 9728 —-a-w- c:\windows\system32\Native.exe 2012-08-08 07:57 . 2012-08-08 11:14 ——– d—–w- C:\ReimageUndo 2012-08-08 07:48 . 2012-08-08 07:48 ——– d—–w- c:\users\Blanca\AppData\Local\Threat Expert 2012-08-08 07:38 . 2012-08-08 11:27 ——– d—–w- C:\rei 2012-08-08 07:38 . 2012-08-08 07:38 ——– d—–w- c:\program files\Reimage 2012-08-06 20:54 . 2012-06-22 18:39 85224 —-a-w- c:\windows\system32\drivers\PCTBD64.sys 2012-08-06 20:54 . 2012-06-22 18:39 149464 —-a-w- c:\windows\SGDetectionTool.dll 2012-08-06 20:54 . 2012-06-22 18:39 2267096 —-a-w- c:\windows\PCTBDCore.dll 2012-08-06 20:54 . 2012-06-22 18:38 767960 —-a-w- c:\windows\BDTSupport.dll 2012-08-06 20:54 . 2012-06-22 18:39 1689560 —-a-w- c:\windows\PCTBDRes.dll 2012-08-06 20:52 . 2012-06-22 22:29 145464 —-a-w- c:\windows\system32\drivers\pctwfpfilter64.sys 2012-08-06 20:52 . 2012-06-22 22:29 341200 —-a-w- c:\windows\system32\drivers\pctgntdi64.sys 2012-08-06 20:52 . 2012-06-22 22:33 14808 —-a-w- c:\windows\system32\drivers\pctBTFix64.sys 2012-08-06 20:52 . 2012-06-22 22:35 92928 —-a-w- c:\windows\system32\drivers\pctplsg64.sys 2012-08-06 20:39 . 2012-02-28 18:43 1096176 —-a-w- c:\windows\system32\drivers\pctEFA64.sys 2012-08-06 20:39 . 2012-02-28 18:43 453896 —-a-w- c:\windows\system32\drivers\pctDS64.sys 2012-08-06 20:39 . 2012-04-23 19:36 426616 —-a-w- c:\windows\system32\drivers\PCTCore64.sys 2012-08-06 20:28 . 2012-08-06 20:28 ——– d—–w- c:\programdata\GFI Software 2012-08-06 19:17 . 2012-08-06 19:17 ——– d—–w- c:\programdata\Lavasoft 2012-08-06 19:17 . 2012-08-06 20:28 ——– dc—-w- c:\program files (x86)\Ad-Aware Antivirus 2012-08-06 19:14 . 2012-08-06 20:11 ——– d—–w- c:\users\Blanca\AppData\Roaming\Ad-Aware Antivirus 2012-08-06 17:23 . 2012-08-06 17:27 ——– dc—-w- c:\program files (x86)\Trojan Remover 2012-08-06 17:23 . 2012-08-06 17:23 ——– d—–w- c:\programdata\Simply Super Software 2012-08-05 20:44 . 2012-08-05 20:44 ——– dc—-w- c:\program files (x86)\Common Files\Comscan 2012-08-05 20:32 . 2012-08-05 20:32 ——– d—–w- c:\users\Blanca\AppData\Local\The Neat Company 2012-08-05 20:30 . 2012-08-05 20:30 ——– d—–w- c:\windows\twain_64 2012-08-05 04:11 . 2012-08-05 04:13 ——– d—–w- c:\users\Blanca\AppData\Roaming\avidemux 2012-08-01 23:04 . 2011-08-24 17:59 102912 —-a-w- c:\windows\agent_x64.exe 2012-08-01 23:04 . 2012-08-01 23:04 ——– d—–w- c:\program files\Send To Neat 2012-08-01 23:03 . 2011-08-24 18:01 52224 —-a-w- c:\windows\system32\sdtnpm.dll 2012-08-01 22:45 . 2012-08-01 22:45 ——– dc—-w- c:\program files (x86)\Common Files\NeatReceipts 2012-08-01 22:45 . 2012-08-01 22:45 ——– d—–w- c:\program files\Common Files\NeatReceipts 2012-08-01 22:43 . 2012-08-01 22:43 ——– dc—-w- c:\program files (x86)\Common Files\Intuit 2012-08-01 22:41 . 2012-08-01 22:41 ——– d—–w- c:\programdata\The Neat Company 2012-08-01 22:41 . 2012-08-05 20:45 ——– d—–w- c:\program files\Common Files\The Neat Company 2012-08-01 22:41 . 2012-08-01 23:01 ——– dc—-w- c:\program files (x86)\Common Files\The Neat Company 2012-08-01 22:29 . 2012-08-01 22:29 ——– dc—-w- c:\program files (x86)\Neat 2012-08-01 22:24 . 2012-08-01 22:24 ——– d—–w- c:\program files\Microsoft Synchronization Services 2012-08-01 22:24 . 2012-08-01 22:24 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition 2012-08-01 22:23 . 2012-08-01 22:23 ——– dc—-w- c:\program files (x86)\Microsoft Synchronization Services 2012-08-01 22:23 . 2012-08-01 22:23 ——– dc—-w- c:\program files (x86)\Microsoft SQL Server Compact Edition 2012-08-01 22:07 . 2012-08-01 22:07 ——– d—–w- c:\users\Frank.mypcwin7\AppData\Local\VirtualStore 2012-08-01 22:06 . 2012-08-01 22:06 ——– d—–w- c:\users\Frank.mypcwin7\AppData\Roaming\Logitech 2012-07-30 23:51 . 2012-07-30 23:51 ——– d—–w- c:\programdata\Logitech 2012-07-30 23:42 . 2012-07-30 23:42 ——– d—–w- c:\users\Blanca\AppData\Roaming\Leadertech 2012-07-30 23:42 . 2012-07-30 23:42 53248 —-a-r- c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2012-07-30 23:42 . 2012-07-30 23:42 ——– dc—-w- c:\program files (x86)\Common Files\LogiShrd 2012-07-30 23:42 . 2012-07-30 23:42 18960 —-a-w- c:\windows\system32\drivers\LNonPnP.sys 2012-07-30 23:34 . 2012-07-30 23:43 ——– d—–w- c:\programdata\Logishrd 2012-07-30 23:34 . 2012-07-30 23:35 ——– d—–w- c:\program files\Logitech 2012-07-27 06:20 . 2012-07-27 06:27 ——– d—–w- c:\users\Blanca\Incomplete 2012-07-27 06:19 . 2012-07-30 23:42 ——– d—–w- c:\program files\Common Files\LogiShrd 2012-07-27 06:19 . 2012-07-30 23:43 ——– d—–w- c:\users\Blanca\AppData\Roaming\Logitech 2012-07-27 06:19 . 2012-07-27 06:19 ——– d—–w- c:\users\Blanca\AppData\Roaming\Logishrd 2012-07-22 22:59 . 2012-08-08 10:58 ——– d—–w- c:\users\LogMeInRemoteUser 2012-07-12 16:44 . 2012-07-12 16:44 110080 —-a-r- c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconF7A21AF7.exe 2012-07-12 16:44 . 2012-07-12 16:44 110080 —-a-r- c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconD7F16134.exe 2012-07-12 16:44 . 2012-07-12 16:44 110080 —-a-r- c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\Icon5B4E0377.exe 2012-07-12 16:43 . 2012-07-12 16:44 ——– d—–w- c:\windows\3F97FA2CC160469697F9EDB23D106E21.TMP 2012-07-12 16:40 . 2012-07-12 16:44 ——– d—–w- c:\windows\7289B0CCBC414C7EA2C7DB1259E8E47A.TMP 2012-07-12 15:11 . 2012-06-12 03:08 3148800 —-a-w- c:\windows\system32\win32k.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-10 01:01 . 2012-06-02 20:40 82816 —-a-w- c:\users\Blanca\AppData\Roaming\pcouffin.sys 2012-08-08 09:04 . 2012-04-11 10:00 5120 —-a-w- c:\windows\SysWow64\wmi.dll 2012-08-08 09:04 . 2012-04-11 10:00 172032 —-a-w- c:\windows\SysWow64\wintrust.dll 2012-08-08 09:04 . 2012-04-11 10:00 155136 —-a-w- c:\windows\SysWow64\imagehlp.dll 2012-08-08 09:04 . 2011-04-27 05:43 73728 ——w- c:\windows\SysWow64\fsutil.exe 2012-08-08 09:04 . 2011-04-27 05:43 1698816 ——w- c:\windows\SysWow64\esent.dll 2012-08-08 09:01 . 2012-06-23 16:04 51200 —-a-w- c:\windows\system32\wuauclt.exe 2012-08-08 09:01 . 2012-06-23 16:04 37376 —-a-w- c:\windows\system32\wups2.dll 2012-08-08 09:01 . 2012-06-23 16:04 2621952 —-a-w- c:\windows\system32\wucltux.dll 2012-08-08 09:01 . 2012-06-23 16:04 2420736 —-a-w- c:\windows\system32\wuaueng.dll 2012-08-08 09:01 . 2012-06-23 16:04 98304 —-a-w- c:\windows\system32\wudriver.dll 2012-08-08 09:01 . 2012-06-23 16:04 695808 —-a-w- c:\windows\system32\wuapi.dll 2012-08-08 09:01 . 2012-06-23 16:04 33280 —-a-w- c:\windows\system32\wups.dll 2012-08-08 09:01 . 2012-06-23 16:04 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-08-08 09:01 . 2012-06-23 16:04 178688 —-a-w- c:\windows\system32\wuwebv.dll 2012-08-08 09:01 . 2012-04-11 10:00 5120 —-a-w- c:\windows\system32\wmi.dll 2012-08-08 09:01 . 2012-04-11 10:00 220672 —-a-w- c:\windows\system32\wintrust.dll 2012-08-08 09:01 . 2012-04-11 10:00 76800 —-a-w- c:\windows\system32\imagehlp.dll 2012-08-08 09:01 . 2011-03-25 03:54 270720 ——w- c:\windows\system32\MpSigStub.exe 2012-08-08 09:01 . 2012-05-09 14:37 1924480 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-08-08 09:01 . 2011-05-11 03:22 52224 —-a-w- c:\windows\system32\drivers\usbehci.sys 2012-08-08 09:01 . 2011-05-11 03:22 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2012-08-08 09:01 . 2011-05-11 03:22 325120 —-a-w- c:\windows\system32\drivers\usbport.sys 2012-08-08 09:01 . 2011-05-11 03:22 98816 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2012-08-08 09:01 . 2011-05-11 03:22 7936 —-a-w- c:\windows\system32\drivers\usbd.sys 2012-08-08 09:01 . 2011-05-11 03:22 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2012-08-08 09:01 . 2011-04-27 05:43 96256 ——w- c:\windows\system32\fsutil.exe 2012-08-08 09:01 . 2011-04-27 05:43 2565632 ——w- c:\windows\system32\esent.dll 2012-08-08 09:01 . 2011-04-27 05:43 189824 ——w- c:\windows\system32\drivers\storport.sys 2012-08-08 08:58 . 2012-05-09 14:37 75136 —-a-w- c:\windows\system32\drivers\partmgr.sys 2012-08-08 08:58 . 2012-04-11 10:00 23104 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-08-08 08:58 . 2011-04-27 05:43 410496 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2012-08-08 08:58 . 2011-04-27 05:43 27008 —-a-w- c:\windows\system32\drivers\amdxata.sys 2012-08-08 08:58 . 2011-04-27 05:43 166272 —-a-w- c:\windows\system32\drivers\nvstor.sys 2012-08-08 08:58 . 2011-04-27 05:43 1659776 ——w- c:\windows\system32\drivers\ntfs.sys 2012-08-08 08:58 . 2011-04-27 05:43 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys 2012-07-11 10:04 . 2011-03-25 04:13 59701280 —-a-w- c:\windows\system32\MRT.exe 2012-07-03 20:46 . 2012-05-08 06:39 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-25 23:04 . 2012-06-25 23:04 1394248 —-a-w- c:\windows\SysWow64\msxml4.dll 2012-06-22 22:35 . 2012-05-15 07:09 251560 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2012-06-22 17:43 . 2012-08-06 20:54 3488 —-a-w- c:\windows\UDB.zip 2012-06-22 17:43 . 2012-08-06 20:54 131 —-a-w- c:\windows\IDB.zip 2012-06-17 19:57 . 2012-06-17 19:57 476936 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2012-06-17 19:57 . 2011-03-26 17:52 472840 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-06-09 05:43 . 2012-07-11 06:42 14172672 —-a-w- c:\windows\system32\shell32.dll 2012-06-06 06:06 . 2012-07-11 06:42 2004480 —-a-w- c:\windows\system32\msxml6.dll 2012-06-06 06:06 . 2012-07-11 06:42 1881600 —-a-w- c:\windows\system32\msxml3.dll 2012-06-06 06:02 . 2012-07-11 06:42 1133568 —-a-w- c:\windows\system32\cdosys.dll 2012-06-06 05:05 . 2012-07-11 06:42 1390080 —-a-w- c:\windows\SysWow64\msxml6.dll 2012-06-06 05:05 . 2012-07-11 06:42 1236992 —-a-w- c:\windows\SysWow64\msxml3.dll 2012-06-06 05:03 . 2012-07-11 06:42 805376 —-a-w- c:\windows\SysWow64\cdosys.dll 2012-06-02 20:40 . 2012-06-02 20:40 82816 —-a-w- c:\windows\system32\drivers\pcouffin.sys 2012-06-02 12:49 . 2012-07-11 10:02 17807360 —-a-w- c:\windows\system32\mshtml.dll 2012-06-02 12:17 . 2012-07-11 10:02 10924032 —-a-w- c:\windows\system32\ieframe.dll 2012-06-02 12:12 . 2012-07-11 10:02 2311680 —-a-w- c:\windows\system32\jscript9.dll 2012-06-02 12:05 . 2012-07-11 10:02 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-06-02 12:05 . 2012-07-11 10:02 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-06-02 12:04 . 2012-07-11 10:02 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-06-02 12:04 . 2012-07-11 10:02 237056 —-a-w- c:\windows\system32\url.dll 2012-06-02 12:03 . 2012-07-11 10:02 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-06-02 12:01 . 2012-07-11 10:02 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-06-02 12:00 . 2012-07-11 10:02 818688 —-a-w- c:\windows\system32\jscript.dll 2012-06-02 11:59 . 2012-07-11 10:02 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-06-02 11:57 . 2012-07-11 10:02 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-06-02 11:57 . 2012-07-11 10:02 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-06-02 11:54 . 2012-07-11 10:02 248320 —-a-w- c:\windows\system32\ieui.dll 2012-06-02 08:33 . 2012-07-11 10:02 1800192 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-06-02 08:25 . 2012-07-11 10:02 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-06-02 08:25 . 2012-07-11 10:02 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-06-02 08:20 . 2012-07-11 10:02 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-06-02 08:16 . 2012-07-11 10:02 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-06-02 05:50 . 2012-07-11 06:42 458704 —-a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 05:48 . 2012-07-11 06:42 95600 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 05:48 . 2012-07-11 06:42 151920 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 05:45 . 2012-07-11 06:42 340992 —-a-w- c:\windows\system32\schannel.dll 2012-06-02 05:44 . 2012-07-11 06:42 307200 —-a-w- c:\windows\system32\ncrypt.dll 2012-06-02 04:40 . 2012-07-11 06:42 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2012-06-02 04:40 . 2012-07-11 06:42 225280 —-a-w- c:\windows\SysWow64\schannel.dll 2012-06-02 04:39 . 2012-07-11 06:42 219136 —-a-w- c:\windows\SysWow64\ncrypt.dll 2012-06-02 04:34 . 2012-07-11 06:42 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2010-03-30 01:40 . 2010-03-30 01:40 100256 ——w- c:\program files\Common Files\LinkInstaller.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240] "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2011-02-02 5546376] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040] "runfile"="c:\program files (x86)\DisplayLink\DLsetup\NoConsoleExe.exe" [2011-03-18 7168] "ControlCenter4"="c:\program files (x86)\ControlCenter4\BrCcBoot.exe" [2011-04-21 139264] "BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2011-05-19 2629632] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "{90120000-0030-0000-0000-0000000FF1CE}"="del" [X] "{90120000-001A-0409-0000-0000000FF1CE}"="del" [X] . c:\users\Blanca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech . Product Registration.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R0 sptd;sptd; [x] R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [2012-02-17 545064] R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys [2011-11-18 79952] R3 cpuz134;cpuz134;c:\users\Blanca\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 71168] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [2011-03-03 13088] R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2012-06-02 82816] R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD64.sys [2012-06-22 85224] R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [2012-06-22 92928] R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992] R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe [2012-06-22 402368] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 88960] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-20 34816] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 117248] R3 tvnserver;TightVNC Server;c:\users\Blanca\AppData\Local\CrossLoop\tvnserver.exe [2010-07-21 814080] R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe [2011-10-15 466736] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-03-25 1255736] S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [2012-03-21 691896] S0 dlkmdldr;dlkmdldr;c:\windows\system32\drivers\dlkmdldr.sys [2012-02-08 15184] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [2012-04-23 426616] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [2012-02-28 453896] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [2012-02-28 1096176] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280] S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [2011-10-03 1263200] S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2011-11-15 103504] S1 BDVEDISK;BDVEDISK;c:\windows\system32\DRIVERS\bdvedisk.sys [2010-01-20 103944] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys [2012-06-22 341200] S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [2012-06-22 251560] S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/09/03 15:40];f:\programs\MEDIA\PowerDVD10\NavFilter\000.fcl [2010-04-02 16:11 146928] S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2011-10-03 3246040] S2 Agent;Agent;c:\windows\agent_x64.exe [2011-08-24 102912] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-06-22 575448] S2 CrossLoopService;CrossLoop Service;c:\users\Blanca\AppData\Local\CrossLoop\CrossLoopService.exe [2010-08-18 560848] S2 DisplayLinkService;DisplayLinkManager;c:\program files\DisplayLink Core Software\DisplayLinkManager.exe [2012-02-08 8454064] S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-03-09 144672] S2 UPDATESRV;BitDefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender 2012\updatesrv.exe [2012-03-14 66096] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2011-10-03 285280] S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys [2011-11-25 258736] S3 BrSerIb;Brother Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys [2009-11-03 87552] S3 BrUsbSIb;Brother Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys [2009-11-03 14592] S3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760] S3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\DRIVERS\DisplayLinkUsbPort_6.1.36484.0.sys [2012-02-08 17408] S3 dlkmd;dlkmd;c:\windows\system32\drivers\dlkmd.sys [2012-02-08 308560] S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056] S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-10-16 19:49 451872 -c—-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2012-08-10 c:\windows\Tasks\SpyHunter4.job - c:\program files\Enigma Software Group\SpyHunter\SpyHunter4.exe [2012-07-11 21:58] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2011-02-02 390720] "BDAgent"="c:\program files\Bitdefender\Bitdefender 2012\bdagent.exe" [2012-04-26 1067256] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152] "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2010-11-04 1580368] "combofix"="c:\combofix\CF8888.3XE" [2010-11-20 345088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ig/ mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Free YouTube Download - c:\users\Blanca\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm IE: {{9f31204d-6ed9-4489-a8c6-9310de31aa59} - f:\programs\MEDIA\Clip Extractor\ClipExtractor.exe LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll Trusted Zone: cleverreach.com\novastor Trusted Zone: google-analytics.com Trusted Zone: novastor.com TCP: DhcpNameServer = 192.168.1.1 192.168.1.1 . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-uTorrent - c:\program files (x86)\uTorrent\uTorrent.exe Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKLM-Run-WinPatrol - c:\program files (x86)\BillP Studios\WinPatrol\winpatrol.exe WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}] "ImagePath"="\??\f:\programs\MEDIA\PowerDVD10\NavFilter\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\SetId\Internal] @Denied: (A 2) (LocalSystem) "DEVICE2"="yquvvMjIyQA=" "DATA2"="\0a" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{3DA165B6-CC41-11d2-BDC6-00C04F79EC6B}\ProgID] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{3DA165B6-CC41-11d2-BDC6-00C04F79EC6B}\Version] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\SysWOW64\bgsvcgen.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\Photodex\ProShowGold\ScsiAccess.exe c:\program files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe c:\program files (x86)\ControlCenter4\BrCtrlCntr.exe C:\DLautoR.exe c:\program files (x86)\ControlCenter4\BrCcUxSys.exe . ************************************************************************** . Completion time: 2012-08-10 15:55:39 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-10 22:55 . Pre-Run: 17,778,995,200 bytes free Post-Run: 18,367,627,264 bytes free . - - End Of File - - 1385B565C8738679CBA548EB5E7E3EE3
We must first enable system restore before continuing any fix.

Click on START and choose Run
In the Run box type or copy/paste the following and press Enter or click on OK:

control sysdm.cpl

Select System Protection tab, under Protection Settings do you see any drive that says protection on? Take note of the Local Drive C: - is it on?
Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

File::
c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconF7A21AF7.exe
c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconD7F16134.exe
c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\Icon5B4E0377.exe
c:\windows\3F97FA2CC160469697F9EDB23D106E21.TMP
c:\windows\7289B0CCBC414C7EA2C7DB1259E8E47A.TMP

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"{90120000-0030-0000-0000-0000000FF1CE}"=-
"{90120000-001A-0409-0000-0000000FF1CE}"=-


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

When finished, it shall produce a log for you. Please post that log, C:\ComboFix.txt, in your next reply.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]
ComboFix updated before running. Here is the log ComboFix 12-08-10.02 - Blanca 08/12/2012 13:54:17.2.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4030.2584 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Blanca\Desktop\CFScript.txt AV: Bitdefender Antivirus *Disabled/Updated* {50909708-FF80-02AF-F814-B28405891E92} FW: Bitdefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9} SP: Bitdefender Antispyware *Disabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F} SP: PC Tools Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\Icon5B4E0377.exe" "c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconD7F16134.exe" "c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconF7A21AF7.exe" "c:\windows\3F97FA2CC160469697F9EDB23D106E21.TMP" "c:\windows\7289B0CCBC414C7EA2C7DB1259E8E47A.TMP" . . ((((((((((((((((((((((((( Files Created from 2012-07-12 to 2012-08-12 ))))))))))))))))))))))))))))))) . . 2012-08-12 21:07 . 2012-08-12 21:07 ——– d—–w- c:\users\Laura\AppData\Local\temp 2012-08-12 21:07 . 2012-08-12 21:07 ——– d—–w- c:\users\Frank\AppData\Local\temp 2012-08-12 21:07 . 2012-08-12 21:07 ——– d—–w- c:\users\Frank.mypcwin7\AppData\Local\temp 2012-08-12 21:07 . 2012-08-12 21:07 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-08-12 15:03 . 2012-08-12 15:03 ——– d—–w- c:\users\Blanca\AppData\Local\LogMeIn 2012-08-08 22:05 . 2012-08-09 07:10 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B8BD43FD-7D88-4EBF-8566-C2F7F8559EAE}\offreg.dll 2012-08-08 22:01 . 2012-08-08 22:00 839152 —-a-w- c:\windows\system32\deployJava1.dll 2012-08-08 22:01 . 2012-08-08 22:00 955888 —-a-w- c:\windows\system32\npDeployJava1.dll 2012-08-08 22:01 . 2012-08-08 22:00 268784 —-a-w- c:\windows\system32\javaws.exe 2012-08-08 22:00 . 2012-08-08 22:00 189424 —-a-w- c:\windows\system32\javaw.exe 2012-08-08 22:00 . 2012-08-08 22:00 188912 —-a-w- c:\windows\system32\java.exe 2012-08-08 22:00 . 2012-08-08 22:00 ——– d—–w- c:\program files\Java 2012-08-08 10:59 . 2012-08-08 10:59 ——– d—–w- c:\program files\Uninstall Information 2012-08-08 10:59 . 2012-08-08 10:59 ——– d—–w- c:\users\Laura\AppData\Roaming\Media Center Programs 2012-08-08 10:59 . 2012-08-08 10:59 ——– d—–w- c:\users\Frank.mypcwin7\AppData\Roaming\Media Center Programs 2012-08-08 10:59 . 2012-08-08 10:59 ——– d—–w- c:\users\Blanca\AppData\Roaming\Media Center Programs 2012-08-08 10:58 . 2012-08-08 10:58 ——– d—–w- c:\users\Default\AppData\Roaming\Media Center Programs 2012-08-08 10:56 . 2010-11-20 11:07 117248 —-a-w- c:\windows\system32\drivers\tsusbhub.sys 2012-08-08 10:56 . 2010-11-20 11:07 31232 —-a-w- c:\windows\system32\drivers\TsUsbGD.sys 2012-08-08 10:56 . 2010-11-20 11:03 34816 —-a-w- c:\windows\system32\drivers\terminpt.sys 2012-08-08 10:56 . 2010-11-20 13:33 88960 —-a-w- c:\windows\system32\drivers\Synth3dVsc.sys 2012-08-08 10:56 . 2010-11-20 09:57 71168 —-a-w- c:\windows\system32\drivers\dmvsc.sys 2012-08-08 10:56 . 2009-06-10 20:35 145792 —-a-w- c:\windows\system32\drivers\E1G6032E.sys 2012-08-08 10:56 . 2010-11-20 12:45 33280 —-a-w- c:\windows\system32\dmvscres.dll 2012-08-08 07:57 . 2012-08-08 07:57 9728 —-a-w- c:\windows\system32\Native.exe 2012-08-08 07:57 . 2012-08-08 11:14 ——– d—–w- C:\ReimageUndo 2012-08-08 07:48 . 2012-08-08 07:48 ——– d—–w- c:\users\Blanca\AppData\Local\Threat Expert 2012-08-08 07:38 . 2012-08-08 11:27 ——– d—–w- C:\rei 2012-08-08 07:38 . 2012-08-08 07:38 ——– d—–w- c:\program files\Reimage 2012-08-06 20:54 . 2012-06-22 18:39 85224 —-a-w- c:\windows\system32\drivers\PCTBD64.sys 2012-08-06 20:54 . 2012-06-22 18:39 149464 —-a-w- c:\windows\SGDetectionTool.dll 2012-08-06 20:54 . 2012-06-22 18:39 2267096 —-a-w- c:\windows\PCTBDCore.dll 2012-08-06 20:54 . 2012-06-22 18:38 767960 —-a-w- c:\windows\BDTSupport.dll 2012-08-06 20:54 . 2012-06-22 18:39 1689560 —-a-w- c:\windows\PCTBDRes.dll 2012-08-06 20:52 . 2012-06-22 22:29 145464 —-a-w- c:\windows\system32\drivers\pctwfpfilter64.sys 2012-08-06 20:52 . 2012-06-22 22:29 341200 —-a-w- c:\windows\system32\drivers\pctgntdi64.sys 2012-08-06 20:52 . 2012-06-22 22:33 14808 —-a-w- c:\windows\system32\drivers\pctBTFix64.sys 2012-08-06 20:52 . 2012-06-22 22:35 92928 —-a-w- c:\windows\system32\drivers\pctplsg64.sys 2012-08-06 20:39 . 2012-02-28 18:43 1096176 —-a-w- c:\windows\system32\drivers\pctEFA64.sys 2012-08-06 20:39 . 2012-02-28 18:43 453896 —-a-w- c:\windows\system32\drivers\pctDS64.sys 2012-08-06 20:39 . 2012-04-23 19:36 426616 —-a-w- c:\windows\system32\drivers\PCTCore64.sys 2012-08-06 20:28 . 2012-08-06 20:28 ——– d—–w- c:\programdata\GFI Software 2012-08-06 19:17 . 2012-08-06 19:17 ——– d—–w- c:\programdata\Lavasoft 2012-08-06 19:17 . 2012-08-06 20:28 ——– dc—-w- c:\program files (x86)\Ad-Aware Antivirus 2012-08-06 19:14 . 2012-08-06 20:11 ——– d—–w- c:\users\Blanca\AppData\Roaming\Ad-Aware Antivirus 2012-08-06 17:23 . 2012-08-06 17:27 ——– dc—-w- c:\program files (x86)\Trojan Remover 2012-08-06 17:23 . 2012-08-06 17:23 ——– d—–w- c:\programdata\Simply Super Software 2012-08-05 20:44 . 2012-08-05 20:44 ——– dc—-w- c:\program files (x86)\Common Files\Comscan 2012-08-05 20:32 . 2012-08-05 20:32 ——– d—–w- c:\users\Blanca\AppData\Local\The Neat Company 2012-08-05 20:30 . 2012-08-05 20:30 ——– d—–w- c:\windows\twain_64 2012-08-05 04:11 . 2012-08-05 04:13 ——– d—–w- c:\users\Blanca\AppData\Roaming\avidemux 2012-08-01 23:04 . 2011-08-24 17:59 102912 —-a-w- c:\windows\agent_x64.exe 2012-08-01 23:04 . 2012-08-01 23:04 ——– d—–w- c:\program files\Send To Neat 2012-08-01 23:03 . 2011-08-24 18:01 52224 —-a-w- c:\windows\system32\sdtnpm.dll 2012-08-01 22:45 . 2012-08-01 22:45 ——– dc—-w- c:\program files (x86)\Common Files\NeatReceipts 2012-08-01 22:45 . 2012-08-01 22:45 ——– d—–w- c:\program files\Common Files\NeatReceipts 2012-08-01 22:43 . 2012-08-01 22:43 ——– dc—-w- c:\program files (x86)\Common Files\Intuit 2012-08-01 22:41 . 2012-08-01 22:41 ——– d—–w- c:\programdata\The Neat Company 2012-08-01 22:41 . 2012-08-05 20:45 ——– d—–w- c:\program files\Common Files\The Neat Company 2012-08-01 22:41 . 2012-08-01 23:01 ——– dc—-w- c:\program files (x86)\Common Files\The Neat Company 2012-08-01 22:29 . 2012-08-01 22:29 ——– dc—-w- c:\program files (x86)\Neat 2012-08-01 22:24 . 2012-08-01 22:24 ——– d—–w- c:\program files\Microsoft Synchronization Services 2012-08-01 22:24 . 2012-08-01 22:24 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition 2012-08-01 22:23 . 2012-08-01 22:23 ——– dc—-w- c:\program files (x86)\Microsoft Synchronization Services 2012-08-01 22:23 . 2012-08-01 22:23 ——– dc—-w- c:\program files (x86)\Microsoft SQL Server Compact Edition 2012-08-01 22:07 . 2012-08-01 22:07 ——– d—–w- c:\users\Frank.mypcwin7\AppData\Local\VirtualStore 2012-08-01 22:06 . 2012-08-01 22:06 ——– d—–w- c:\users\Frank.mypcwin7\AppData\Roaming\Logitech 2012-07-30 23:51 . 2012-07-30 23:51 ——– d—–w- c:\programdata\Logitech 2012-07-30 23:42 . 2012-07-30 23:42 ——– d—–w- c:\users\Blanca\AppData\Roaming\Leadertech 2012-07-30 23:42 . 2012-07-30 23:42 53248 —-a-r- c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2012-07-30 23:42 . 2012-07-30 23:42 ——– dc—-w- c:\program files (x86)\Common Files\LogiShrd 2012-07-30 23:42 . 2012-07-30 23:42 18960 —-a-w- c:\windows\system32\drivers\LNonPnP.sys 2012-07-30 23:34 . 2012-07-30 23:43 ——– d—–w- c:\programdata\Logishrd 2012-07-30 23:34 . 2012-07-30 23:35 ——– d—–w- c:\program files\Logitech 2012-07-27 06:20 . 2012-07-27 06:27 ——– d—–w- c:\users\Blanca\Incomplete 2012-07-27 06:19 . 2012-07-30 23:42 ——– d—–w- c:\program files\Common Files\LogiShrd 2012-07-27 06:19 . 2012-07-30 23:43 ——– d—–w- c:\users\Blanca\AppData\Roaming\Logitech 2012-07-27 06:19 . 2012-07-27 06:19 ——– d—–w- c:\users\Blanca\AppData\Roaming\Logishrd 2012-07-22 22:59 . 2012-08-08 10:58 ——– d—–w- c:\users\LogMeInRemoteUser . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-10 01:01 . 2012-06-02 20:40 82816 —-a-w- c:\users\Blanca\AppData\Roaming\pcouffin.sys 2012-08-08 09:04 . 2012-04-11 10:00 5120 —-a-w- c:\windows\SysWow64\wmi.dll 2012-08-08 09:04 . 2012-04-11 10:00 172032 —-a-w- c:\windows\SysWow64\wintrust.dll 2012-08-08 09:04 . 2012-04-11 10:00 155136 —-a-w- c:\windows\SysWow64\imagehlp.dll 2012-08-08 09:04 . 2011-04-27 05:43 73728 ——w- c:\windows\SysWow64\fsutil.exe 2012-08-08 09:04 . 2011-04-27 05:43 1698816 ——w- c:\windows\SysWow64\esent.dll 2012-08-08 09:01 . 2012-06-23 16:04 51200 —-a-w- c:\windows\system32\wuauclt.exe 2012-08-08 09:01 . 2012-06-23 16:04 37376 —-a-w- c:\windows\system32\wups2.dll 2012-08-08 09:01 . 2012-06-23 16:04 2621952 —-a-w- c:\windows\system32\wucltux.dll 2012-08-08 09:01 . 2012-06-23 16:04 2420736 —-a-w- c:\windows\system32\wuaueng.dll 2012-08-08 09:01 . 2012-06-23 16:04 98304 —-a-w- c:\windows\system32\wudriver.dll 2012-08-08 09:01 . 2012-06-23 16:04 695808 —-a-w- c:\windows\system32\wuapi.dll 2012-08-08 09:01 . 2012-06-23 16:04 33280 —-a-w- c:\windows\system32\wups.dll 2012-08-08 09:01 . 2012-06-23 16:04 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-08-08 09:01 . 2012-06-23 16:04 178688 —-a-w- c:\windows\system32\wuwebv.dll 2012-08-08 09:01 . 2012-04-11 10:00 5120 —-a-w- c:\windows\system32\wmi.dll 2012-08-08 09:01 . 2012-04-11 10:00 220672 —-a-w- c:\windows\system32\wintrust.dll 2012-08-08 09:01 . 2012-04-11 10:00 76800 —-a-w- c:\windows\system32\imagehlp.dll 2012-08-08 09:01 . 2011-03-25 03:54 270720 ——w- c:\windows\system32\MpSigStub.exe 2012-08-08 09:01 . 2012-05-09 14:37 1924480 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-08-08 09:01 . 2011-05-11 03:22 52224 —-a-w- c:\windows\system32\drivers\usbehci.sys 2012-08-08 09:01 . 2011-05-11 03:22 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2012-08-08 09:01 . 2011-05-11 03:22 325120 —-a-w- c:\windows\system32\drivers\usbport.sys 2012-08-08 09:01 . 2011-05-11 03:22 98816 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2012-08-08 09:01 . 2011-05-11 03:22 7936 —-a-w- c:\windows\system32\drivers\usbd.sys 2012-08-08 09:01 . 2011-05-11 03:22 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2012-08-08 09:01 . 2011-04-27 05:43 96256 ——w- c:\windows\system32\fsutil.exe 2012-08-08 09:01 . 2011-04-27 05:43 2565632 ——w- c:\windows\system32\esent.dll 2012-08-08 09:01 . 2011-04-27 05:43 189824 ——w- c:\windows\system32\drivers\storport.sys 2012-08-08 08:58 . 2012-05-09 14:37 75136 —-a-w- c:\windows\system32\drivers\partmgr.sys 2012-08-08 08:58 . 2012-04-11 10:00 23104 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-08-08 08:58 . 2011-04-27 05:43 410496 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2012-08-08 08:58 . 2011-04-27 05:43 27008 —-a-w- c:\windows\system32\drivers\amdxata.sys 2012-08-08 08:58 . 2011-04-27 05:43 166272 —-a-w- c:\windows\system32\drivers\nvstor.sys 2012-08-08 08:58 . 2011-04-27 05:43 1659776 ——w- c:\windows\system32\drivers\ntfs.sys 2012-08-08 08:58 . 2011-04-27 05:43 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys 2012-07-12 16:44 . 2012-07-12 16:44 110080 —-a-r- c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconF7A21AF7.exe 2012-07-12 16:44 . 2012-07-12 16:44 110080 —-a-r- c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\IconD7F16134.exe 2012-07-12 16:44 . 2012-07-12 16:44 110080 —-a-r- c:\users\Blanca\AppData\Roaming\Microsoft\Installer\{7289B0CC-BC41-4C7E-A2C7-DB1259E8E47A}\Icon5B4E0377.exe 2012-07-11 10:04 . 2011-03-25 04:13 59701280 —-a-w- c:\windows\system32\MRT.exe 2012-07-03 20:46 . 2012-05-08 06:39 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-25 23:04 . 2012-06-25 23:04 1394248 —-a-w- c:\windows\SysWow64\msxml4.dll 2012-06-22 22:35 . 2012-05-15 07:09 251560 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2012-06-22 17:43 . 2012-08-06 20:54 3488 —-a-w- c:\windows\UDB.zip 2012-06-22 17:43 . 2012-08-06 20:54 131 —-a-w- c:\windows\IDB.zip 2012-06-17 19:57 . 2012-06-17 19:57 476936 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2012-06-17 19:57 . 2011-03-26 17:52 472840 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-06-12 03:08 . 2012-07-12 15:11 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-06-09 05:43 . 2012-07-11 06:42 14172672 —-a-w- c:\windows\system32\shell32.dll 2012-06-06 06:06 . 2012-07-11 06:42 2004480 —-a-w- c:\windows\system32\msxml6.dll 2012-06-06 06:06 . 2012-07-11 06:42 1881600 —-a-w- c:\windows\system32\msxml3.dll 2012-06-06 06:02 . 2012-07-11 06:42 1133568 —-a-w- c:\windows\system32\cdosys.dll 2012-06-06 05:05 . 2012-07-11 06:42 1390080 —-a-w- c:\windows\SysWow64\msxml6.dll 2012-06-06 05:05 . 2012-07-11 06:42 1236992 —-a-w- c:\windows\SysWow64\msxml3.dll 2012-06-06 05:03 . 2012-07-11 06:42 805376 —-a-w- c:\windows\SysWow64\cdosys.dll 2012-06-02 20:40 . 2012-06-02 20:40 82816 —-a-w- c:\windows\system32\drivers\pcouffin.sys 2012-06-02 12:49 . 2012-07-11 10:02 17807360 —-a-w- c:\windows\system32\mshtml.dll 2012-06-02 12:17 . 2012-07-11 10:02 10924032 —-a-w- c:\windows\system32\ieframe.dll 2012-06-02 12:12 . 2012-07-11 10:02 2311680 —-a-w- c:\windows\system32\jscript9.dll 2012-06-02 12:05 . 2012-07-11 10:02 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-06-02 12:05 . 2012-07-11 10:02 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-06-02 12:04 . 2012-07-11 10:02 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-06-02 12:04 . 2012-07-11 10:02 237056 —-a-w- c:\windows\system32\url.dll 2012-06-02 12:03 . 2012-07-11 10:02 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-06-02 12:01 . 2012-07-11 10:02 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-06-02 12:00 . 2012-07-11 10:02 818688 —-a-w- c:\windows\system32\jscript.dll 2012-06-02 11:59 . 2012-07-11 10:02 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-06-02 11:57 . 2012-07-11 10:02 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-06-02 11:57 . 2012-07-11 10:02 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-06-02 11:54 . 2012-07-11 10:02 248320 —-a-w- c:\windows\system32\ieui.dll 2012-06-02 08:33 . 2012-07-11 10:02 1800192 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-06-02 08:25 . 2012-07-11 10:02 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-06-02 08:25 . 2012-07-11 10:02 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-06-02 08:20 . 2012-07-11 10:02 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-06-02 08:16 . 2012-07-11 10:02 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-06-02 05:50 . 2012-07-11 06:42 458704 —-a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 05:48 . 2012-07-11 06:42 95600 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 05:48 . 2012-07-11 06:42 151920 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 05:45 . 2012-07-11 06:42 340992 —-a-w- c:\windows\system32\schannel.dll 2012-06-02 05:44 . 2012-07-11 06:42 307200 —-a-w- c:\windows\system32\ncrypt.dll 2012-06-02 04:40 . 2012-07-11 06:42 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2012-06-02 04:40 . 2012-07-11 06:42 225280 —-a-w- c:\windows\SysWow64\schannel.dll 2012-06-02 04:39 . 2012-07-11 06:42 219136 —-a-w- c:\windows\SysWow64\ncrypt.dll 2012-06-02 04:34 . 2012-07-11 06:42 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2010-03-30 01:40 . 2010-03-30 01:40 100256 ——w- c:\program files\Common Files\LinkInstaller.exe . . ((((((((((((((((((((((((((((( SnapShot@2012-08-10_22.44.37 ))))))))))))))))))))))))))))))))))))))))) . - 2012-08-06 20:55 . 2012-08-10 17:56 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2012-08-06 20:55 . 2012-08-11 22:53 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2009-07-14 04:54 . 2012-08-11 22:53 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-08-10 17:56 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-08-10 22:43 81920 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-08-11 22:53 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-08-10 17:56 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-03-25 03:33 . 2012-08-10 22:43 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-03-25 03:33 . 2012-08-12 20:14 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-08-12 20:14 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-08-10 22:43 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 05:12 . 2012-08-12 20:14 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat - 2009-07-14 05:12 . 2012-08-10 22:43 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat - 2011-03-25 03:33 . 2012-08-10 22:43 131072 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-03-25 03:33 . 2012-08-12 20:14 131072 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240] "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2011-02-02 5546376] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040] "runfile"="c:\program files (x86)\DisplayLink\DLsetup\NoConsoleExe.exe" [2011-03-18 7168] "ControlCenter4"="c:\program files (x86)\ControlCenter4\BrCcBoot.exe" [2011-04-21 139264] "BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2011-05-19 2629632] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] . c:\users\Blanca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech . Product Registration.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R0 sptd;sptd; [x] R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 CrossLoopService;CrossLoop Service;c:\users\Blanca\AppData\Local\CrossLoop\CrossLoopService.exe [2010-08-18 560848] R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [2012-02-17 545064] R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys [2011-11-18 79952] R3 cpuz134;cpuz134;c:\users\Blanca\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 71168] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [2011-03-03 13088] R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2012-06-02 82816] R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [2012-06-22 92928] R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992] R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe [2012-06-22 402368] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 88960] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-20 34816] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 117248] R3 tvnserver;TightVNC Server;c:\users\Blanca\AppData\Local\CrossLoop\tvnserver.exe [2010-07-21 814080] R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe [2011-10-15 466736] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-03-25 1255736] S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [2012-03-21 691896] S0 dlkmdldr;dlkmdldr;c:\windows\system32\drivers\dlkmdldr.sys [2012-02-08 15184] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [2012-04-23 426616] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [2012-02-28 453896] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [2012-02-28 1096176] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280] S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [2011-10-03 1263200] S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2011-11-15 103504] S1 BDVEDISK;BDVEDISK;c:\windows\system32\DRIVERS\bdvedisk.sys [2010-01-20 103944] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys [2012-06-22 341200] S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [2012-06-22 251560] S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/09/03 15:40];f:\programs\MEDIA\PowerDVD10\NavFilter\000.fcl [2010-04-02 16:11 146928] S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2011-10-03 3246040] S2 Agent;Agent;c:\windows\agent_x64.exe [2011-08-24 102912] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-06-22 575448] S2 DisplayLinkService;DisplayLinkManager;c:\program files\DisplayLink Core Software\DisplayLinkManager.exe [2012-02-08 8454064] S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-03-09 144672] S2 UPDATESRV;BitDefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender 2012\updatesrv.exe [2012-03-14 66096] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2011-10-03 285280] S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys [2011-11-25 258736] S3 BrSerIb;Brother Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys [2009-11-03 87552] S3 BrUsbSIb;Brother Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys [2009-11-03 14592] S3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760] S3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\DRIVERS\DisplayLinkUsbPort_6.1.36484.0.sys [2012-02-08 17408] S3 dlkmd;dlkmd;c:\windows\system32\drivers\dlkmd.sys [2012-02-08 308560] S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056] S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128] S3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD64.sys [2012-06-22 85224] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-10-16 19:49 451872 -c—-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2012-08-12 c:\windows\Tasks\SpyHunter4.job - c:\program files\Enigma Software Group\SpyHunter\SpyHunter4.exe [2012-07-11 21:58] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2011-02-02 390720] "BDAgent"="c:\program files\Bitdefender\Bitdefender 2012\bdagent.exe" [2012-04-26 1067256] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152] "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2010-11-04 1580368] . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ig/ mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Free YouTube Download - c:\users\Blanca\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm IE: {{9f31204d-6ed9-4489-a8c6-9310de31aa59} - f:\programs\MEDIA\Clip Extractor\ClipExtractor.exe LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll Trusted Zone: cleverreach.com\novastor Trusted Zone: google-analytics.com Trusted Zone: novastor.com TCP: DhcpNameServer = 192.168.1.1 192.168.1.1 . - - - - ORPHANS REMOVED - - - - . WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}] "ImagePath"="\??\f:\programs\MEDIA\PowerDVD10\NavFilter\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\SetId\Internal] @Denied: (A 2) (LocalSystem) "DEVICE2"="yquvvMjIyQA=" "DATA2"="\0a" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{3DA165B6-CC41-11d2-BDC6-00C04F79EC6B}\ProgID] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{3DA165B6-CC41-11d2-BDC6-00C04F79EC6B}\Version] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-08-12 14:15:25 ComboFix-quarantined-files.txt 2012-08-12 21:15 ComboFix2.txt 2012-08-10 22:55 . Pre-Run: 18,488,299,520 bytes free Post-Run: 18,390,831,104 bytes free . - - End Of File - - 5199D045580C2A16FE5D789D0034F5BB
No, actually it is going right to my home page when i log onto the internet…about:blank seems to be taken care of as well as a couple other glitches i was seeing when I ran IE …
Hi,

Thanks for the feedback.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Make sure you saved the log somewhere else. Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI