This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible Infection? Keep getting random redirects in IE [Closed]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Recently I'll get redirected to malicous sites when attempting to go to known good sites. WoT catches it, but I keep thinking I may have an infection causing this.
Any help appreciated. OS: Windows 7 Professional SP 1 x64.
Running MS Security Essentials.
Most of the time I'll browse using Sandboxie… occasionallly I'll just use default IE9.

HijackThis Scan Results:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:51:34 PM, on 9/17/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\ATK Hotkey\HControlUser.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files (x86)\Fisher-Price\iXL\iXL.Middleware.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\WINDOWS\SYSTEM32\PROCEXP.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Tools\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
O4 - HKLM\..\Run: [HControlUser] "C:\Program Files (x86)\ATK Hotkey\HcontrolUser.exe"
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [iXL_MiddleWare] C:\Program Files (x86)\Fisher-Price\iXL\iXL.Middleware.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - HKCU\..\Run: [Temporary Internet Files] rundll32.exe "C:\Users\Cherie\AppData\Local\VirtualStore\Temporary Internet Files\jzjtx.dll",winampGetInModule2W
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {12193C65-F0E1-4DD1-AD4E-DB73C6911014} (DCPForm Control 1.0.1.4) - file:///D:/activeX/DCP.cab
O16 - DPF: {721700FE-7F0E-49C5-BDED-CA92B7CB1245} (Camera Stream Client Control Object) - https://www.mydlink.com/8D/activeX//dcsclictrl.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FB1C9BD4-54A9-4996-9FAA-579DCC4204DF} (ParentWatchLive_3_01 Class) - https://www.parentwatch.com/centers/video/push-3-01-00.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com//activex/ractrl.cab?lmi=928
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11063 bytes


thanks!
Additional Information: . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 22:01:40 on 2012-09-17 Microsoft Windows 7 Enterprise 6.1.7601.1.1252.1.1033.18.4031.2594 [GMT -5:00] . AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Sandboxie\SbieSvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files (x86)\ATK Hotkey\ASLDRSrv.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe C:\Program Files\Microsoft LifeCam\MSCamS64.exe C:\Program Files (x86)\ATK Hotkey\Hcontrol.exe C:\Program Files (x86)\ATK Hotkey\MsgTranAgt.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\ATK Hotkey\MsgTranAgt64.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\ATK Hotkey\LOSD.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Sandboxie\SbieCtrl.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe C:\Windows\System32\rundll32.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\ATK Hotkey\HControlUser.exe C:\Windows\SysWOW64\rundll32.exe C:\Program Files (x86)\Citrix\ICA Client\concentr.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe C:\Program Files (x86)\Fisher-Price\iXL\iXL.Middleware.exe C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\ATK Hotkey\ATKOSD.exe C:\Program Files (x86)\ATK Hotkey\WDC.exe C:\Windows\system32\wuauclt.exe C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\SysWOW64\DllHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - C:\Program Files (x86)\WOT\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - C:\Program Files (x86)\WOT\WOT.dll EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll uRun: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" uRun: [Temporary Internet Files] rundll32.exe "C:\Users\Cherie\AppData\Local\VirtualStore\Temporary Internet Files\jzjtx.dll",winampGetInModule2W mRun: [HControlUser] "C:\Program Files (x86)\ATK Hotkey\HcontrolUser.exe" mRun: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon mRun: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe" mRun: [iXL_MiddleWare] C:\Program Files (x86)\Fisher-Price\iXL\iXL.Middleware.exe mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll DPF: {12193C65-F0E1-4DD1-AD4E-DB73C6911014} - file:///D:/activeX/DCP.cab DPF: {721700FE-7F0E-49C5-BDED-CA92B7CB1245} - hxxps://www.mydlink.com/8D/activeX//dcsclictrl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {FB1C9BD4-54A9-4996-9FAA-579DCC4204DF} - hxxps://www.parentwatch.com/centers/video/push-3-01-00.cab DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com//activex/ractrl.cab?lmi=928 TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{37F18CAC-89DD-448A-B2D9-A5797AF6B78C} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{37F18CAC-89DD-448A-B2D9-A5797AF6B78C}\34963736F68333831343 : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{37F18CAC-89DD-448A-B2D9-A5797AF6B78C}\64279637B6974496E676F6 : DhcpNameServer = [removed] [removed] TCP: Interfaces\{C25BE034-5F5F-477D-B0D3-91BE40746F8F} : DhcpNameServer = 192.168.1.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL IFEO: taskmgr.exe - "C:\WINDOWS\SYSTEM32\PROCEXP.EXE" BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll BHO-X64: Canon Easy-WebPrint EX BHO - No File BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll TB-X64: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll EB-X64: {21347690-EC41-4F9A-8887-1F4AEE672439} - No File mRun-x64: [HControlUser] "C:\Program Files (x86)\ATK Hotkey\HcontrolUser.exe" mRun-x64: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon mRun-x64: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup mRun-x64: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe" mRun-x64: [iXL_MiddleWare] C:\Program Files (x86)\Fisher-Price\iXL\iXL.Middleware.exe mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL IFEO-X64: taskmgr.exe - "C:\WINDOWS\SYSTEM32\PROCEXP.EXE" . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys –> C:\Windows\system32\DRIVERS\MpFilter.sys [?] R1 ctxusbm;Citrix USB Monitor Driver;C:\Windows\system32\DRIVERS\ctxusbm.sys –> C:\Windows\system32\DRIVERS\ctxusbm.sys [?] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys –> C:\Windows\system32\drivers\IntcHdmi.sys [?] R3 itecir;ITECIR Infrared Receiver;C:\Windows\system32\DRIVERS\itecir.sys –> C:\Windows\system32\DRIVERS\itecir.sys [?] R3 MTsensor64;PU ACPI UTILITY;C:\Windows\system32\DRIVERS\PuAcpi64.sys –> C:\Windows\system32\DRIVERS\PuAcpi64.sys [?] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys –> C:\Windows\system32\DRIVERS\netw5v64.sys [?] R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2012-6-17 166576] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944] S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys –> C:\Windows\system32\drivers\dmvsc.sys [?] S3 MatSvc;Microsoft Automated Troubleshooting Service;C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2011-6-13 343856] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536] S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\system32\Drivers\nx6000.sys –> C:\Windows\system32\Drivers\nx6000.sys [?] S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys –> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?] S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696] S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys –> C:\Windows\system32\drivers\rdpvideominiport.sys [?] S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992] S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys –> C:\Windows\system32\drivers\synth3dvsc.sys [?] S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys –> C:\Windows\system32\drivers\terminpt.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?] S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys –> C:\Windows\system32\drivers\tsusbhub.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] . =============== Created Last 30 ================ . 2012-09-18 02:30:51 9310152 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{00E4D1C0-225A-4749-A599-406AA9FBB293}\mpengine.dll 2012-09-16 15:37:08 9310152 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-09-13 04:09:04 ——– d—–w- C:\cherie stuff 2012-09-11 03:23:14 ——– d—–w- C:\Jensen Project 2012-09-07 04:04:27 ——– d—–w- C:\Landens First Birthday 2012-09-02 21:00:52 ——– d—–w- C:\Cisco Router Backups 2012-09-02 16:32:21 ——– d—–w- C:\camera captures 2012-09-02 16:28:24 ——– d—–w- C:\Program Files\DivX 2012-09-02 16:28:19 ——– d—–w- C:\Program Files (x86)\Common Files\DivX Shared 2012-09-02 16:27:35 ——– d—–w- C:\Program Files (x86)\DivX 2012-09-02 16:27:09 ——– d—–w- C:\ProgramData\DivX 2012-09-02 15:57:37 ——– d—–w- C:\Program Files (x86)\NetworkSurveillanceAX 2012-09-02 14:28:26 ——– d—–w- C:\ProgramData\Cisco Systems 2012-08-29 02:43:22 ——– d—–w- C:\ProgramData\Battle.net 2012-08-25 16:04:44 ——– d—–r- C:\Program Files (x86)\Skype 2012-08-20 04:48:14 446464 —-a-w- C:\Windows\SysWow64\wmvdmoe.dll 2012-08-20 04:47:37 ——– d—–w- C:\ProgramData\PY_Software 2012-08-20 04:47:37 ——– d—–w- C:\Program Files\Argus Surveillance DVR . ==================== Find3M ==================== . 2012-07-19 13:05:53 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-19 13:05:53 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-07-18 18:15:06 3148800 —-a-w- C:\Windows\System32\win32k.sys 2012-07-04 22:13:27 59392 —-a-w- C:\Windows\System32\browcli.dll 2012-07-04 22:13:27 136704 —-a-w- C:\Windows\System32\browser.dll 2012-07-04 21:14:34 41984 —-a-w- C:\Windows\SysWow64\browcli.dll 2012-06-29 03:56:34 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2012-06-29 03:49:11 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-06-29 03:48:07 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-06-29 03:43:49 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-06-29 03:39:48 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-06-29 00:16:58 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-06-29 00:09:01 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-06-29 00:08:59 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-06-29 00:04:43 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-06-29 00:00:45 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-06-20 16:56:41 71104 —-a-w- C:\Windows\CouponPrinter.ocx . ============= FINISH: 22:02:26.47 ===============

Attachments:

Hello flayofish and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your logs now and will reply with instructions shortly.

Satchfan
Hello again.

I need some more scans to see what may be happening here.

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    consrv.dll
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Thank you for taking time to address my issue, Satchfan.

Prior to your response, I did find a virus on my laptop: http://www.microsoft.com/security/portal/T…atid=2147659134

However, this did not fix my redirect issue.
See below for results of requested scans:

OTL:

OTL logfile created on: 9/18/2012 9:14:45 PM - Run 1
OTL by OldTimer - Version 3.2.64.0 Folder = C:\Tools
64bit- Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.94 Gb Total Physical Memory | 2.15 Gb Available Physical Memory | 54.52% Memory free
7.87 Gb Paging File | 5.95 Gb Available in Paging File | 75.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297.99 Gb Total Space | 105.63 Gb Free Space | 35.45% Space Free | Partition Type: NTFS

Computer Name: CHERIE-PC | User Name: Cherie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/18 21:14:03 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Tools\OTL.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/05 18:50:30 | 000,295,304 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2012/07/05 18:41:08 | 007,392,136 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2012/05/20 09:13:00 | 000,351,904 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
PRC - [2011/08/04 09:57:18 | 000,056,376 | —- | M] (Fisher-Price) – C:\Program Files (x86)\Fisher-Price\iXL\iXL.Middleware.exe
PRC - [2011/07/28 18:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/04/02 11:18:54 | 001,185,112 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
PRC - [2010/03/02 20:52:00 | 000,140,640 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
PRC - [2009/09/12 23:09:10 | 000,103,768 | —- | M] (Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
PRC - [2009/09/12 23:09:04 | 000,550,232 | —- | M] (Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
PRC - [2009/05/22 20:06:28 | 000,245,760 | —- | M] (Pegatron Corp.) – C:\Program Files (x86)\ATK Hotkey\HControl.exe
PRC - [2009/03/16 20:21:30 | 002,789,376 | R— | M] () – C:\Program Files (x86)\ATK Hotkey\ATKOSD.exe
PRC - [2009/03/11 15:39:12 | 000,098,304 | R— | M] () – C:\Program Files (x86)\ATK Hotkey\AsLdrSrv.exe
PRC - [2009/02/17 18:08:40 | 000,151,552 | R— | M] () – C:\Program Files (x86)\ATK Hotkey\WDC.exe
PRC - [2009/02/13 18:28:50 | 000,098,304 | R— | M] () – C:\Program Files (x86)\ATK Hotkey\HControlUser.exe
PRC - [2009/02/13 18:24:48 | 000,110,592 | R— | M] () – C:\Program Files (x86)\ATK Hotkey\MsgTranAgt.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/19 08:33:48 | 012,436,480 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012/06/19 08:33:38 | 001,591,808 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012/05/19 16:47:53 | 005,452,800 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/05/19 16:47:49 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/05/19 16:47:47 | 007,967,232 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/05/19 16:47:35 | 011,492,864 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/28 18:09:42 | 000,096,112 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/28 18:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/07/20 10:59:04 | 001,283,744 | —- | M] () – C:\Program Files (x86)\WOT\WOT.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2009/02/13 18:28:50 | 000,098,304 | R— | M] () – C:\Program Files (x86)\ATK Hotkey\HControlUser.exe
MOD - [2007/11/12 16:41:50 | 000,106,496 | R— | M] () – C:\Program Files (x86)\ATK Hotkey\MsgTran.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/07/11 13:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2012/06/17 02:52:14 | 000,098,576 | —- | M] (SANDBOXIE L.T.D) [Auto | Running] – C:\Program Files\Sandboxie\SbieSvc.exe – (SbieSvc)
SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2011/06/13 23:21:14 | 000,343,856 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Fix it Center\Matsvc.exe – (MatSvc)
SRV:64bit: - [2010/05/20 16:26:28 | 000,199,536 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft LifeCam\MSCamS64.exe – (MSCamSvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 14:14:14 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/07/05 18:41:08 | 007,392,136 | —- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe – (LeapFrog Connect Device Service)
SRV - [2010/03/18 14:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/03/11 15:39:12 | 000,098,304 | R— | M] () [Auto | Running] – C:\Program Files (x86)\ATK Hotkey\AsLdrSrv.exe – (ASLDRService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/06/17 02:52:12 | 000,166,576 | —- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] – C:\Program Files\Sandboxie\SbieDrv.sys – (SbieDrv)
DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/15 11:01:50 | 000,052,736 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/12/15 12:29:42 | 000,031,232 | —- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tap0901.sys – (tap0901)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 22:24:43 | 000,020,992 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2010/11/20 22:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 22:23:48 | 000,117,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tsusbhub.sys – (tsusbhub)
DRV:64bit: - [2010/11/20 22:23:48 | 000,088,960 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Synth3dVsc.sys – (Synth3dVsc)
DRV:64bit: - [2010/11/20 22:23:48 | 000,071,168 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2010/11/20 22:23:48 | 000,034,816 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2010/11/20 22:23:47 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 22:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/08/25 20:36:04 | 010,611,552 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/07/13 10:57:08 | 000,069,736 | —- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\itecir.sys – (itecir)
DRV:64bit: - [2010/05/20 16:26:28 | 000,036,720 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nx6000.sys – (MSHUSBVideo)
DRV:64bit: - [2009/09/08 18:13:16 | 000,087,600 | —- | M] (Citrix Systems, Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\ctxusbm.sys – (ctxusbm)
DRV:64bit: - [2009/08/07 06:24:14 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/25 18:04:20 | 000,067,584 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\rimmpx64.sys – (rimmptsk)
DRV:64bit: - [2009/06/25 17:38:52 | 000,057,856 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\rixdpx64.sys – (rismxdp)
DRV:64bit: - [2009/06/25 17:13:44 | 000,055,296 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\rimspx64.sys – (rimsptsk)
DRV:64bit: - [2009/06/10 16:01:14 | 001,227,776 | —- | M] (Motorola Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SmSerl64.sys – (smserial)
DRV:64bit: - [2009/06/10 15:35:28 | 005,434,368 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\netw5v64.sys – (netw5v64)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 23:44:48 | 000,015,880 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\PuAcpi64.sys – (MTsensor64)
DRV:64bit: - [2009/05/26 05:13:10 | 000,138,752 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A9 57 18 1A 15 99 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {A03A04FA-899E-4B97-B352-A415E31C9567}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{A03A04FA-899E-4B97-B352-A415E31C9567}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Cherie\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Cherie\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Cherie\AppData\Local\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Cherie\AppData\Local\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Cherie\AppData\Local\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Cherie\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Users\Cherie\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.2_0\
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Users\Cherie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Ghostery = C:\Users\Cherie\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\2.4.0_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ATK Hotkey\HcontrolUser.exe ()
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [iXL_MiddleWare] C:\Program Files (x86)\Fisher-Price\iXL\iXL.Middleware.exe (Fisher-Price)
O4 - HKLM..\Run: [LifeCam] C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Monitor] C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [Temporary Internet Files] C:\Users\Cherie\AppData\Local\VirtualStore\Temporary Internet Files\jzjtx.dll (Hewlett-Packard)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {12193C65-F0E1-4DD1-AD4E-DB73C6911014} file:///D:/activeX/DCP.cab (DCPForm Control 1.0.1.4)
O16 - DPF: {721700FE-7F0E-49C5-BDED-CA92B7CB1245} https://www.mydlink.com/8D/activeX//dcsclictrl.cab (Camera Stream Client Control Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FB1C9BD4-54A9-4996-9FAA-579DCC4204DF} https://www.parentwatch.com/centers/video/push-3-01-00.cab (ParentWatchLive_3_01 Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com//activex/ractrl.cab?lmi=928 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{37F18CAC-89DD-448A-B2D9-A5797AF6B78C}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C25BE034-5F5F-477D-B0D3-91BE40746F8F}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\wot - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2a4f371e-476e-11e0-a3a6-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{2a4f371e-476e-11e0-a3a6-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/18 01:25:16 | 000,000,000 | —D | C] – C:\Users\Cherie\AppData\Roaming\SUPERAntiSpyware.com
[2012/09/18 01:25:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012/09/18 01:25:07 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2012/09/18 01:25:07 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/09/17 22:28:49 | 000,000,000 | —D | C] – C:\Users\Cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UVK
[2012/09/17 22:28:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\UVK
[2012/09/12 23:09:04 | 000,000,000 | —D | C] – C:\cherie stuff
[2012/09/12 22:26:07 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/09/10 22:23:14 | 000,000,000 | —D | C] – C:\Jensen Project
[2012/09/06 23:04:27 | 000,000,000 | —D | C] – C:\Landens First Birthday
[2012/09/02 16:00:52 | 000,000,000 | —D | C] – C:\Cisco Router Backups
[2012/09/02 11:39:04 | 000,000,000 | —D | C] – C:\Users\Cherie\AppData\Roaming\DivX
[2012/09/02 11:32:21 | 000,000,000 | —D | C] – C:\camera captures
[2012/09/02 11:28:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[2012/09/02 11:28:24 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2012/09/02 11:28:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DivX Shared
[2012/09/02 11:27:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\DivX
[2012/09/02 11:27:09 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2012/09/02 10:57:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\NetworkSurveillanceAX
[2012/09/02 09:28:26 | 000,000,000 | —D | C] – C:\ProgramData\Cisco Systems
[2012/08/28 21:43:22 | 000,000,000 | —D | C] – C:\ProgramData\Battle.net
[2012/08/25 11:04:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/08/25 11:04:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2012/08/25 11:04:44 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2012/08/19 23:48:14 | 000,446,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmvdmoe.dll
[2012/08/19 23:48:01 | 000,000,000 | —D | C] – C:\Users\Cherie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Argus Surveillance
[2012/08/19 23:48:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Argus Surveillance
[2012/08/19 23:47:37 | 000,000,000 | —D | C] – C:\ProgramData\PY_Software
[2012/08/19 23:47:37 | 000,000,000 | —D | C] – C:\Program Files\Argus Surveillance DVR

========== Files - Modified Within 30 Days ==========

[2012/09/18 20:54:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-39385524-2566068495-1255450090-1000UA.job
[2012/09/18 17:25:00 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 69956a67-ceaa-412e-812b-40b69f78bfb1.job
[2012/09/18 06:09:18 | 000,022,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 06:09:18 | 000,022,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 06:01:54 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/09/18 06:01:46 | 3170,009,088 | -HS- | M] () – C:\hiberfil.sys
[2012/09/18 02:00:00 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1598bd21-166e-433d-b225-f0df51aa44dd.job
[2012/09/18 01:25:14 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/09/17 22:54:05 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-39385524-2566068495-1255450090-1000Core.job
[2012/09/17 22:28:49 | 000,000,954 | —- | M] () – C:\Users\Cherie\Desktop\UVK.lnk
[2012/09/17 22:06:22 | 000,001,650 | —- | M] () – C:\Users\Cherie\Desktop\Attach.zip
[2012/09/17 21:57:13 | 000,061,585 | —- | M] () – C:\Users\Cherie\Desktop\Capture.JPG
[2012/09/16 19:23:00 | 044,454,194 | —- | M] () – C:\Users\Cherie\Desktop\20120102_145000.avi
[2012/09/09 12:25:50 | 000,001,130 | —- | M] () – C:\Users\Cherie\Desktop\IMAG0139.jpg - Shortcut (2).lnk
[2012/09/04 23:52:24 | 000,000,781 | —- | M] () – C:\Users\Cherie\Desktop\The Universe — Full Episodes & Video Online — H2 on History.com.website
[2012/09/04 22:47:38 | 001,323,284 | —- | M] () – C:\Users\Cherie\Desktop\brothers.jpg
[2012/09/04 19:56:10 | 000,002,416 | —- | M] () – C:\Users\Cherie\Desktop\Google Chrome.lnk
[2012/09/03 21:22:40 | 000,001,450 | —- | M] () – C:\Users\Cherie\Desktop\sda1 (192.168.1.1) - Shortcut.lnk
[2012/09/03 20:42:47 | 000,729,944 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/03 20:42:47 | 000,626,540 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/09/03 20:42:47 | 000,107,784 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/09/02 11:25:14 | 008,911,636 | —- | M] () – C:\Users\Cherie\Desktop\20120902_111500.avi
[2012/09/02 11:14:37 | 001,835,008 | —- | M] () – C:\Users\Cherie\Desktop\20120902_111414.avi
[2012/09/02 11:14:37 | 001,835,008 | —- | M] () – C:\Users\Cherie\Desktop\20120902_111414 - Copy.avi
[2012/09/02 10:50:12 | 000,001,024 | —- | M] () – C:\Users\Cherie\Desktop\My Camera (30941163).lnk
[2012/09/02 09:58:16 | 000,001,084 | —- | M] () – C:\Users\Cherie\Desktop\Cisco Connect Cloud.lnk
[2012/09/01 10:30:35 | 000,001,972 | —- | M] () – C:\Windows\Sandboxie.ini
[2012/08/25 11:04:50 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2012/08/19 23:14:28 | 001,354,671 | —- | M] () – C:\Users\Cherie\Desktop\Argus_DVR_Manual.pdf

========== Files Created - No Company Name ==========

[2012/09/18 01:25:20 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 69956a67-ceaa-412e-812b-40b69f78bfb1.job
[2012/09/18 01:25:20 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1598bd21-166e-433d-b225-f0df51aa44dd.job
[2012/09/18 01:25:14 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/09/17 22:28:49 | 000,000,954 | —- | C] () – C:\Users\Cherie\Desktop\UVK.lnk
[2012/09/17 22:06:22 | 000,001,650 | —- | C] () – C:\Users\Cherie\Desktop\Attach.zip
[2012/09/17 21:57:13 | 000,061,585 | —- | C] () – C:\Users\Cherie\Desktop\Capture.JPG
[2012/09/16 19:21:07 | 044,454,194 | —- | C] () – C:\Users\Cherie\Desktop\20120102_145000.avi
[2012/09/09 12:25:50 | 000,001,130 | —- | C] () – C:\Users\Cherie\Desktop\IMAG0139.jpg - Shortcut (2).lnk
[2012/09/08 10:04:54 | 001,835,008 | —- | C] () – C:\Users\Cherie\Desktop\20120902_111414 - Copy.avi
[2012/09/04 22:47:38 | 001,323,284 | —- | C] () – C:\Users\Cherie\Desktop\brothers.jpg
[2012/09/03 21:22:40 | 000,001,450 | —- | C] () – C:\Users\Cherie\Desktop\sda1 (192.168.1.1) - Shortcut.lnk
[2012/09/02 11:24:55 | 008,911,636 | —- | C] () – C:\Users\Cherie\Desktop\20120902_111500.avi
[2012/09/02 11:14:36 | 001,835,008 | —- | C] () – C:\Users\Cherie\Desktop\20120902_111414.avi
[2012/09/02 10:50:12 | 000,001,024 | —- | C] () – C:\Users\Cherie\Desktop\My Camera (30941163).lnk
[2012/09/02 09:58:16 | 000,001,084 | —- | C] () – C:\Users\Cherie\Desktop\Cisco Connect Cloud.lnk
[2012/08/19 23:14:28 | 001,354,671 | —- | C] () – C:\Users\Cherie\Desktop\Argus_DVR_Manual.pdf
[2012/04/29 10:18:22 | 000,000,084 | —- | C] () – C:\Users\Cherie\AppData\Roaming\programs.vc
[2011/10/22 11:34:00 | 000,001,972 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/05/16 13:31:44 | 000,008,592 | —- | C] () – C:\Windows\SysWow64\ractrlkeyhook.dll
[2011/03/05 22:08:29 | 000,059,232 | —- | C] () – C:\Windows\SysWow64\CNC8100W.DAT
[2011/03/05 16:43:10 | 000,000,546 | —- | C] () – C:\Windows\SysWow64\AB.DAT
[2011/03/05 14:21:59 | 000,744,094 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 22:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 22:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 22:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 22:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/20 22:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 22:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: Hitachi HTS543232L9A300
Partitions: 2
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 298.00GB
Starting Offset: 105906176
Hidden sectors: 0


< End of report >
Avast Scan Results: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-09-18 21:28:32 —————————– 21:28:32.149 OS Version: Windows x64 6.1.7601 Service Pack 1 21:28:32.149 Number of processors: 2 586 0x170A 21:28:32.149 ComputerName: CHERIE-PC UserName: Cherie 21:28:33.725 Initialize success 21:29:29.496 AVAST engine defs: 12091400 21:31:12.596 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 21:31:12.596 Disk 0 Vendor: Hitachi_ FB4O Size: 305245MB BusType: 3 21:31:12.612 Disk 0 MBR read successfully 21:31:12.612 Disk 0 MBR scan 21:31:12.627 Disk 0 Windows 7 default MBR code 21:31:12.643 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 21:31:12.690 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 305143 MB offset 206848 21:31:12.783 Disk 0 scanning C:\Windows\system32\drivers 21:31:26.699 Service scanning 21:32:09.786 Modules scanning 21:32:09.786 Disk 0 trace - called modules: 21:32:09.833 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 21:32:09.833 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005d7b060] 21:32:10.348 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa80042f6040] 21:32:10.348 5 ACPI.sys[fffff88000f9c7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004bf7050] 21:32:11.689 AVAST engine scan C:\Windows 21:32:14.482 AVAST engine scan C:\Windows\system32 21:36:50.104 AVAST engine scan C:\Windows\system32\drivers 21:37:06.156 AVAST engine scan C:\Users\Cherie 21:51:52.207 AVAST engine scan C:\ProgramData 21:54:53.638 Scan finished successfully
I know something's wrong, because I'm still getting redirected to [removed] websites from Google searches. Worst case, I can: 1. create a WinPE bootdisk 2. boot to WinPE 3. copy any family pics/vids/etc… to usb 4. flatten HD 5. reimage 6. move pics back to laptop. 7. change all passwords to everything I have accessed in last 3 months. Not to sound unappreciative, but I'd like to get your opinion on the matter ASAP, as I don't wish to fall prey to any compromised online passwords. Thanks
Yes, you have a Google redirect virus but there is no evidence that your passwords have been compromised and we should be able to sort it out. However, with any malware there is no definite guarantee.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\..\SearchScopes,DefaultScope = {A03A04FA-899E-4B97-B352-A415E31C9567}
    IE - HKCU\..\SearchScopes\{A03A04FA-899E-4B97-B352-A415E31C9567}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
    O4 - HKCU..\Run: [Temporary Internet Files] C:\Users\Cherie\AppData\Local\VirtualStore\Temporary Internet Files\jzjtx.dll (Hewlett-Packard)
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
==============================================

Download and run ComboFix

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It MUST be saved directly to your desktop. Choose save as and then make sure you choose Desktop

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • when finished, it will produce a report for you.
  • please post the C:\ComboFix.txt for further review.
Logs to include in the next post:

OTL fix log
ComboFix.txt


Could you also include Extras.txt which was produced when you ran OTL and would have been saved in the same location.

Thanks

Satchfan
OTL results:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A03A04FA-899E-4B97-B352-A415E31C9567}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A03A04FA-899E-4B97-B352-A415E31C9567}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Temporary Internet Files deleted successfully.
C:\Users\Cherie\AppData\Local\VirtualStore\Temporary Internet Files\jzjtx.dll moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Tools\cmd.bat deleted successfully.
C:\Tools\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Cherie
->Temp folder emptied: 301366640 bytes
->Temporary Internet Files folder emptied: 490014692 bytes
->Java cache emptied: 114866 bytes
->Google Chrome cache emptied: 7171254 bytes
->Flash cache emptied: 1217 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56502 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 301657261 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 164669 bytes

Total Files Cleaned = 1,050.00 mb


OTL by OldTimer - Version 3.2.64.0 log created on 09192012_064203

Files\Folders moved on Reboot…
C:\Users\Cherie\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Cherie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W6B4YPWQ\iframe[1].htm moved successfully.
C:\Users\Cherie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P9PUOFHU\index[3].htm moved successfully.
C:\Users\Cherie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8eF560086FDF.dat moved successfully.
C:\Users\Cherie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
C:\Users\Cherie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\SuggestedSites.dat moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…

Will run ComboFix later this morning.

FYI: When I opened IE to post results, I received a popup saying my default search provider was corrupted and IE was set back to Bing as default search (it was Google).
Sorry for the delay, Combofix broke IE9 and had to run MS Fixit Center to get it back online. Combofix results: ComboFix 12-09-18.07 - Cherie 09/19/2012 13:04:52.1.2 - x64 Microsoft Windows 7 Enterprise 6.1.7601.1.1252.1.1033.18.4031.2763 [GMT -5:00] Running from: c:\tools\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6} SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-08-19 to 2012-09-19 ))))))))))))))))))))))))))))))) . . 2012-09-19 11:42 . 2012-09-19 11:42 ——– d—–w- C:\_OTL 2012-09-19 11:38 . 2012-08-23 08:26 9310152 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{226954E7-142C-4D0B-ACC5-84DFBA858F3D}\mpengine.dll 2012-09-19 04:52 . 2012-08-22 18:12 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-19 04:52 . 2012-08-22 18:12 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-19 04:52 . 2012-08-22 18:12 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-09-19 04:52 . 2012-08-22 18:12 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-19 04:52 . 2012-08-02 17:58 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-09-19 04:52 . 2012-08-02 16:57 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll 2012-09-19 04:52 . 2012-07-04 20:26 41472 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-19 00:53 . 2012-08-23 08:26 9310152 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-09-18 06:25 . 2012-09-18 06:25 ——– d—–w- c:\users\Cherie\AppData\Roaming\SUPERAntiSpyware.com 2012-09-18 06:25 . 2012-09-18 06:25 ——– d—–w- c:\program files\SUPERAntiSpyware 2012-09-18 06:25 . 2012-09-18 06:25 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2012-09-18 03:28 . 2012-09-18 04:00 ——– d—–w- c:\program files (x86)\UVK 2012-09-13 04:09 . 2012-09-13 04:09 ——– d—–w- C:\cherie stuff 2012-09-11 03:23 . 2012-09-11 11:53 ——– d—–w- C:\Jensen Project 2012-09-07 04:04 . 2012-09-07 04:10 ——– d—–w- C:\Landens First Birthday 2012-09-02 21:00 . 2012-09-02 21:01 ——– d—–w- C:\Cisco Router Backups 2012-09-02 16:39 . 2012-09-02 16:39 ——– d—–w- c:\users\Cherie\AppData\Roaming\DivX 2012-09-02 16:32 . 2012-09-02 16:59 ——– d—–w- C:\camera captures 2012-09-02 16:28 . 2012-09-02 16:28 ——– d—–w- c:\program files\DivX 2012-09-02 16:28 . 2012-09-02 16:28 ——– d—–w- c:\program files (x86)\Common Files\DivX Shared 2012-09-02 16:27 . 2012-09-02 16:28 ——– d—–w- c:\program files (x86)\DivX 2012-09-02 16:27 . 2012-09-02 16:28 ——– d—–w- c:\programdata\DivX 2012-09-02 15:57 . 2012-09-02 15:57 ——– d—–w- c:\program files (x86)\NetworkSurveillanceAX 2012-09-02 14:28 . 2012-09-02 14:58 ——– d—–w- c:\programdata\Cisco Systems 2012-08-29 02:43 . 2012-08-29 02:43 ——– d—–w- c:\programdata\Battle.net 2012-08-25 16:04 . 2012-08-25 16:04 ——– d—–w- c:\program files (x86)\Common Files\Skype 2012-08-25 16:04 . 2012-08-25 16:04 ——– d—–r- c:\program files (x86)\Skype . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-19 04:53 . 2011-03-15 03:05 64462936 —-a-w- c:\windows\system32\MRT.exe 2012-09-01 03:05 . 2011-04-18 01:58 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-07-19 13:05 . 2012-04-19 12:04 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-19 13:05 . 2011-05-29 02:04 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-18 18:15 . 2012-08-17 06:04 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-04 22:16 . 2012-08-17 06:04 73216 —-a-w- c:\windows\system32\netapi32.dll 2012-07-04 22:13 . 2012-08-17 06:04 136704 —-a-w- c:\windows\system32\browser.dll 2012-07-04 22:13 . 2012-08-17 06:04 59392 —-a-w- c:\windows\system32\browcli.dll 2012-07-04 21:14 . 2012-08-17 06:04 41984 —-a-w- c:\windows\SysWow64\browcli.dll 2012-06-29 04:55 . 2012-08-17 06:08 17809920 —-a-w- c:\windows\system32\mshtml.dll 2012-06-29 04:09 . 2012-08-17 06:08 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-06-29 03:56 . 2012-08-17 06:08 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-06-29 03:49 . 2012-08-17 06:08 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-06-29 03:49 . 2012-08-17 06:08 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-06-29 03:48 . 2012-08-17 06:08 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-06-29 03:47 . 2012-08-17 06:08 237056 —-a-w- c:\windows\system32\url.dll 2012-06-29 03:45 . 2012-08-17 06:08 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-06-29 03:44 . 2012-08-17 06:08 816640 —-a-w- c:\windows\system32\jscript.dll 2012-06-29 03:43 . 2012-08-17 06:08 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-06-29 03:42 . 2012-08-17 06:08 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-06-29 03:40 . 2012-08-17 06:08 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-06-29 03:39 . 2012-08-17 06:08 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-06-29 03:35 . 2012-08-17 06:08 248320 —-a-w- c:\windows\system32\ieui.dll 2012-06-29 00:16 . 2012-08-17 06:08 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-06-29 00:09 . 2012-08-17 06:08 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-06-29 00:08 . 2012-08-17 06:08 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-06-29 00:04 . 2012-08-17 06:08 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-06-29 00:00 . 2012-08-17 06:08 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Cherie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Cherie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Cherie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Cherie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2012-06-17 694032] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-09-06 5663616] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HControlUser"="c:\program files (x86)\ATK Hotkey\HcontrolUser.exe" [2009-02-13 98304] "CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112] "IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2010-03-03 140640] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2009-09-13 103768] "LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2010-05-20 119152] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "Monitor"="c:\program files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe" [2012-07-05 295304] "iXL_MiddleWare"="c:\program files (x86)\Fisher-Price\iXL\iXL.Middleware.exe" [2011-08-04 56376] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168] R3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [2011-06-14 343856] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536] R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys [2010-05-20 36720] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-21 98688] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-03-05 1255736] S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2009-09-08 87600] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-05-26 138752] S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2010-07-13 69736] S3 MTsensor64;PU ACPI UTILITY;c:\windows\system32\DRIVERS\PuAcpi64.sys [2009-06-05 15880] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-39385524-2566068495-1255450090-1000Core.job - c:\users\Cherie\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-05 20:01] . 2012-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-39385524-2566068495-1255450090-1000UA.job - c:\users\Cherie\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-05 20:01] . 2012-09-18 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 1598bd21-166e-433d-b225-f0df51aa44dd.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52] . 2012-09-18 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 69956a67-ceaa-412e-812b-40b69f78bfb1.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Cherie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Cherie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Cherie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Cherie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 208.67.220.220 208.67.222.222 DPF: {12193C65-F0E1-4DD1-AD4E-DB73C6911014} - file:///D:/activeX/DCP.cab DPF: {721700FE-7F0E-49C5-BDED-CA92B7CB1245} - hxxps://www.mydlink.com/8D/activeX//dcsclictrl.cab DPF: {FB1C9BD4-54A9-4996-9FAA-579DCC4204DF} - hxxps://www.parentwatch.com/centers/video/push-3-01-00.cab . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\ATK Hotkey\ASLDRSrv.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe c:\program files (x86)\ATK Hotkey\Hcontrol.exe c:\program files (x86)\ATK Hotkey\MsgTranAgt.exe c:\program files (x86)\ATK Hotkey\ATKOSD.exe c:\program files (x86)\ATK Hotkey\WDC.exe . ************************************************************************** . Completion time: 2012-09-19 13:15:39 - machine was rebooted ComboFix-quarantined-files.txt 2012-09-19 18:15 . Pre-Run: 113,421,119,488 bytes free Post-Run: 113,020,424,192 bytes free . - - End Of File - - 3E6444268A0C30B91C6A0EE2E3CE2C93
It’s there somewhere, we just have to find it. :)

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

Download RogueKiller to your desktop.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the prescan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects.
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

Thanks

Satchfan
Hi flayofish It has been a couple of days since I replied with instructions to help diagnose your computer problems. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI