This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with Win32/small.CA Virus [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys, Never posted on tech forums for help before so forgive me if im not quite "in the know"! This virus popped up yesterday and my pc has been behaving strangely ever since. Mostly crashing games and random BSODs of a wide variety of sources. I followed the typical windows security scanner and a guide from the avast forums to no avail. Here is my DDS:- . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 20:41:11.04 on 21/10/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.9.2 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8159.4908 [GMT 1:00] . AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\TiltWheelMouse.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe C:\Program Files\Logitech Gaming Software\LCore.exe C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe C:\Windows\vVX3000.exe C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe C:\Program Files (x86)\Steam\Steam.exe C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files (x86)\installshield installation information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe C:\Program Files\Microsoft LifeCam\MSCamS64.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Users\Pedro\AppData\Local\Apps\2.0\GDJ0J0OD.K5O\2G9AQTQ8.Y4B\curs..tion_9e9e83ddf3ed3ead_0005.0001_161f1f0e4761792c\CurseClient.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\SearchIndexer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPNetworkCommunicator.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe C:\Program Files\Logitech Gaming Software\Applets\LCDPop3.exe C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Windows\system32\DllHost.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe C:\Windows\system32\sppsvc.exe C:\games\World of Warcraft\Wow-64.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\SysWOW64\ctfmon.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Pedro\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent uRun: [HP Deskjet 3070 B611 series (NET)] "C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN1BM671PV05MQ:NW" -scfn "HP Deskjet 3070 B611 series (NET)" -AutoStart 1 mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun: [ASUS AiChargerPlus Execute] C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun: [] mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" StartupFolder: C:\Users\Pedro\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe StartupFolder: C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\OFFICE11\REFIEBAR.DLL DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/select/asusTek_sys_ctrl3.cab DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab BHO-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll TB-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll mRun-x64: [MouseDriver] TiltWheelMouse.exe mRun-x64: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized mRun-x64: [VX3000] C:\Windows\vVX3000.exe mRun-x64: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s . ============= SERVICES / DRIVERS =============== . R0 AiChargerPlus;ASUS Charger Plus Driver;C:\Windows\System32\drivers\AiChargerPlus.sys [2012-1-6 14464] R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-1-6 969200] R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-1-6 359464] R1 JSWPSLWF;JumpStart Wireless Filter Driver;C:\Windows\System32\drivers\jswpslwfx.sys [2008-10-1 26624] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960] R2 asComSvc;ASUS Com Service;C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [2011-6-13 922240] R2 asHmComSvc;ASUS HM Com Service;C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-2 915584] R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2012-1-6 586880] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-1-6 25232] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-1-6 71600] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-8-25 44808] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-1-6 13592] R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2012-1-6 2253120] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-6-2 128488] R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-6-2 401896] R3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);C:\Windows\System32\drivers\ICCWDT.sys [2011-6-29 26136] R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\System32\drivers\LGBusEnum.sys [2009-11-23 22408] R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\System32\drivers\LGVirHid.sys [2009-11-23 16008] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2012-1-7 174184] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-10-21 646248] R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;C:\Windows\System32\drivers\WN111v2w7x.sys [2010-4-27 783360] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-1 136176] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-3 250808] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-1 136176] S3 jswpsapi;Jumpstart Wifi Protected Setup;C:\Program Files (x86)\NETGEAR\WN111v2\jswpsapi.exe [2008-2-29 942080] S3 PCAMp50a64;PCAMp50a64 NDIS Protocol Driver;C:\Windows\System32\drivers\PCAMp50a64.sys [2012-1-6 43328] S3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;C:\Windows\System32\drivers\PCASp50a64.sys [2012-1-6 41280] S3 t_mouse.sys;iBall Advanced Mouse;C:\Windows\System32\drivers\t_mouse.sys [2009-4-16 25088] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-1-7 59392] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-1-7 1255736] S3 whfltr2k;WheelMouse USB Lower Filter Driver;C:\Windows\System32\drivers\whfltr2k.sys [2012-2-29 10368] . =============== Created Last 30 ================ . 2012-10-21 19:29:36 5067584 —-a-w- C:\Windows\System32\nvsvc64.dll 2012-10-21 19:29:36 3536817 —-a-w- C:\Windows\System32\nvcoproc.bin 2012-10-21 19:29:36 3074368 —-a-w- C:\Windows\System32\nvsvcr.dll 2012-10-21 19:29:36 222528 —-a-w- C:\Windows\System32\nvmctray.dll 2012-10-21 19:29:36 1640768 —-a-w- C:\Windows\System32\nvvsvc.exe 2012-10-21 19:29:36 137536 —-a-w- C:\Windows\System32\nvshext.dll 2012-10-21 19:29:36 10406208 —-a-w- C:\Windows\System32\nvcpl.dll 2012-10-21 19:29:07 ——– d—–w- C:\PROGRA~3\NVIDIA Corporation 2012-10-21 17:33:45 ——– d—–w- C:\Program Files (x86)\ESET 2012-10-21 17:20:01 ——– d—–w- C:\$RECYCLE.BIN 2012-10-21 17:10:42 98816 —-a-w- C:\Windows\sed.exe 2012-10-21 17:10:42 518144 —-a-w- C:\Windows\SWREG.exe 2012-10-21 17:10:42 256000 —-a-w- C:\Windows\PEV.exe 2012-10-21 17:10:42 208896 —-a-w- C:\Windows\MBR.exe 2012-10-21 17:10:40 ——– d—–w- C:\ComboFix 2012-10-21 15:35:48 ——– d—–w- C:\Users\Pedro\AppData\Roaming\SpeedyPC Software 2012-10-21 15:35:48 ——– d—–w- C:\Users\Pedro\AppData\Roaming\DriverCure 2012-10-21 15:35:40 ——– d—–w- C:\PROGRA~3\SpeedyPC Software 2012-10-21 15:10:59 2684416 —-a-w- C:\Windows\System32\RCoRes64.dat 2012-10-21 15:09:55 200836 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll 2012-10-21 15:09:53 331908 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll 2012-10-21 14:14:31 ——– d—–w- C:\Users\Pedro\AppData\Roaming\Malwarebytes 2012-10-21 14:14:22 ——– d—–w- C:\PROGRA~3\Malwarebytes 2012-10-21 14:14:21 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys 2012-10-21 14:14:21 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-10-21 14:07:16 74272 —-a-w- C:\Windows\System32\RtNicProp64.dll 2012-10-21 14:07:15 646248 —-a-w- C:\Windows\System32\drivers\Rt64win7.sys 2012-10-21 13:48:13 ——– d—–w- C:\Users\Pedro\AppData\Roaming\Easeware 2012-10-21 13:48:11 ——– d—–w- C:\Program Files\Easeware 2012-10-21 13:45:22 ——– d—–w- C:\Program Files (x86)\NirSoft 2012-10-21 08:21:05 ——– d—–w- C:\Users\Pedro\AppData\Local\{C723298B-C832-4322-A0A9-B1B137DD5E9E} 2012-10-21 00:51:18 ——– d—–w- C:\Users\Pedro\AppData\Local\{DC06EB75-136B-48F3-95F6-69C498244252} 2012-10-20 10:03:54 ——– d—–w- C:\Users\Pedro\AppData\Local\{71BE2444-4D4A-48D5-BEFC-F11D02D72FAD} 2012-10-19 20:04:20 95208 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2012-10-19 20:01:50 9291768 ——w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{9012B983-3C89-4A80-AEB5-7670BD7DD9B4}\mpengine.dll 2012-10-19 19:55:41 ——– d—–w- C:\Users\Pedro\AppData\Local\{57F27946-4123-4B4E-9071-2FCD1BFEF37D} 2012-10-18 16:35:29 ——– d—–w- C:\Users\Pedro\AppData\Local\{949D0C71-6733-4F3C-BD5D-E5531F65F192} 2012-10-17 16:29:57 ——– d—–w- C:\Users\Pedro\AppData\Local\{A3128FC5-33E2-47F7-90D5-02DEF9CEED23} 2012-10-16 16:50:50 ——– d—–w- C:\Users\Pedro\AppData\Local\{F2AA42CC-5E17-4BAE-A4C9-BAB960781A08} 2012-10-15 16:06:44 ——– d—–w- C:\Users\Pedro\AppData\Local\{4EBD83E7-B177-4629-95A1-8B7C54A4E96D} 2012-10-14 08:05:54 ——– d—–w- C:\Users\Pedro\AppData\Local\{F5EC3258-AC06-419A-8B50-94DC773FA3A8} 2012-10-13 22:09:11 ——– d—–w- C:\Users\Pedro\AppData\Local\{46455992-6FA2-4FE2-8B55-9F5264F8B5CB} 2012-10-13 06:00:46 ——– d—–w- C:\Users\Pedro\AppData\Local\{CA6482DA-C4F4-44F0-9634-2A85C81B2B7B} 2012-10-12 15:35:06 ——– d—–w- C:\Users\Pedro\AppData\Local\{91F434EE-6B89-4A8C-B9F5-770305E4B9A4} 2012-10-11 16:10:56 ——– d—–w- C:\Users\Pedro\AppData\Local\{7B87ECC9-3664-4600-A593-57F533A534BB} 2012-10-10 20:23:48 247144 —-a-w- C:\Windows\System32\nvinitx.dll 2012-10-10 20:23:40 1482600 —-a-w- C:\Windows\System32\nvdispgenco64.dll 2012-10-10 20:23:38 6127464 —-a-w- C:\Windows\SysWow64\nvopencl.dll 2012-10-10 20:23:26 831848 —-a-w- C:\Windows\SysWow64\nvumdshim.dll 2012-10-10 20:23:26 202600 —-a-w- C:\Windows\SysWow64\nvinit.dll 2012-10-10 20:23:24 7414632 —-a-w- C:\Windows\System32\nvopencl.dll 2012-10-10 20:23:20 973672 —-a-w- C:\Windows\System32\nvumdshimx.dll 2012-10-10 20:22:52 1533248 —-a-w- C:\Windows\System32\nvdispco64.dll 2012-10-10 16:58:59 4096 —ha-w- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll 2012-10-10 16:49:58 ——– d—–w- C:\Users\Pedro\AppData\Local\{0F1BAA30-53E5-410B-956A-1B35DDA11F37} 2012-10-09 15:12:47 ——– d—–w- C:\Users\Pedro\AppData\Local\{BBCE5110-A2A0-4E9A-B1BE-CF01A8B4EB81} 2012-10-08 18:14:21 ——– d—–w- C:\Users\Pedro\AppData\Local\{DBBAF798-A4F9-4153-AB40-061B333817DC} 2012-10-07 08:14:33 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2012-10-07 08:13:59 ——– d—–w- C:\Program Files\iPod 2012-10-07 08:13:58 ——– d—–w- C:\Program Files\iTunes 2012-10-07 08:13:58 ——– d—–w- C:\Program Files (x86)\iTunes 2012-10-07 08:13:58 ——– d—–w- C:\PROGRA~3\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-10-06 22:11:27 ——– d—–w- C:\Users\Pedro\AppData\Local\{182E9932-090B-4744-BFB6-805D16F10C9B} 2012-10-06 07:33:45 ——– d—–w- C:\Users\Pedro\AppData\Local\{9E90B9F5-6905-49E6-945B-1EE6E169995C} 2012-10-05 17:49:59 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe 2012-10-05 17:37:31 ——– d—–w- C:\Users\Pedro\AppData\Local\{59F99C3E-404D-4B1D-8F9E-1A5ADD091A99} . ==================== Find3M ==================== . 2012-10-20 17:26:16 4088576 —-a-w- C:\Windows\PE_Rom.dll 2012-10-08 20:02:47 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-10-08 20:02:47 696760 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-09-14 19:19:29 2048 —-a-w- C:\Windows\System32\tzres.dll 2012-09-14 18:28:53 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2012-09-01 23:14:51 916456 —-a-w- C:\Windows\System32\deployJava1.dll 2012-09-01 23:14:51 108008 —-a-w- C:\Windows\System32\WindowsAccessBridge-64.dll 2012-09-01 23:14:51 1034216 —-a-w- C:\Windows\System32\npdeployJava1.dll 2012-09-01 23:14:06 821736 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll 2012-09-01 23:14:06 746984 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2012-08-31 18:19:35 1659760 —-a-w- C:\Windows\System32\drivers\ntfs.sys 2012-08-30 18:03:45 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe 2012-08-30 17:12:02 3968880 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2012-08-30 17:12:02 3914096 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2012-08-24 18:05:07 220160 —-a-w- C:\Windows\System32\wintrust.dll 2012-08-24 16:57:48 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll 2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll 2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll 2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-08-22 18:12:50 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2012-08-22 18:12:40 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys 2012-08-22 18:12:40 376688 —-a-w- C:\Windows\System32\drivers\netio.sys 2012-08-22 18:12:33 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2012-08-21 12:01:20 125872 —-a-w- C:\Windows\System32\GEARAspi64.dll 2012-08-21 12:01:20 106928 —-a-w- C:\Windows\SysWow64\GEARAspi.dll 2012-08-21 09:13:13 969200 —-a-w- C:\Windows\System32\drivers\aswSnx.sys 2012-08-21 09:13:12 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2012-08-21 09:13:12 54072 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys 2012-08-21 09:12:33 41224 —-a-w- C:\Windows\avastSS.scr 2012-08-20 18:48:44 362496 —-a-w- C:\Windows\System32\wow64win.dll 2012-08-20 18:48:44 243200 —-a-w- C:\Windows\System32\wow64.dll 2012-08-20 18:48:44 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2012-08-20 18:48:43 215040 —-a-w- C:\Windows\System32\winsrv.dll 2012-08-20 18:48:37 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2012-08-20 18:48:35 424448 —-a-w- C:\Windows\System32\KernelBase.dll 2012-08-20 18:46:22 338432 —-a-w- C:\Windows\System32\conhost.exe 2012-08-20 17:40:21 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2012-08-20 17:38:44 44032 —-a-w- C:\Windows\apppatch\acwow64.dll 2012-08-20 17:38:26 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2012-08-20 17:37:19 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2012-08-20 17:37:18 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2012-08-20 15:38:21 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2012-08-20 15:38:20 2048 —-a-w- C:\Windows\SysWow64\user.exe 2012-08-20 15:33:28 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2012-08-20 15:33:28 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2012-08-20 15:33:28 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2012-08-20 15:33:28 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2012-08-12 10:18:37 4154112 —-a-w- C:\Windows\PE_File.dll 2012-08-11 00:56:03 715776 —-a-w- C:\Windows\System32\kerberos.dll 2012-08-10 23:56:14 542208 —-a-w- C:\Windows\SysWow64\kerberos.dll 2012-08-02 17:58:52 574464 —-a-w- C:\Windows\System32\d3d10level9.dll 2012-08-02 16:57:20 490496 —-a-w- C:\Windows\SysWow64\d3d10level9.dll . ============= FINISH: 20:41:21.03 =============== Worth noting that i also have a log file from aswMBR which was part of the guide i previously ran if that is of use.
Hello Pedro_202,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
Hi Pedro_202,

You log indicates that you have ComboFix on your computer. You should not be using Combofix unless instructed to do so by a Malware Removal Expert. It is a powerful tool intended by its creator to be "used under the guidance and supervision of an expert", NOT for private use. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again. Please read Combofix's Disclaimer.

With that being said, if you did run ComboFix previously it would have produced a log. Please locate the log and post it in your next reply. (it should be located -> C:\ComboFix.txt)

Next

You also stated you have run aswMBR. Locate the log and post it also in your next reply.

Next

  • Download OTL to your desktop.
  • Right click and select "Run as Administrator". Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
In your next post please provide the following:
  • ComboFix log (if you have it)
  • aswMBR log
  • OTL.txt
  • Extras.txt
Good evening OCD, thanks for your continued help. I ran combofix following a guide to remove the virus before i came across this site so it was a blind blunder i suppose. No damage done as of yet tho.

Here is my OTL log:-

OTL logfile created on: 23/10/2012 20:28:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pedro\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.97 Gb Total Physical Memory | 5.81 Gb Available Physical Memory | 72.95% Memory free
15.93 Gb Paging File | 13.48 Gb Available in Paging File | 84.61% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 709.18 Gb Free Space | 76.14% Space Free | Partition Type: NTFS

Computer Name: PEDRO-PC | User Name: Pedro | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Pedro\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe ()
PRC - C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\installshield installation information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe ()
PRC - C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe (ASUSTeK Computer Inc.)
PRC - C:\Windows\vVX3000.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ce7268841a00e097fc0b70869f10e780\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\d27d5cced1b7d812f60e71d4e509661d\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\HookKey32.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Sensor\Sensor.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\BarGadget\BarGadget.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Sensor Graph\SensorGraph.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\MyLogo\MyLogo.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Update\Update.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\AssistFunc.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\AI Charger+\AIChargerPlus.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Settings\Settings.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Probe_II\ProbeII.dll ()
MOD - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMLib.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\TabGadget\TabGadget.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Splitter\Splitter.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\ImageHelper.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ImageHelper.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\pngio.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (asComSvc) – C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe ()
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (asHmComSvc) – C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe ()
SRV - (AsSysCtrlService) – C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (jswpsapi) – C:\Program Files (x86)\NETGEAR\WN111v2\jswpsapi.exe (Atheros Communications, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (ICCWDT) – C:\Windows\SysNative\drivers\ICCWDT.sys (Intel Corporation)
DRV:64bit: - (asmtxhci) – C:\Windows\SysNative\drivers\asmtxhci.sys (ASMedia Technology Inc)
DRV:64bit: - (asmthub3) – C:\Windows\SysNative\drivers\asmthub3.sys (ASMedia Technology Inc)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (AiChargerPlus) – C:\Windows\SysNative\drivers\AiChargerPlus.sys (ASUSTek Computer Inc.)
DRV:64bit: - (VX3000) – C:\Windows\SysNative\drivers\VX3000.sys (Microsoft Corporation)
DRV:64bit: - (WN111v2) – C:\Windows\SysNative\drivers\WN111v2w7x.sys (Atheros Communications, Inc.)
DRV:64bit: - (LGVirHid) – C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.)
DRV:64bit: - (LGBusEnum) – C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.)
DRV:64bit: - (whfltr2k) – C:\Windows\SysNative\drivers\whfltr2k.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (t_mouse.sys) – C:\Windows\SysNative\drivers\t_mouse.sys ()
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (JSWPSLWF) – C:\Windows\SysNative\drivers\jswpslwfx.sys (Atheros Communications, Inc.)
DRV:64bit: - (PCAMp50a64) – C:\Windows\SysNative\drivers\PCAMp50a64.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV:64bit: - (PCASp50a64) – C:\Windows\SysNative\drivers\PCASp50a64.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 58 99 4A 17 B2 AF CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2012/03/12 19:23:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions
[2012/03/12 19:23:03 | 000,000,000 | —D | M] (uTorrentControl2 Community Toolbar) – C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U5 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: avast! WebRep = C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\
CHR - Extension: Gmail = C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/10/21 18:19:59 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [MouseDriver] C:\Windows\SysNative\TiltWheelMouse.exe (Pixart Imaging Inc)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ASUS AiChargerPlus Execute] C:\Program Files (x86)\installshield installation information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LifeCam] C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKCU..\Run: [HP Deskjet 3070 B611 series (NET)] C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A36077EE-57D5-41FC-A8F5-10B6E9412302}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/23 20:23:34 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Pedro\Desktop\OTL.exe
[2012/10/21 20:31:35 | 000,837,952 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\easyupdatusapiu64.dll
[2012/10/21 20:31:02 | 024,742,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/10/21 20:31:02 | 018,871,616 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/10/21 20:31:02 | 008,791,360 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2012/10/21 20:31:02 | 007,041,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/10/21 20:31:02 | 001,454,400 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/10/21 20:31:02 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2012/10/21 20:31:02 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2012/10/21 20:31:01 | 024,796,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/10/21 20:31:01 | 017,248,576 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/10/21 20:31:01 | 015,693,120 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/10/21 20:31:01 | 013,205,312 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/10/21 20:31:01 | 007,581,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/10/21 20:31:01 | 005,578,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/10/21 20:31:01 | 002,808,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2012/10/21 20:31:01 | 002,542,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/10/21 20:31:01 | 002,458,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/10/21 20:31:01 | 002,401,088 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/10/21 20:31:01 | 002,232,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/10/21 20:31:01 | 002,099,520 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/10/21 20:29:36 | 010,406,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2012/10/21 20:29:36 | 005,067,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2012/10/21 20:29:36 | 003,074,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2012/10/21 20:29:36 | 000,222,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2012/10/21 20:29:36 | 000,137,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2012/10/21 20:29:07 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2012/10/21 18:33:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/10/21 18:20:01 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/10/21 18:17:18 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/10/21 18:10:42 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/10/21 18:10:42 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/10/21 18:10:42 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/10/21 18:10:40 | 000,000,000 | —D | C] – C:\ComboFix
[2012/10/21 18:10:27 | 000,000,000 | —D | C] – C:\Qoobox
[2012/10/21 18:10:16 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/10/21 18:09:12 | 004,986,495 | R— | C] (Swearware) – C:\Users\Pedro\Desktop\ComboFix.exe
[2012/10/21 16:48:01 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Pedro\Desktop\aswMBR.exe
[2012/10/21 16:35:48 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Roaming\SpeedyPC Software
[2012/10/21 16:35:48 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Roaming\DriverCure
[2012/10/21 16:35:40 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/10/21 16:11:49 | 000,000,000 | —D | C] – C:\Windows\SysWow64\RTCOM
[2012/10/21 16:11:13 | 002,604,376 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\WavesGUILib.dll
[2012/10/21 16:11:12 | 001,361,336 | —- | C] (TOSHIBA Corporation) – C:\Windows\SysNative\tosade.dll
[2012/10/21 16:11:12 | 000,177,088 | —- | C] (TOSHIBA Corporation) – C:\Windows\SysNative\tadefxapo264.dll
[2012/10/21 16:11:12 | 000,065,432 | —- | C] (TOSHIBA CORPORATION.) – C:\Windows\SysNative\tepeqapo64.dll
[2012/10/21 16:11:11 | 000,518,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSX64.dll
[2012/10/21 16:11:11 | 000,211,184 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSH64.dll
[2012/10/21 16:11:11 | 000,155,888 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSWOW64.dll
[2012/10/21 16:11:11 | 000,148,416 | —- | C] (TOSHIBA Corporation) – C:\Windows\SysNative\tadefxapo.dll
[2012/10/21 16:11:10 | 000,198,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSHP64.dll
[2012/10/21 16:11:07 | 000,219,752 | —- | C] (Sony Corporation) – C:\Windows\SysNative\SFSS_APO.dll
[2012/10/21 16:11:06 | 000,221,024 | —- | C] (Synopsys, Inc.) – C:\Windows\SysNative\SFNHK64.dll
[2012/10/21 16:11:06 | 000,081,248 | —- | C] (Synopsys, Inc.) – C:\Windows\SysNative\SFCOM64.dll
[2012/10/21 16:11:06 | 000,078,688 | —- | C] (Synopsys, Inc.) – C:\Windows\SysNative\SFAPO64.dll
[2012/10/21 16:11:06 | 000,074,064 | —- | C] (Virage Logic Corporation / Sonic Focus) – C:\Windows\SysWow64\SFCOM.dll
[2012/10/21 16:11:05 | 002,615,400 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtPgEx64.dll
[2012/10/21 16:11:05 | 001,560,168 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTSnMg64.cpl
[2012/10/21 16:11:04 | 000,331,880 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtlCPAPI64.dll
[2012/10/21 16:11:02 | 000,014,952 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCoLDR64.dll
[2012/10/21 16:11:01 | 003,744,872 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkAPO64.dll
[2012/10/21 16:11:01 | 001,969,768 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkApi64.dll
[2012/10/21 16:11:01 | 000,375,128 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEP64A.dll
[2012/10/21 16:11:01 | 000,204,120 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEED64A.dll
[2012/10/21 16:11:01 | 000,149,608 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCfg64.dll
[2012/10/21 16:11:01 | 000,101,208 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEL64A.dll
[2012/10/21 16:11:01 | 000,078,680 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEG64A.dll
[2012/10/21 16:11:00 | 001,247,848 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTCOM64.dll
[2012/10/21 16:11:00 | 000,310,104 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DHT64.dll
[2012/10/21 16:11:00 | 000,310,104 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DAA64.dll
[2012/10/21 16:10:59 | 002,684,416 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoRes64.dat
[2012/10/21 16:10:59 | 000,100,456 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoInstII64.dll
[2012/10/21 16:10:58 | 003,308,376 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEP64A.dll
[2012/10/21 16:10:58 | 000,426,328 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EED64A.dll
[2012/10/21 16:10:58 | 000,136,024 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEL64A.dll
[2012/10/21 16:10:58 | 000,118,104 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEA64A.dll
[2012/10/21 16:10:58 | 000,074,072 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEG64A.dll
[2012/10/21 16:10:57 | 000,334,680 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2012/10/21 16:10:56 | 003,768,152 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioRealtek.dll
[2012/10/21 16:10:56 | 000,702,808 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioRealtek2.dll
[2012/10/21 16:10:55 | 002,132,824 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioEQ.dll
[2012/10/21 16:10:55 | 000,341,336 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO30.dll
[2012/10/21 16:10:55 | 000,318,808 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO20.dll
[2012/10/21 16:10:53 | 000,603,984 | —- | C] (Knowles Acoustics ) – C:\Windows\SysNative\KAAPORT64.dll
[2012/10/21 16:10:43 | 002,085,440 | —- | C] (Fortemedia Corporation) – C:\Windows\SysNative\FMAPO64.dll
[2012/10/21 16:10:43 | 000,693,352 | —- | C] (DTS) – C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2012/10/21 16:10:43 | 000,439,808 | —- | C] (DTS) – C:\Windows\SysNative\DTSU2PREC64.dll
[2012/10/21 16:10:42 | 000,527,872 | —- | C] (DTS) – C:\Windows\SysNative\DTSU2PLFX64.dll
[2012/10/21 16:10:42 | 000,515,584 | —- | C] (DTS) – C:\Windows\SysNative\DTSU2PGFX64.dll
[2012/10/21 16:10:41 | 001,756,264 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2012/10/21 16:10:41 | 001,568,360 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2012/10/21 16:10:41 | 000,712,296 | —- | C] (DTS) – C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2012/10/21 16:10:40 | 000,491,112 | —- | C] (DTS) – C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2012/10/21 16:10:39 | 000,432,744 | —- | C] (DTS) – C:\Windows\SysNative\DTSLimiterDLL64.dll
[2012/10/21 16:10:39 | 000,242,792 | —- | C] (DTS) – C:\Windows\SysNative\DTSLFXAPO64.dll
[2012/10/21 16:10:39 | 000,241,768 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPONS64.dll
[2012/10/21 16:10:38 | 000,428,648 | —- | C] (DTS) – C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2012/10/21 16:10:38 | 000,242,792 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPO64.dll
[2012/10/21 16:10:37 | 001,486,952 | —- | C] (DTS) – C:\Windows\SysNative\DTSBoostDLL64.dll
[2012/10/21 16:10:37 | 000,728,680 | —- | C] (DTS) – C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2012/10/21 16:10:33 | 000,200,800 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAC64.dll
[2012/10/21 16:10:33 | 000,108,960 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAR64.dll
[2012/10/21 15:14:31 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Roaming\Malwarebytes
[2012/10/21 15:14:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/21 15:14:22 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/10/21 15:14:21 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/10/21 15:14:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/10/21 15:13:45 | 010,669,952 | —- | C] (Malwarebytes Corporation ) – C:\Users\Pedro\Desktop\malwarebytes.exe
[2012/10/21 15:07:15 | 000,646,248 | —- | C] (Realtek ) – C:\Windows\SysNative\drivers\Rt64win7.sys
[2012/10/21 14:48:13 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Roaming\Easeware
[2012/10/21 14:48:11 | 000,000,000 | —D | C] – C:\Program Files\Easeware
[2012/10/21 14:48:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverEasy
[2012/10/21 14:45:22 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
[2012/10/21 14:45:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\NirSoft
[2012/10/21 09:21:05 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{C723298B-C832-4322-A0A9-B1B137DD5E9E}
[2012/10/21 01:51:18 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{DC06EB75-136B-48F3-95F6-69C498244252}
[2012/10/20 11:03:54 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{71BE2444-4D4A-48D5-BEFC-F11D02D72FAD}
[2012/10/19 21:04:20 | 000,174,056 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/10/19 21:04:20 | 000,174,056 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2012/10/19 21:04:20 | 000,095,208 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012/10/19 20:55:41 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{57F27946-4123-4B4E-9071-2FCD1BFEF37D}
[2012/10/18 17:35:29 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{949D0C71-6733-4F3C-BD5D-E5531F65F192}
[2012/10/17 17:29:57 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{A3128FC5-33E2-47F7-90D5-02DEF9CEED23}
[2012/10/16 17:50:50 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{F2AA42CC-5E17-4BAE-A4C9-BAB960781A08}
[2012/10/15 23:25:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2012/10/15 22:36:00 | 227,947,968 | —- | C] (NVIDIA Corporation) – C:\Users\Pedro\Desktop\306.97-desktop-win8-win7-winvista-64bit-international-whql.exe
[2012/10/15 17:06:44 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{4EBD83E7-B177-4629-95A1-8B7C54A4E96D}
[2012/10/14 09:05:54 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{F5EC3258-AC06-419A-8B50-94DC773FA3A8}
[2012/10/13 23:09:11 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{46455992-6FA2-4FE2-8B55-9F5264F8B5CB}
[2012/10/13 07:00:46 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{CA6482DA-C4F4-44F0-9634-2A85C81B2B7B}
[2012/10/12 16:35:06 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{91F434EE-6B89-4A8C-B9F5-770305E4B9A4}
[2012/10/11 17:10:56 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{7B87ECC9-3664-4600-A593-57F533A534BB}
[2012/10/10 21:23:48 | 000,247,144 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvinitx.dll
[2012/10/10 21:23:40 | 001,482,600 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispgenco64.dll
[2012/10/10 21:23:38 | 006,127,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvopencl.dll
[2012/10/10 21:23:26 | 000,831,848 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvumdshim.dll
[2012/10/10 21:23:26 | 000,202,600 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvinit.dll
[2012/10/10 21:23:24 | 007,414,632 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvopencl.dll
[2012/10/10 21:23:20 | 000,973,672 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvumdshimx.dll
[2012/10/10 21:22:52 | 001,533,248 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/10/10 17:59:37 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/10/10 17:59:36 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/10/10 17:59:36 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/10/10 17:59:18 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/10/10 17:59:18 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012/10/10 17:59:18 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012/10/10 17:59:18 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012/10/10 17:59:16 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012/10/10 17:59:16 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012/10/10 17:59:16 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012/10/10 17:59:16 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012/10/10 17:59:15 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012/10/10 17:59:15 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012/10/10 17:59:15 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012/10/10 17:59:15 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/10 17:59:15 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/10 17:59:15 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/10 17:59:15 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/10 17:59:15 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/10 17:59:15 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/10/10 17:59:15 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/10/10 17:59:15 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/10/10 17:59:15 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/10 17:59:15 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/10/10 17:59:15 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/10 17:59:14 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012/10/10 17:59:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/10 17:59:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/10/10 17:59:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/10/10 17:59:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/10 17:59:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/10 17:59:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/10 17:59:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/10/10 17:59:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/10/10 17:59:12 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/10/10 17:59:12 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/10/10 17:59:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/10/10 17:59:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/10 17:59:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/10/10 17:59:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/10/10 17:59:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/10 17:59:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/10 17:59:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/10 17:59:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/10 17:59:10 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/10/10 17:59:10 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/10 17:59:10 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/10 17:59:10 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/10/10 17:59:10 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/10/10 17:59:10 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/10 17:59:10 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/10 17:59:01 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/10 17:59:01 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/10/10 17:59:00 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/10/10 17:59:00 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/10 17:58:59 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/10/10 17:58:58 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/10/10 17:58:58 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/10/10 17:58:58 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/10/10 17:58:54 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012/10/10 17:58:37 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012/10/10 17:58:15 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/10/10 17:58:14 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/10/10 17:49:58 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{0F1BAA30-53E5-410B-956A-1B35DDA11F37}
[2012/10/09 16:12:47 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{BBCE5110-A2A0-4E9A-B1BE-CF01A8B4EB81}
[2012/10/08 19:14:21 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{DBBAF798-A4F9-4153-AB40-061B333817DC}
[2012/10/07 09:16:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2012/10/07 09:14:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/10/07 09:14:33 | 000,033,240 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2012/10/07 09:13:59 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/10/07 09:13:58 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/10/07 09:13:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/10/07 09:13:58 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012/10/06 23:11:27 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{182E9932-090B-4744-BFB6-805D16F10C9B}
[2012/10/06 08:33:45 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{9E90B9F5-6905-49E6-945B-1EE6E169995C}
[2012/10/06 03:00:31 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/10/06 03:00:30 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/10/06 03:00:30 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/10/06 03:00:30 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/10/06 03:00:30 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/10/06 03:00:30 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/10/06 03:00:30 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/10/06 03:00:30 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/10/06 03:00:29 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/10/06 03:00:29 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/10/06 03:00:28 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/10/06 03:00:28 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/10/06 03:00:27 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/10/06 03:00:27 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/10/06 03:00:27 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/10/05 18:49:59 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2012/10/05 18:37:31 | 000,000,000 | —D | C] – C:\Users\Pedro\AppData\Local\{59F99C3E-404D-4B1D-8F9E-1A5ADD091A99}
[2012/04/17 19:08:35 | 074,672,991 | —- | C] (Igor Pavlov) – C:\Users\Pedro\Office2003Lite-SFX.exe

========== Files - Modified Within 30 Days ==========

[2012/10/23 20:27:49 | 000,014,752 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/23 20:27:49 | 000,014,752 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/23 20:26:23 | 000,779,266 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/23 20:26:23 | 000,664,532 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/10/23 20:26:23 | 000,125,268 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/10/23 20:23:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Pedro\Desktop\OTL.exe
[2012/10/23 20:20:54 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/23 20:20:03 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/10/23 20:19:51 | 2121,629,695 | -HS- | M] () – C:\hiberfil.sys
[2012/10/23 08:11:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/23 08:01:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/21 20:37:23 | 000,625,664 | —- | M] () – C:\Users\Pedro\Desktop\dds.scr
[2012/10/21 20:11:59 | 797,426,485 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/10/21 18:19:59 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/10/21 18:09:46 | 004,986,495 | R— | M] (Swearware) – C:\Users\Pedro\Desktop\ComboFix.exe
[2012/10/21 18:03:43 | 000,000,512 | —- | M] () – C:\Users\Pedro\Desktop\MBR.dat
[2012/10/21 16:48:20 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Pedro\Desktop\aswMBR.exe
[2012/10/21 15:52:12 | 000,001,769 | —- | M] () – C:\Windows\Language_trs.ini
[2012/10/21 15:14:22 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/21 15:13:54 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Users\Pedro\Desktop\malwarebytes.exe
[2012/10/21 14:48:11 | 000,000,967 | —- | M] () – C:\Users\Public\Desktop\DriverEasy.lnk
[2012/10/20 18:26:16 | 004,088,576 | —- | M] () – C:\Windows\PE_Rom.dll
[2012/10/19 21:34:48 | 000,010,369 | —- | M] () – C:\Windows\MB.idx
[2012/10/19 21:34:15 | 000,000,551 | —- | M] () – C:\Windows\Path.idx
[2012/10/15 22:46:44 | 227,947,968 | —- | M] (NVIDIA Corporation) – C:\Users\Pedro\Desktop\306.97-desktop-win8-win7-winvista-64bit-international-whql.exe
[2012/10/10 21:23:48 | 000,247,144 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvinitx.dll
[2012/10/10 21:23:40 | 001,482,600 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispgenco64.dll
[2012/10/10 21:23:38 | 006,127,464 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvopencl.dll
[2012/10/10 21:23:26 | 000,831,848 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvumdshim.dll
[2012/10/10 21:23:26 | 000,202,600 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvinit.dll
[2012/10/10 21:23:24 | 007,414,632 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvopencl.dll
[2012/10/10 21:23:20 | 000,973,672 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvumdshimx.dll
[2012/10/08 21:02:47 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/10/08 21:02:47 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/10/07 22:11:53 | 011,888,726 | —- | M] () – C:\Users\Pedro\Desktop\Zygor.rar
[2012/10/02 20:51:15 | 003,536,817 | —- | M] () – C:\Windows\SysNative\nvcoproc.bin
[2012/09/29 19:54:26 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/09/24 23:16:33 | 000,095,208 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012/09/24 23:08:27 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/09/24 23:07:57 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe

========== Files Created - No Company Name ==========

[2012/10/21 20:37:21 | 000,625,664 | —- | C] () – C:\Users\Pedro\Desktop\dds.scr
[2012/10/21 20:29:36 | 003,536,817 | —- | C] () – C:\Windows\SysNative\nvcoproc.bin
[2012/10/21 18:10:42 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/10/21 18:10:42 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/10/21 18:10:42 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/10/21 18:10:42 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/10/21 18:10:42 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/10/21 18:03:43 | 000,000,512 | —- | C] () – C:\Users\Pedro\Desktop\MBR.dat
[2012/10/21 16:11:00 | 000,200,468 | —- | C] () – C:\Windows\SysNative\drivers\RTAIODAT.DAT
[2012/10/21 15:14:22 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/21 15:07:16 | 000,074,272 | —- | C] () – C:\Windows\SysNative\RtNicProp64.dll
[2012/10/21 14:48:11 | 000,000,967 | —- | C] () – C:\Users\Public\Desktop\DriverEasy.lnk
[2012/10/10 21:22:44 | 000,007,384 | —- | C] () – C:\Windows\SysNative\nvinfo.pb
[2012/10/07 22:11:01 | 011,888,726 | —- | C] () – C:\Users\Pedro\Desktop\Zygor.rar
[2012/09/02 20:55:14 | 001,795,471 | —- | C] () – C:\Users\Pedro\electoral roll letter.jpg
[2012/08/19 14:38:48 | 000,056,934 | —- | C] () – C:\Users\Pedro\Credit_Card_Agreementsoph.pdf
[2012/07/28 22:20:05 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2012/07/19 20:51:45 | 087,436,896 | —- | C] () – C:\Users\Pedro\Bejeweled3Setup-en.exe
[2012/07/12 19:21:29 | 062,591,656 | —- | C] () – C:\Users\Pedro\BejeweledBlitzSetup_FB_EN.exe
[2012/05/21 23:14:20 | 000,296,011 | —- | C] () – C:\Users\Pedro\quantum_space_617.jpg
[2012/05/19 07:57:34 | 000,708,577 | —- | C] () – C:\Users\Pedro\Engine Mapper's Subaru Tuning Guide V1.1.pdf
[2012/05/08 20:44:11 | 000,343,260 | —- | C] () – C:\Users\Pedro\Jacamo.jpg
[2012/04/17 19:12:03 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2012/03/31 12:54:14 | 004,154,112 | —- | C] () – C:\Windows\PE_File.dll
[2012/03/26 17:26:02 | 000,764,734 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/03/11 16:19:22 | 003,168,840 | —- | C] () – C:\Users\Pedro\zygor_3.3.3572.zip
[2012/01/14 10:28:56 | 000,880,537 | —- | C] () – C:\Users\Pedro\1326533268230.jpg
[2012/01/08 23:05:40 | 001,871,497 | —- | C] () – C:\Users\Pedro\Windows Loader v2.0.0.zip
[2012/01/07 13:31:39 | 000,254,914 | —- | C] () – C:\Users\Pedro\your_credit_agreement.pdf
[2012/01/07 09:49:48 | 002,580,231 | —- | C] () – C:\Users\Pedro\P8Z68-V-LX-ASUS-0703.zip
[2012/01/07 01:12:36 | 004,088,576 | —- | C] () – C:\Windows\PE_Rom.dll
[2012/01/06 22:57:35 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2012/01/06 22:57:32 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2012/01/06 22:51:50 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2012/01/06 22:51:46 | 000,030,387 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2011/10/15 00:54:52 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe

========== ZeroAccess Check ==========

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 06:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 05:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 02:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 13:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 02:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/09/07 19:42:14 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\.minecraft
[2012/10/14 20:41:00 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\.techniclauncher
[2012/10/21 16:35:48 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\DriverCure
[2012/10/21 14:48:13 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\Easeware
[2012/04/13 19:58:36 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\fltk.org
[2012/01/07 00:17:10 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\Leadertech
[2012/04/27 22:29:07 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\LoneSurvivor
[2012/03/04 20:57:19 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\LucasArts
[2012/01/06 23:08:17 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\Opera
[2012/02/13 20:22:10 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\Origin
[2012/10/21 16:35:48 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\SpeedyPC Software
[2012/07/24 23:10:50 | 000,000,000 | —D | M] – C:\Users\Pedro\AppData\Roaming\TS3Client

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 07:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 07:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 13:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 07:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 07:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 06:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 14:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 07:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 06:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 02:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 07:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 07:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/14 02:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\erdnt\cache64\services.exe
[2009/07/14 02:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/14 02:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache86\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\erdnt\cache64\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 13:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache86\userinit.exe
[2010/11/20 13:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 13:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\erdnt\cache64\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 14:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 14:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 14:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 02:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 08:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ST31000524AS
Partitions: 2
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 105906176
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\SysWOW64\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction

< End of report >
my aswMBR log:- aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-10-21 16:53:23 —————————– 16:53:23.074 OS Version: Windows x64 6.1.7601 Service Pack 1 16:53:23.074 Number of processors: 8 586 0x2A07 16:53:23.076 ComputerName: PEDRO-PC UserName: Pedro 16:53:55.775 Initialize success 16:53:59.038 AVAST engine defs: 12102100 16:54:05.151 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 16:54:05.153 Disk 0 Vendor: ST310005 JC4B Size: 953869MB BusType: 3 16:54:05.162 Disk 0 MBR read successfully 16:54:05.164 Disk 0 MBR scan 16:54:05.168 Disk 0 Windows 7 default MBR code 16:54:05.192 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 16:54:05.213 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848 16:54:05.313 Disk 0 scanning C:\Windows\system32\drivers 16:54:24.903 Service scanning 16:54:47.272 Modules scanning 16:54:47.280 Disk 0 trace - called modules: 16:54:47.303 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 16:54:47.308 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800773e790] 16:54:47.315 3 CLASSPNP.SYS[fffff88001c3243f] -> nt!IofCallDriver -> [0xfffffa80071b7800] 16:54:47.320 5 ACPI.sys[fffff88000f4e7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800729f050] 16:55:09.256 AVAST engine scan C:\Windows 16:55:32.567 AVAST engine scan C:\Windows\system32 17:00:49.180 AVAST engine scan C:\Windows\system32\drivers 17:01:39.986 AVAST engine scan C:\Users\Pedro 17:58:37.270 AVAST engine scan C:\ProgramData 18:02:45.180 Scan finished successfully 18:03:43.572 Disk 0 MBR has been saved successfully to "C:\Users\Pedro\Desktop\MBR.dat" 18:03:43.576 The log file has been saved successfully to "C:\Users\Pedro\Desktop\aswMBR.txt" My Combofix log:- ComboFix 12-10-21.02 - Pedro 21/10/2012 18:12:09.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8159.4360 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_nvsvc . . ((((((((((((((((((((((((( Files Created from 2012-09-21 to 2012-10-21 ))))))))))))))))))))))))))))))) . . 2012-10-21 15:35 . 2012-10-21 15:35 ——– d—–w- c:\users\Pedro\AppData\Roaming\SpeedyPC Software 2012-10-21 15:35 . 2012-10-21 15:35 ——– d—–w- c:\users\Pedro\AppData\Roaming\DriverCure 2012-10-21 15:35 . 2012-10-21 15:40 ——– d—–w- c:\programdata\SpeedyPC Software 2012-10-21 15:16 . 2012-10-21 15:16 ——– d—–w- c:\users\TEMP 2012-10-21 15:10 . 2011-12-12 16:20 100456 —-a-w- c:\windows\system32\RCoInstII64.dll 2012-10-21 15:09 . 2012-10-21 15:09 200836 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll 2012-10-21 14:14 . 2012-10-21 14:14 ——– d—–w- c:\users\Pedro\AppData\Roaming\Malwarebytes 2012-10-21 14:14 . 2012-10-21 14:14 ——– d—–w- c:\programdata\Malwarebytes 2012-10-21 14:14 . 2012-10-21 14:14 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-10-21 14:14 . 2012-09-29 18:54 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-10-21 14:08 . 2012-10-21 14:08 ——– d—–w- C:\Advanced Wheel Mouse 2012-10-21 14:07 . 2011-09-29 16:30 74272 —-a-w- c:\windows\system32\RtNicProp64.dll 2012-10-21 14:07 . 2011-09-29 16:30 646248 —-a-w- c:\windows\system32\drivers\Rt64win7.sys 2012-10-21 13:48 . 2012-10-21 13:48 ——– d—–w- c:\users\Pedro\AppData\Roaming\Easeware 2012-10-21 13:48 . 2012-10-21 13:48 ——– d—–w- c:\program files\Easeware 2012-10-21 13:45 . 2012-10-21 13:45 ——– d—–w- c:\program files (x86)\NirSoft 2012-10-19 20:04 . 2012-09-24 22:16 95208 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2012-10-19 20:01 . 2012-10-12 07:19 9291768 ——w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9012B983-3C89-4A80-AEB5-7670BD7DD9B4}\mpengine.dll 2012-10-15 22:24 . 2012-10-02 19:51 3536817 —-a-w- c:\windows\system32\nvcoproc.bin 2012-10-10 16:58 . 2012-08-20 17:32 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll 2012-10-07 08:14 . 2012-08-21 12:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-10-07 08:13 . 2012-10-07 08:13 ——– d—–w- c:\program files\iPod 2012-10-07 08:13 . 2012-10-07 08:14 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-10-07 08:13 . 2012-10-07 08:14 ——– d—–w- c:\program files\iTunes 2012-10-07 08:13 . 2012-10-07 08:14 ——– d—–w- c:\program files (x86)\iTunes 2012-10-05 17:49 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-10-02 12:15 . 2012-10-02 12:15 430952 —-a-w- c:\windows\SysWow64\nvStreaming.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-20 17:26 . 2012-01-07 00:12 4088576 —-a-w- c:\windows\PE_Rom.dll 2012-10-11 16:16 . 2012-01-06 23:06 65309168 —-a-w- c:\windows\system32\MRT.exe 2012-10-08 20:02 . 2012-04-03 18:28 696760 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-10-08 20:02 . 2012-01-06 22:36 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-10-02 22:21 . 2012-02-09 21:43 973672 —-a-w- c:\windows\system32\nvumdshimx.dll 2012-10-02 22:21 . 2012-02-09 21:43 15309160 —-a-w- c:\windows\SysWow64\nvd3dum.dll 2012-10-02 22:21 . 2012-01-06 23:12 26331496 —-a-w- c:\windows\system32\nvoglv64.dll 2012-10-02 22:21 . 2012-01-06 23:12 18252136 —-a-w- c:\windows\system32\nvd3dumx.dll 2012-10-02 22:21 . 2012-01-06 23:12 1760104 —-a-w- c:\windows\system32\nvdispco64.dll 2012-10-02 22:21 . 2012-01-06 23:12 14922600 —-a-w- c:\windows\system32\nvwgf2umx.dll 2012-10-02 22:21 . 2011-05-21 06:01 2731880 —-a-w- c:\windows\system32\nvapi64.dll 2012-10-02 19:51 . 2012-01-06 22:56 3293544 —-a-w- c:\windows\system32\nvsvc64.dll 2012-10-02 19:51 . 2012-01-06 22:56 6200680 —-a-w- c:\windows\system32\nvcpl.dll 2012-10-02 19:50 . 2012-01-06 22:56 891240 —-a-w- c:\windows\system32\nvvsvc.exe 2012-10-02 19:50 . 2012-01-06 22:56 63336 —-a-w- c:\windows\system32\nvshext.dll 2012-10-02 19:50 . 2012-01-06 22:56 2557800 —-a-w- c:\windows\system32\nvsvcr.dll 2012-10-02 19:50 . 2012-01-06 22:56 118120 —-a-w- c:\windows\system32\nvmctray.dll 2012-09-01 23:14 . 2012-09-01 23:15 289768 —-a-w- c:\windows\system32\javaws.exe 2012-09-01 23:14 . 2012-09-01 23:14 189416 —-a-w- c:\windows\system32\javaw.exe 2012-09-01 23:14 . 2012-09-01 23:14 188904 —-a-w- c:\windows\system32\java.exe 2012-09-01 23:14 . 2012-09-01 23:14 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2012-09-01 23:14 . 2012-03-25 19:56 1034216 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-09-01 23:14 . 2012-02-05 20:59 916456 —-a-w- c:\windows\system32\deployJava1.dll 2012-09-01 23:14 . 2012-03-25 20:49 821736 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2012-09-01 23:14 . 2012-02-09 19:41 746984 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-08-22 18:12 . 2012-09-12 18:15 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-08-22 18:12 . 2012-09-12 18:15 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-08-22 18:12 . 2012-09-12 18:15 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-08-22 18:12 . 2012-09-12 18:15 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-08-21 12:01 . 2012-01-06 22:50 125872 —-a-w- c:\windows\system32\GEARAspi64.dll 2012-08-21 12:01 . 2012-01-06 22:50 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2012-08-21 09:13 . 2012-01-06 22:12 359464 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-08-21 09:13 . 2012-01-06 22:12 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-08-21 09:13 . 2012-01-06 22:12 969200 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-08-21 09:13 . 2012-03-18 22:57 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-08-21 09:13 . 2012-01-06 22:12 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-08-21 09:13 . 2012-01-06 22:12 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-08-21 09:12 . 2012-01-06 22:11 41224 —-a-w- c:\windows\avastSS.scr 2012-08-21 09:12 . 2012-01-06 22:11 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe 2012-08-21 09:12 . 2012-01-06 22:12 285328 —-a-w- c:\windows\system32\aswBoot.exe 2012-08-20 17:38 . 2012-10-10 16:59 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-08-12 10:18 . 2012-03-31 11:54 4154112 —-a-w- c:\windows\PE_File.dll 2012-08-02 17:58 . 2012-09-12 18:15 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-08-02 16:57 . 2012-09-12 18:15 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-08-04 1353080] "HP Deskjet 3070 B611 series (NET)"="c:\program files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe" [2011-03-30 2547048] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-05-19 284440] "ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888] "LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2010-05-20 119152] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-01-12 49208] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-09 421776] "WheelMouse"="c:\advanc~1\wh_exec.exe" [2010-05-26 147456] . c:\users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] CurseClientStartup.ccip [2012-1-7 0] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-01 136176] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-08 250808] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-01 136176] R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files (x86)\NETGEAR\WN111v2\jswpsapi.exe [2008-02-29 942080] R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 16008] R3 PCAMp50a64;PCAMp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50a64.sys [2006-11-28 43328] R3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCASp50a64.sys [2006-11-28 41280] R3 Tcpz-x64;Tcpz-x64;c:\users\Pedro\AppData\Local\Temp\Tcpz-x64.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-06 1255736] S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464] S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 JSWPSLWF;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwfx.sys [2008-10-01 26624] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [2011-06-13 922240] S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584] S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-08-21 71600] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-05-19 13592] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-02 1258856] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2011-06-02 128488] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2011-06-02 401896] S3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [2011-06-29 26136] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 22408] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-07-07 174184] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248] S3 t_mouse.sys;iBall Advanced Mouse;c:\windows\system32\DRIVERS\t_mouse.sys [2009-04-16 25088] S3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\DRIVERS\whfltr2k.sys [2009-09-16 10368] S3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\DRIVERS\WN111v2w7x.sys [2010-04-27 783360] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-10-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 20:02] . 2012-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-01 18:24] . 2012-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-01 18:24] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-08-21 09:11 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MouseDriver"="TiltWheelMouse.exe" [2010-11-01 241152] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816] "VX3000"="c:\windows\vVX3000.exe" [2010-05-20 762736] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-12-12 7560296] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{687578b9-7132-4a7a-80e4-30ee31099e03} - (no file) Wow6432Node-HKCU-Run-EA Core - c:\program files (x86)\Electronic Arts\EADM\Core.exe Wow6432Node-HKCU-Run-MobileDocuments - c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe Wow6432Node-HKLM-Run-jswtrayutil - c:\program files (x86)\NETGEAR\WN111v2\jswtrayutil.exe Wow6432Node-HKLM-Run- - (no file) WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe c:\program files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe c:\program files (x86)\ASUS\AI Suite II\AI Suite II.exe c:\program files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe . ************************************************************************** . Completion time: 2012-10-21 18:23:43 - machine was rebooted ComboFix-quarantined-files.txt 2012-10-21 17:23 . Pre-Run: 761,868,496,896 bytes free Post-Run: 762,643,410,944 bytes free . - - End Of File - - 701CE33F51786384AF9635274AB82016
my Extras Log:-

OTL Extras logfile created on: 23/10/2012 20:28:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pedro\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.97 Gb Total Physical Memory | 5.81 Gb Available Physical Memory | 72.95% Memory free
15.93 Gb Paging File | 13.48 Gb Available in Paging File | 84.61% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 709.18 Gb Free Space | 76.14% Space Free | Partition Type: NTFS

Computer Name: PEDRO-PC | User Name: Pedro | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03338A4D-01AF-4063-8120-04FC80DBCD9A}" = rport=445 | protocol=6 | dir=out | app=system |
"{0948D162-0008-4113-B2C5-E05E6F0FE8AD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0B5EC768-E8EF-4EE5-BF98-571108A5A92F}" = lport=138 | protocol=17 | dir=in | app=system |
"{0D70470E-83E3-443B-B5B0-89C48EE88EB6}" = rport=10243 | protocol=6 | dir=out | app=system |
"{155A9D9D-F758-4CE7-B01B-F6DC025EE657}" = rport=65535 | protocol=17 | dir=out | name=minecraft udp |
"{1BCBCAA2-2B13-4B64-8733-14E63D0CC3EC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1F2301B1-706B-42EB-B6F6-2E8A4D0B4FF9}" = lport=137 | protocol=17 | dir=in | app=system |
"{47C8741B-446F-4311-902B-AD7EC5D7BF62}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{4E33A50B-A7C5-46A7-8B8F-B44F974DC7DF}" = lport=10243 | protocol=6 | dir=in | app=system |
"{5CC5CFC2-67E4-4099-A953-8AB359644919}" = rport=137 | protocol=17 | dir=out | app=system |
"{6768D7D9-5789-48F8-9A6F-5818F6F9027E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{71BDDF97-BDCB-4D4A-9D25-745E13CC7863}" = rport=65535 | protocol=6 | dir=out | name=minecraft tcp |
"{76FD76D6-EEA1-4FBA-9A8E-E84B6EE66742}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{87F25373-4CA3-41B8-84FF-D4F3F0D5ED4D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8812ECC4-5801-4D0D-9B13-E93F02AF9FBA}" = lport=139 | protocol=6 | dir=in | app=system |
"{8A978056-1E00-4413-A3A0-9F6CBD9AB2FE}" = lport=445 | protocol=6 | dir=in | app=system |
"{8DE14C1D-DF88-4A60-8A04-F78C632DE38A}" = lport=65535 | protocol=6 | dir=in | name=minecraft tcp |
"{A3830ECC-4A7A-41B1-9B33-CF1351295FB4}" = lport=65535 | protocol=17 | dir=in | name=minecraft udp |
"{AB1E3498-D0D5-46A4-BD53-46FD6C59422A}" = rport=138 | protocol=17 | dir=out | app=system |
"{AC574918-23F4-4BC6-8662-BCC4DB7651AF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BC12E2B5-9A9A-4304-998D-CBAEB8ABE39E}" = rport=139 | protocol=6 | dir=out | app=system |
"{C81251BE-B3A4-4994-B240-3C5324B14498}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{CBDC3524-686E-4B48-B518-19832BE44FBB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D840D865-E6DF-48F6-A075-597A50AC5E56}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E08FFFFB-7710-4997-9549-DD5AA1FEBCDC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E11AE967-6AAA-4B78-8390-521AC567CD02}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FD3524F1-1BA6-41E4-84CC-53F24E54C60B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00D8BCB9-06D3-4D81-A9C0-452E14CD4973}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{02455A2E-0B33-4D26-BA0F-D890CAB9BC0C}" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe |
"{025547E1-77DC-47B3-9CD5-30198CCB1F77}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{04214F3A-AC9B-40E0-8AE3-1ED4A246D0B2}" = dir=in | app=c:\program files\hp\hp deskjet 3070 b611 series\bin\devicesetup.exe |
"{042D6799-3C8B-4454-8182-CAF38D7E11CB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{067E91B5-81D2-4859-99D9-9DBDC8EB17AC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{098CD4F7-41D2-40EA-9324-A7443C49F78A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\silent hill homecoming\bin\silenthill.exe |
"{0A538711-E0DD-4BFE-AC0B-FC0B3B350132}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{0D8B0C14-5605-4A1F-881E-2543064552FB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lone survivor\lonesurvivor\lonesurvivor.exe |
"{108D9236-C700-474E-8517-D07D64169C7C}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeenc2.exe |
"{10B0D632-BD32-47DC-A297-023484F5547B}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"{15D5AC1F-55FD-4812-9DCB-C717476D38AF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{16E733FD-406F-4B3E-84C4-A24C2B3A94BB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{191AEADB-7D75-4199-AF07-DC95A21C7E3E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1DF047C3-3CF4-4DC6-BBF6-A5C19B7F307F}" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe |
"{1E0F777F-1BA4-4F31-8164-603122502BD6}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{23EB5F15-9864-42C1-9F9B-FC35041875D7}" = protocol=6 | dir=in | app=c:\games\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{283AC0AD-301C-4D49-B668-CD9B18347A71}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{283CC3E0-CF6A-4CB6-9224-3FB6CD130EBA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\l.a.noire\lanlauncher.exe |
"{289A2779-1B1E-4E48-ABF9-3392475B0490}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{28F884D6-61CD-4CEE-BE2B-2B359AAF9EBA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{298E6C1F-69BF-4D54-9DD4-AFCAD3EE4EC8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2E4F4B6E-7842-41AB-A766-2A21DF6EA8BC}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{2E8A0E5B-D971-48BD-B367-3C7099EE9B33}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeexp.exe |
"{2FCDEE37-4315-4662-AD0A-30ACE146022A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifetray.exe |
"{30B029D2-0F79-4EF6-A271-24A848A67A2A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief_gold\thief.exe |
"{3326C351-B78D-4593-B4DA-901801F13C3A}" = protocol=17 | dir=in | app=c:\games\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{3367C430-5878-45D5-B41B-FBBC9B0A623C}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{374ED8FD-367D-44F1-9E34-7FC06F90C136}" = protocol=17 | dir=in | app=c:\games\world of warcraft\launcher.exe |
"{37A6EC95-02BF-47E6-AC77-84F7D9DA20BA}" = protocol=17 | dir=in | app=c:\users\pedro\appdata\local\apps\2.0\c0mgpoe1.htc\5r8mxbnd.rkc\curs..tion_eee711038731a406_0004.0000_2ad57791d5c42008\curseclient.exe |
"{390F978F-6E5D-44C7-BE96-20F572E354D8}" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"{3A1B6D93-E37A-4337-B1C7-2B5057B38BFA}" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe |
"{413CDEF4-405C-4537-B382-3DF4C38639BC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief deadly shadows\system\runme.exe |
"{4626DBAC-78B3-45F6-B508-11980FFD890F}" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"{46B7F9AA-646E-4FD9-9428-1685618249EE}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifetray.exe |
"{49871674-AF2A-49A4-88FD-EC35B5B8BFD0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead island\deadislandgame.exe |
"{49F1A427-09ED-4F82-A4BC-FA79D91A0329}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"{4A4BC321-FD6F-4EEF-A288-4CB025B236FC}" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
"{4A4FACF9-E5E1-4786-BDEE-3C68BEC5CF6D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead island\deadislandgame.exe |
"{4B78F56C-7AD6-4222-974E-8B10218D275E}" = dir=in | app=c:\program files\hp\hp deskjet 3070 b611 series\bin\hpnetworkcommunicator.exe |
"{4CAB8446-74CC-452A-B222-38863C175A0D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{4D3AF867-FBE4-47FB-938A-1F03D0363D3F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{4F30033D-49D9-4D8F-B90E-65DB0BD27854}" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe |
"{549FFFA7-21EF-4528-AC19-9D6E923BF7FE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{54FC2704-0A52-4A9E-B6DE-DC4B5C276EB7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{61E8FD27-A7BE-4D64-AE7E-BB28D82A365B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{64532440-5B23-4B0D-8630-8C94EBECD9DF}" = protocol=6 | dir=out | app=system |
"{6B82434F-E3B1-47FB-8B74-B33B0A856A8C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief_2\thief2.exe |
"{6F9A22C7-3CEC-423A-878C-014C3179CD97}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\launcher.exe |
"{724BA91E-B195-456F-B603-DED200E6EE3F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7815ED64-66A8-4587-BC15-5A23E12BEF5D}" = protocol=6 | dir=in | app=c:\games\world of warcraft\launcher.exe |
"{7C31BFDE-92B4-420E-B025-97716D93BD44}" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe |
"{7CBB2799-1978-4295-B7DC-A818975FA65D}" = protocol=6 | dir=in | app=c:\games\diablo iii\diablo iii.exe |
"{7D8F0421-E34F-4CFA-9BA7-74257A8FE03A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monkey2\monkey2.exe |
"{7E09BFE7-31D9-4928-A2CD-E58A61EE50B3}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7EA5F70B-7530-4012-B82F-CC79810B0D98}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{8079778A-29D7-475B-BA61-B3D5E51CB83C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online.exe |
"{828BBC66-65C9-49CF-B2E3-C66105EC42A0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\launcher.exe |
"{86959BC1-4FE0-4641-A1B9-534CC70DEDD0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{869D8391-8B56-4614-AF93-008635A6343B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeenc2.exe |
"{87022185-543F-4E39-B4B1-1CE3A9FB3B84}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{874CC005-0E69-4958-9141-44EC4AD4BE57}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\l.a.noire\lanlauncher.exe |
"{8826D6B8-DAA2-4CB3-8B98-554DB00CA009}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeexp.exe |
"{89178EBB-031F-4172-83E0-BEA8476ECBAC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{8B037CD2-2810-486F-A4AF-18F0F40C1361}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8C50B7E8-3A42-4AFB-BDA1-996468A378FE}" = protocol=17 | dir=in | app=c:\games\diablo iii\diablo iii.exe |
"{8C604745-F051-4F53-9E76-5AF4A5FA9626}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{90AACA30-2D16-46A6-9D5B-6C5B6A96D4C7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{90BBE814-B916-4B4A-8200-0B96C88D0194}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\silent hill homecoming\bin\silenthill.exe |
"{94530FB6-681A-415D-9345-681AEC7DA08E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{960E7003-684B-48A4-A810-29602415E7D0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{98E53C5C-6A73-47A2-8C0A-877E8AA4B2F3}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9A16A640-2D44-4429-97FA-623D47FE53F0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{9E12B15D-655A-48E9-8F80-F8684D3FD732}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gemini rue\reslists\gemini rue.exe |
"{9ED128DC-374A-405B-A393-E754B7E6D0B3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lone survivor\lonesurvivor\lonesurvivor.exe |
"{9F9863C3-51EB-4200-96BB-C08C6C815E0A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{9FAA67E8-4734-45D6-BD21-86D9EC55B1D6}" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"{A28A6B99-4380-418F-935A-521C9E711ADB}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{A29B3EA8-E869-4CE1-B066-976484D0BE2B}" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"{A3EE8F46-82B9-4625-A3D5-2D058EFC293C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A3FB5ABE-312C-4478-B5B2-B2054A3CDAC9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{A4732178-49C4-44DD-9493-E4727E8F8121}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gemini rue\reslists\gemini rue.exe |
"{A693E4BD-E9DA-46E5-B9A6-AC63D47EEBAD}" = protocol=6 | dir=in | app=c:\users\pedro\appdata\local\apps\2.0\c0mgpoe1.htc\5r8mxbnd.rkc\curs..tion_eee711038731a406_0004.0000_2ad57791d5c42008\curseclient.exe |
"{A6C2F149-02DC-49D7-A977-6F3E936286A6}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A6F0987A-4ADE-4CD3-8E69-626DBA95886A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A7FCD898-FEC1-4466-884B-FBFC92387CB1}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{A9C4E2A6-6082-4415-B5A6-102D206EEF0F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{ABA0FDD7-1493-4CB0-A515-B1E5FCBE7BB9}" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"{ABDFA344-33AB-4B1B-9B99-69A4CC7D245A}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"{ACF04416-1FD4-4D59-95B0-B97141452772}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief deadly shadows\system\runme.exe |
"{AE61E778-7028-411B-A842-3598A33F58E5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{B22B0B3C-5289-4FA5-BC94-793166429CD9}" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"{B5C661DC-7189-485F-93F5-C597CCB8E20C}" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe |
"{B7669842-C6AF-4162-A487-3226F845CE81}" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"{B8FDADF1-9489-4841-AE66-7D7FCE5425D1}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{BBD9814D-AA26-4079-B726-78DDF545C711}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{BC85E5D8-AA4B-425C-A524-AD6288656517}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{BCC63303-F849-4FEE-AB95-A9833258EE03}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifecam.exe |
"{BE8F34F1-A234-455F-87B7-930C3107918E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{C1892675-05C1-404D-9869-A494A652DE68}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{C1B2ED70-DF7A-48FF-9F4C-9F4AEDBC8E5F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C29395E5-7C14-4A4A-9AC5-68107CA72F65}" = protocol=17 | dir=in | app=c:\games\world of warcraft\launcher.patch.exe |
"{C62CAAD4-DCDF-469B-9976-173B64D707AC}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifecam.exe |
"{C77FC69B-AE73-443E-9FD6-B870B96EDAC5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monkey2\monkey2.exe |
"{CE9D2FE7-AC7F-4B85-BD7C-63C3FC3B8859}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"{D0AC1C14-BDCA-481B-BBAC-A01CA3D43E59}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online.exe |
"{D2987C37-C3D7-4394-A861-6791FA54B1BC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{D2F492FD-30EB-4AEC-B3D8-4F01C348C84C}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D42C8422-0128-4C1A-94CB-66B799080DFA}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{DB04A39D-3CDE-4122-9355-9657CAC4E816}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{DCF020B5-0E6F-40BB-9A7D-E32815C29F1C}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{DD57A1D7-8465-4BB4-9B9E-4D670B5A254D}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{E31B6533-5F91-4EAF-A5A4-8BF976CD7140}" = protocol=6 | dir=in | app=c:\games\world of warcraft\launcher.patch.exe |
"{E3E92DD4-1D65-4899-9CD6-62A576DD6E00}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E83C917F-5A09-4D67-A9F6-9BAFC672C212}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief_2\thief2.exe |
"{F1A0A588-9A11-4D62-9716-95E52E11E1F3}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{F28A78CA-F14E-4A7E-B544-ABFCC0CC8FDB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief_gold\thief.exe |
"{F94F1D7C-5371-448D-950F-D6695B9F3E34}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{FB40462B-9336-4D3C-BE7F-32935848BE2B}" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
"{FB78491F-81D1-41E5-A646-7EF5F33E8DBE}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{FCA94942-E06D-4A90-ACC9-6537A2973507}" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"{FCD489A5-A44B-40CD-9218-0AE417ADDCEB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{FE58E9EA-C638-499F-BFFE-8B4847FFE0AB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"TCP Query User{09728837-485A-46AC-B1B3-AABFEEAC9DE2}C:\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe |
"TCP Query User{335B2AE0-7350-41EB-AA1A-778E45C8317C}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"TCP Query User{35767D92-0A73-4A29-808B-48720BDAB726}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"TCP Query User{3FC30567-F046-4B4A-8F51-ADD83BAEC3A1}C:\games\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\backgrounddownloader.exe |
"TCP Query User{4DB357CC-69D3-4A28-98C2-789CB3890D6F}C:\games\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe |
"TCP Query User{50A24325-5F64-4579-953F-EAF1D2EB7450}C:\games\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe |
"TCP Query User{51F927C8-880C-4B44-8B69-8385BFCB2B5F}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{690B2A89-6D88-47BD-A709-F9641EED8611}C:\program files (x86)\asus\ai suite ii\ai suite ii.exe" = protocol=6 | dir=in | app=c:\program files (x86)\asus\ai suite ii\ai suite ii.exe |
"TCP Query User{6C38A59F-CB58-42D2-B9EB-F57DA32E1EE0}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{6C8D79B2-A644-458D-80E1-337634B22336}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"TCP Query User{8C54281D-B947-4C1B-8646-27D741FCE767}C:\games\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
"TCP Query User{A6548292-8618-49DA-8111-B0451DBFED9A}C:\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\launcher.exe |
"TCP Query User{B493BC7F-815F-4340-B6F8-AADA42E315D0}C:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"TCP Query User{B549F7A8-42DF-43BA-AB05-1B449858FFF5}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
"TCP Query User{C4B50B8E-1C36-417C-95A3-51BA16FFDC32}C:\games\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe |
"TCP Query User{CC42F23F-4411-4D49-BD7F-7491617DD03D}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"TCP Query User{CC83E537-6C9A-45B0-A8A8-C76C38032F08}C:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe |
"TCP Query User{D06859BB-1B29-4A15-956C-6527304352EB}C:\games\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\backgrounddownloader.exe |
"TCP Query User{D7FFCC38-152A-4DCC-9695-ADFD7896E78E}C:\games\world of warcraft\temp\wow-4.2.1.2685-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2685-enus-tools-downloader.exe |
"TCP Query User{EF4AF715-20F8-40FA-9717-44AA951AFB11}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{F0C07103-E588-4612-B83F-DF06A816A99E}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{FD195602-CF39-4A84-8B59-E8CB92EBF99F}C:\games\world of warcraft\temp\wow-4.2.1.2683-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2683-enus-tools-downloader.exe |
"UDP Query User{0D8E9FA8-4A67-48BB-8C63-3974A42630F3}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"UDP Query User{1E934815-FE56-46BE-ADFF-977C61075900}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{210FAB83-2B60-4880-8773-99E725740A02}C:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"UDP Query User{26BAEDEA-D9E3-4A2C-BAAC-002B67AEAA16}C:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe |
"UDP Query User{2F805628-F87E-4160-8BE8-85B78316EE1B}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{326FA54B-E359-44CE-8F66-C7B50554B105}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{380B4880-A6FD-45B8-8D60-9C7E73D59D31}C:\games\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe |
"UDP Query User{42F497EF-2E92-425E-963A-5809AD8F76AD}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"UDP Query User{4CE3BC6E-0298-4346-ABA0-42EEB26F2F8B}C:\games\world of warcraft\temp\wow-4.2.1.2685-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2685-enus-tools-downloader.exe |
"UDP Query User{6A8AFD57-FD93-4395-B3C7-48CCBB820EC4}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"UDP Query User{6E7F565A-FB1B-4353-A318-A3910CCB12AB}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{795688DE-4C8D-4B52-8702-18DE9FA96ED5}C:\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\launcher.exe |
"UDP Query User{7B4985D6-CF84-48A5-B4E9-B07DABF80202}C:\games\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\backgrounddownloader.exe |
"UDP Query User{96C02218-EE01-4E82-B785-77C44F8D1C03}C:\games\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe |
"UDP Query User{C288E8EE-9764-4F61-B761-0194D762F4F6}C:\games\world of warcraft\temp\wow-4.2.1.2683-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2683-enus-tools-downloader.exe |
"UDP Query User{C2CC5108-D7C4-425D-AB0C-181232084A7D}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"UDP Query User{C50087D5-EDE4-4369-8550-1E6273B11E7C}C:\games\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
"UDP Query User{C8F390DF-150B-483A-9B57-3C33099AE331}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
"UDP Query User{CC865585-B6E2-4A1A-B545-DA2546CDE62F}C:\games\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe |
"UDP Query User{E1D6E44B-DB65-4EBA-A67B-D1E095842B6B}C:\program files (x86)\asus\ai suite ii\ai suite ii.exe" = protocol=17 | dir=in | app=c:\program files (x86)\asus\ai suite ii\ai suite ii.exe |
"UDP Query User{ECCEF897-E0F3-46B4-9868-93FEB4579498}C:\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe |
"UDP Query User{F60ACF08-781D-4ABA-A45E-1F4012D63B4F}C:\games\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\games\world of warcraft\backgrounddownloader.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86417007FF}" = Java 7 Update 7 (64-bit)
"{4BC310C4-B898-46E2-B5FB-B85A30AA7142}" = iCloud
"{4DEA21F6-2F26-464F-BCDA-3335184FF1F3}" = HP Deskjet 3070 B611 series Product Improvement Study
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software
"{6965A8D2-465D-4F98-9FAA-0E9E2348F329}" = Microsoft LifeCam
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C5A08BF-BB99-4998-81BD-F6CC32483B34}" = Microsoft Corporation
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{DC8D8E05-ECDF-413D-A4F7-5DD161CEFAE5}" = HP Deskjet 3070 B611 series Basic Device Software
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.61.3
"DriverEasy_is1" = DriverEasy 4.1.1
"Logitech Gaming Software" = Logitech Gaming Software 8.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinRAR archiver" = WinRAR 4.11 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1C0E9C6B-D4D5-4D3C-8A10-F10A3E7BEEA5}" = WN111v2
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
"{34D3688E-A737-44C5-9E2A-FF73618728E1}" = AI Suite II
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3FD0C489-0F02-481a-A3E1-9754CD396761}" = Intel® Watchdog Timer Driver (Intel® WDT)
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F20CE56-3828-432D-A3C5-3EC6A2ED93C6}" = HP Deskjet 3070 B611 series Help
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"avast" = avast! Free Antivirus
"Bejeweled 3" = Bejeweled 3
"Bejeweled Blitz" = Bejeweled Blitz
"Diablo III" = Diablo III
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"InstallShield_{1C0E9C6B-D4D5-4D3C-8A10-F10A3E7BEEA5}" = RangeMax Wireless-N USB Adapter WN111v2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"NirSoft BlueScreenView" = NirSoft BlueScreenView
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenTTD" = OpenTTD 1.2.1
"Origin" = Origin
"Rockstar Games Social Club" = Rockstar Games Social Club
"Steam App 105600" = Terraria
"Steam App 110800" = L.A. Noire
"Steam App 19000" = Silent Hill: Homecoming
"Steam App 209830" = Lone Survivor
"Steam App 211740" = Thief 2
"Steam App 32460" = Monkey Island 2: Special Edition
"Steam App 3590" = Plants vs. Zombies: Game of the Year
"Steam App 550" = Left 4 Dead 2
"Steam App 57300" = Amnesia: The Dark Descent
"Steam App 65800" = Dungeon Defenders
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 80310" = Gemini Rue
"Steam App 91310" = Dead Island
"Steam App 9900" = Star Trek Online
"WinLiveSuite" = Windows Live Essentials
"World of Warcraft" = World of Warcraft

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"101a9f93b8f0bb6f" = Curse Client - 1
"c5c968b829b4973b" = Curse Client - Test

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 22/10/2012 18:43:21 | Computer Name = Pedro-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 20

Error - 22/10/2012 18:43:21 | Computer Name = Pedro-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 21

Error - 22/10/2012 18:43:21 | Computer Name = Pedro-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 22

Error - 22/10/2012 18:43:21 | Computer Name = Pedro-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 23

Error - 22/10/2012 18:43:21 | Computer Name = Pedro-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 24

Error - 23/10/2012 02:57:00 | Computer Name = Pedro-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1515
Description = Windows has backed up this user profile. Windows will automatically
try to use the backup profile the next time this user logs on.

Error - 23/10/2012 02:57:00 | Computer Name = Pedro-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1511
Description = Windows cannot find the local profile and is logging you on with a
temporary profile. Changes you make to this profile will be lost when you log off.

Error - 23/10/2012 15:22:43 | Computer Name = Pedro-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1515
Description = Windows has backed up this user profile. Windows will automatically
try to use the backup profile the next time this user logs on.

Error - 23/10/2012 15:22:43 | Computer Name = Pedro-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1511
Description = Windows cannot find the local profile and is logging you on with a
temporary profile. Changes you make to this profile will be lost when you log off.

Error - 23/10/2012 15:25:46 | Computer Name = Pedro-PC | Source = VSS | ID = 8193
Description =

Error - 23/10/2012 15:29:40 | Computer Name = Pedro-PC | Source = VSS | ID = 8193
Description =

[ System Events ]
Error - 21/10/2012 09:53:40 | Computer Name = Pedro-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 21/10/2012 09:53:40 | Computer Name = Pedro-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 21/10/2012 10:31:14 | Computer Name = Pedro-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 15:29:13 on ?21/?10/?2012 was unexpected.

Error - 21/10/2012 10:31:15 | Computer Name = PEDRO-PC | Source = BugCheck | ID = 1001
Description =

Error - 21/10/2012 13:15:05 | Computer Name = Pedro-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 21/10/2012 13:17:53 | Computer Name = Pedro-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 21/10/2012 13:17:56 | Computer Name = Pedro-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 21/10/2012 15:12:08 | Computer Name = Pedro-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 19:59:48 on ?21/?10/?2012 was unexpected.

Error - 21/10/2012 15:12:09 | Computer Name = PEDRO-PC | Source = BugCheck | ID = 1001
Description =

Error - 21/10/2012 18:45:58 | Computer Name = Pedro-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.


< End of report >
Hi Pedro_202,

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: c:\users\Pedro\AppData\Local\Temp\Tcpz-x64.sys
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.

Run OTL.exe Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2012/03/12 19:23:03 | 000,000,000 | —D | M] (uTorrentControl2 Community Toolbar) – C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
    http://www.systemlookup.com/search.php?type=name&client=malwaresearch-ff&search=uTorrentControl2%20Community%20Toolbar
    O4 - HKLM..\Run: [] File not found
    
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptyjava]
    [emptyflash]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Next


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right click GMER.exe, select "Run as Administrator" If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries.

In your next post please provide the following:
  • VirusTotal results
  • OTL.txt
  • Gmer.txt
  • Tell me how your computer is running at the moment
Not having much success with this im afraid OCD. When i try to browse to the file in VirusTotal it is not there. So i could not run that scan. Also when running GMER everything is greyed out on the right apart from "Services, Registry and Files" with C:\ ticked. I do not have any listing in the window like you do. OTL was completed successfully however and here is the log:- All processes killed ========== OTL ========== C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\searchplugin folder moved successfully. C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\modules folder moved successfully. C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\META-INF folder moved successfully. C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\defaults folder moved successfully. C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\components folder moved successfully. C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\chrome folder moved successfully. C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03} folder moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYJAVA] User: All Users User: Default User: Default User User: Pedro ->Java cache emptied: 461866 bytes User: Public User: TEMP User: UpdatusUser Total Java Files Cleaned = 0.00 mb [EMPTYFLASH] User: All Users User: Default User: Default User User: Pedro ->Flash cache emptied: 85790 bytes User: Public User: TEMP User: UpdatusUser Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Pedro ->Temp folder emptied: 3275882 bytes ->Temporary Internet Files folder emptied: 310979838 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 354444910 bytes ->Opera cache emptied: 53049939 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: TEMP ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 540350 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50467 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 624 bytes RecycleBin emptied: 298914729 bytes Total Files Cleaned = 974.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 10242012_192314 Files\Folders moved on Reboot… C:\Users\Pedro\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files… Registry entries deleted on Reboot…
With regards to how my system is running. It is running perfectly fine. Games run as quick as they should. browsing isnt a problem and everything is as expected. The Windows Action Centre is still telling me that the virus is present however you would be hard pressed to see its effects. My crashes and bluescreens seemed to be an issue with one of two unrelated issues. I had recently updated to the newest Nvidia drivers. 306.97 which i have now rolled back. I have also removed 8gb of ram to leave me with the other 8gb. There were compatibility issues in the past so back to basics until im sorted. Since the driver reversal to version 286 and the ram removed crashes have stopped.
Hi Pedro_202,

Could you please open the Windows Action Center and give me additional details about the virus it says is present.

Next

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the log file to your desktop.
[external image: Posted Image]
Click the image to enlarge it

Next

Locate Malwarebytes' Anti-Malware (it should be on your desktop).
  • Right - click the MBAM icon and select "Run as Administrator"to launch the program.
  • Once the program has loaded, select the Update tab to get the latest updates before performing the scan.
  • Select Perform quick scan, then click Scan.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Next

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.

In your next post please provide the following:
  • Windows Action Center information
  • aswMBR log
  • MBAM log
  • ESET's log.txt
Hi OCD. My Windows Action Centre just States "Remove the Win32/Small.CA Virus" Clicking on it displays:-

Remove the Win32/Small.CA virus from your PC
This problem was caused by Win32/Small.CA, a known computer virus.

My aswMBR log is :-

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-10-25 19:37:26
—————————–
19:37:26.583 OS Version: Windows x64 6.1.7601 Service Pack 1
19:37:26.583 Number of processors: 8 586 0x2A07
19:37:26.583 ComputerName: PEDRO-PC UserName: Pedro
19:37:34.391 Initialize success
19:37:34.448 AVAST engine defs: 12102501
19:37:46.530 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:37:46.532 Disk 0 Vendor: ST310005 JC4B Size: 953869MB BusType: 3
19:37:46.542 Disk 0 MBR read successfully
19:37:46.544 Disk 0 MBR scan
19:37:46.548 Disk 0 Windows 7 default MBR code
19:37:46.556 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
19:37:46.569 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
19:37:46.588 Disk 0 scanning C:\Windows\system32\drivers
19:37:54.083 Service scanning
19:38:09.929 Modules scanning
19:38:09.937 Disk 0 trace - called modules:
19:38:09.968 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
19:38:09.974 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007719790]
19:38:09.980 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> [0xfffffa8007304e40]
19:38:09.985 5 ACPI.sys[fffff88000fab7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007307050]
19:38:27.889 AVAST engine scan C:\Windows
19:38:35.994 AVAST engine scan C:\Windows\system32
19:41:11.253 AVAST engine scan C:\Windows\system32\drivers
19:41:36.634 AVAST engine scan C:\Users\Pedro
20:01:20.782 AVAST engine scan C:\ProgramData
20:02:56.967 Scan finished successfully
20:03:06.098 Disk 0 MBR has been saved successfully to "C:\Users\Pedro\Desktop\MBR.dat"
20:03:06.101 The log file has been saved successfully to "C:\Users\Pedro\Desktop\aswMBR.txt"

My MBAM log is :-

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.10.25.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Pedro :: PEDRO-PC [administrator]

25/10/2012 20:04:13
mbam-log-2012-10-25 (20-04-13).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 242395
Time elapsed: 2 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

After running ESET Online scanner no threats were found. There was no log to view i could only exit or download their virus software. so i exited.

Its worth noting that the message from my action centre was first mentioned on the 15th October and now it has been archived it has not come up again.
Hi Pedro_202,

Your log appears to be clean. We have a few items to take care of before we get to the All Clean Speech.

The following will implement important cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bold text into the Run box and click OK:

ComboFix /Uninstall
(Note the space between the ..X and the /U, it needs to be there.)

[external image: Posted Image]

Next

Clean up with OTL:
  • Right-click OTL.exe select "Run as Administrator" to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
Next

You can delete any tools and logs still remaning on your desktop.

Next

Clear Java Cache
  • Start button, select Control Panel.
  • In the Control Panel, open the Java Control Panel.
  • Click on Settings button under Temporary Internet Files.
  • Click Delete Files button at the Temporary Files Settings window.
  • Click on OK button at confirmation dialog.
  • Exit the Control Panel.
With the above items taken care of let's move on to the All Clean part of the process.

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:
Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Steps followed thanks PCD. Was a great experience working with you. The world needs more people like yourself! Take care and with all the respect due i hope i never have to bother you again!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI