This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

BeeSQ.net Redirect

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello & Thanks Everybody,

I've ran TDSSkiller / Malwarebytes which did not display any infections, but when using the search bar it redirects to random websites BeeSQ.net. I get redirected from Chrome / Firefox / IE 9, I checked to make sure the search provider is set to Google and disabled addons on the browsers. Prior to posting this I ran:
1) OTL
2) Hijackthis
3)DDS

Here is what the finding from those programs, which were obtained by links provided by LDTate.

OTL logfile created on: 11/28/2012 3:39:46 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\kendrabish.DOMAIN\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 1.29 Gb Available Physical Memory | 39.77% Memory free
6.50 Gb Paging File | 4.39 Gb Available in Paging File | 67.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.69 Gb Total Space | 28.77 Gb Free Space | 25.76% Space Free | Partition Type: NTFS
Drive H: | 200.00 Gb Total Space | 103.15 Gb Free Space | 51.57% Space Free | Partition Type: NTFS
Drive Y: | 200.00 Gb Total Space | 85.22 Gb Free Space | 42.61% Space Free | Partition Type: NTFS
Drive Z: | 51.88 Gb Total Space | 26.43 Gb Free Space | 50.95% Space Free | Partition Type: NTFS

Computer Name: HOTEL | User Name: kendrabish | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\kendrabish.DOMAIN\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\kendrabish.DOMAIN\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Yammer\Yammer.exe ()
PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Panda Cloud Systems Management\Gui.exe (CentraStage)
PRC - C:\Program Files\Panda Cloud Systems Management\CagService.exe (CentraStage)
PRC - C:\Program Files\Panda Security\WaAgent\WAHost\WAHost.exe (Panda Security International)
PRC - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files\Panda Security\WAC\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Splashtop\Splashtop Remote\Server\SRService.exe (Splashtop Inc.)
PRC - C:\Program Files\Splashtop\Splashtop Remote\Server\SRServer.exe (Splashtop Inc.)
PRC - C:\Program Files\Splashtop\Splashtop Remote\Server\SRFeature.exe (Splashtop Inc.)
PRC - C:\Program Files\Splashtop\Splashtop Remote\Server\DataProxy.exe (Splashtop Inc.)
PRC - C:\Program Files\Panda Security\WAC\PSUAService.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\WAC\PSUAMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Cloud Systems Management\UltraVNC\winvnc.exe (UltraVNC)
PRC - C:\Program Files\Splashtop\Splashtop Software Updater\SSUService.exe (Splashtop Inc.)
PRC - C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files\DYMO\DYMO Label Software\DymoPnpService.exe (Sanford, L.P.)
PRC - C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\audiodg.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
PRC - C:\Windows\SSDriver\fi5110\SsWiaChecker.exe (PFU LIMITED)
PRC - C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
PRC - C:\Windows\System32\WTablet\TabUserW.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\Tablet.exe (Wacom Technology, Corp.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\WebKit.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\cf840dca36a7b949696ce331d0532d3e\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c64ca3678261c8ffcd9e7efd1af6ed54\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll ()
MOD - C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\pdf.dll ()
MOD - C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\libglesv2.dll ()
MOD - C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\libegl.dll ()
MOD - C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\avutil-51.dll ()
MOD - C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\avformat-54.dll ()
MOD - C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\avcodec-54.dll ()
MOD - C:\Program Files\Yammer\Yammer.exe ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Panda Cloud Systems Management\LinqBridge.dll ()
MOD - C:\Program Files\Panda Cloud Systems Management\Core.XmlSerializers.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\System32\spool\drivers\w32x86\3\ricaz0ur.dll ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\PfuSsConfig.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\PfuSsExtention.dll ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\SSsltsa.dll ()
MOD - C:\Program Files\VIA\VIAudioi\VDeck\skin.dll ()
MOD - C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll ()
MOD - C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll ()
MOD - C:\Program Files\PFU\ScanSnap\CardMinder\CardPath.dll ()
MOD - C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll ()
MOD - C:\Program Files\PFU\ScanSnap\Driver\PfuSsImgIO.dll ()
MOD - C:\Program Files\Common Files\PFU\ScanSnap\OCR\FJ\F5BDKAKU.DLL ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (CagService) – C:\Program Files\Panda Cloud Systems Management\CagService.exe (CentraStage)
SRV - (WAHost) – C:\Program Files\Panda Security\WaAgent\WAHost\WAHost.exe (Panda Security International)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\WAC\PSANHost.exe (Panda Security, S.L.)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SplashtopRemoteService) – C:\Program Files\Splashtop\Splashtop Remote\Server\SRService.exe (Splashtop Inc.)
SRV - (PSUAService) – C:\Program Files\Panda Security\WAC\PSUAService.exe (Panda Security, S.L.)
SRV - (uvnc_service) – C:\Program Files\Panda Cloud Systems Management\UltraVNC\winvnc.exe (UltraVNC)
SRV - (Fitbit) – C:\Program Files\Fitbit\fitbit.exe (Fitbit, Inc.)
SRV - (SSUService) – C:\Program Files\Splashtop\Splashtop Software Updater\SSUService.exe (Splashtop Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (DymoPnpService) – C:\Program Files\DYMO\DYMO Label Software\DymoPnpService.exe (Sanford, L.P.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (TabletService) – C:\Windows\System32\Tablet.exe (Wacom Technology, Corp.)


========== Driver Services (SafeList) ==========

DRV - (SBRE) – C:\Windows\system32\drivers\SBREdrv.sys File not found
DRV - (efavdrv) – C:\Windows\system32\drivers\efavdrv.sys File not found
DRV - (catchme) – C:\Users\KENDRA~1.MED\AppData\Local\Temp\catchme.sys File not found
DRV - (NNSIDS) – C:\Windows\System32\drivers\NNSIds.sys (Panda Security, S.L.)
DRV - (NNSPROT) – C:\Windows\System32\drivers\NNSProt.sys (Panda Security, S.L.)
DRV - (NNSSTRM) – C:\Windows\System32\drivers\NNSStrm.sys (Panda Security, S.L.)
DRV - (NNSPRV) – C:\Windows\System32\drivers\NNSPrv.sys (Panda Security, S.L.)
DRV - (NNSSMTP) – C:\Windows\System32\drivers\NNSSmtp.sys (Panda Security, S.L.)
DRV - (NNSPOP3) – C:\Windows\System32\drivers\NNSPop3.sys (Panda Security, S.L.)
DRV - (NNSTLSC) – C:\Windows\System32\drivers\NNStlsc.sys (Panda Security, S.L.)
DRV - (NNSHTTP) – C:\Windows\System32\drivers\NNSHttp.sys (Panda Security, S.L.)
DRV - (NNSPICC) – C:\Windows\System32\drivers\NNSpicc.sys (Panda Security, S.L.)
DRV - (NNSALPC) – C:\Windows\System32\drivers\NNSAlpc.sys (Panda Security, S.L.)
DRV - (NNSPIHS) – C:\Windows\System32\drivers\NNSpihs.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\Windows\System32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (PSINAflt) – C:\Windows\System32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (NNSNAHS) – C:\Windows\System32\drivers\NNSNAHS.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\Windows\System32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (PSINProt) – C:\Windows\System32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINProc) – C:\Windows\System32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (dvctprov) – C:\Windows\System32\drivers\dvctprov.sys (Panda Security, S.L.)
DRV - (PSINDvct) – C:\Windows\System32\drivers\PSINDvct.sys (Panda Security, S.L.)
DRV - (SIUSBXP) – C:\Windows\System32\drivers\SiUSBXp.sys (Silicon Laboratories)
DRV - (PSKMAD) – C:\Windows\System32\drivers\PSKMAD.sys (Panda Security)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (SCDEmu) – C:\Windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (VIAHdAudAddService) – C:\Windows\System32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (AMBFilt) – C:\Windows\System32\drivers\Ambfilt.sys (Creative)
DRV - (NVNET) – C:\Windows\System32\drivers\nvmf6232.sys (NVIDIA Corporation)
DRV - (MonFilt) – C:\Windows\System32\drivers\Monfilt.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/reader/view/?hl=en#overview-page
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 20 25 0C 4D 49 FE CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {22834095-E2DE-4EBC-B4ED-05F7CE0D8CBE}
IE - HKCU\..\SearchScopes\{22834095-E2DE-4EBC-B4ED-05F7CE0D8CBE}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.DOMAIN.com/Admin/UserAccounts/tabid/43/filter/Unauthorized/currentpage/1/Default.aspx|http://ui.benchmarkemail.com/Contacts/Add/Detail?4gcr%2FApPM0I%2BU2bszJyvrnAly0nRoqMZNyIeD9VsXLU%3D"
FF - prefs.js..extensions.enabledAddons: [removed]:1.0
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@dymo.com/DymoLabelFramework: C:\Program Files\DYMO\DYMO Label Software\Framework\npDYMOLabelFramework.dll ( Sanford L.P.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/05/25 10:35:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/29 07:32:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/10/29 07:32:17 | 000,000,000 | —D | M]

[2012/03/14 11:55:30 | 000,000,000 | —D | M] (No name found) – C:\Users\kendrabish.DOMAIN\AppData\Roaming\mozilla\Extensions
[2012/10/24 06:20:25 | 000,000,000 | —D | M] (No name found) – C:\Users\kendrabish.DOMAIN\AppData\Roaming\mozilla\Firefox\Profiles\nmd92tf2.default\extensions
[2009/07/13 17:11:12 | 000,004,819 | —- | M] () (No name found) – C:\Users\kendrabish.DOMAIN\AppData\Roaming\mozilla\firefox\profiles\nmd92tf2.default\extensions\[removed]
[2012/10/29 07:32:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/10/29 07:32:18 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/08/30 13:43:25 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/22 08:46:41 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\23.0.1271.91\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: DYMO Label Framework (Enabled) = C:\Program Files\DYMO\DYMO Label Software\Framework\npDYMOLabelFramework.dll
CHR - plugin: Google Update (Enabled) = C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Pocket (formerly Read It Later) = C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj\1.1.3_0\
CHR - Extension: Gmail = C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/10/03 09:15:24 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Panda Cloud Systems Management] C:\Program Files\Panda Cloud Systems Management\Gui.exe (CentraStage)
O4 - HKLM..\Run: [PSUAMain] C:\Program Files\Panda Security\WAC\PSUAMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ScanSnap WIA Service Checker] C:\Windows\SSDriver\fi5110\SsWiaChecker.exe (PFU LIMITED)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - Startup: C:\Users\kendrabish.DOMAIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\kendrabish.DOMAIN\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\kendrabish.DOMAIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Yammer.lnk = C:\Program Files\Yammer\Yammer.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: citrix ([]file in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.15
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DOMAIN.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{238663BF-CCDA-4D9B-A751-CD2220CDD6C3}: DhcpNameServer = 192.168.1.15
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 15:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/11/28 15:35:46 | 000,688,992 | —- | C] (Swearware) – C:\Users\kendrabish.DOMAIN\Desktop\dds.scr
[2012/11/28 15:35:43 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\kendrabish.DOMAIN\Desktop\OTL.exe
[2012/11/28 15:35:43 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\kendrabish.DOMAIN\Desktop\HiJackThis.exe
[2012/11/28 11:07:39 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Local\CentraStage
[2012/11/28 11:07:38 | 000,000,000 | —D | C] – C:\ProgramData\CentraStage
[2012/11/28 11:07:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Cloud Systems Management
[2012/11/28 11:07:25 | 000,000,000 | —D | C] – C:\Program Files\Panda Cloud Systems Management
[2012/11/28 03:16:22 | 000,046,280 | —- | C] (Panda Security) – C:\Windows\System32\drivers\PSKMAD.sys
[2012/11/27 11:17:11 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2012/11/27 11:17:10 | 000,000,000 | —D | C] – C:\Program Files\FileZilla FTP Client
[2012/11/27 07:28:09 | 000,042,808 | —- | C] (Panda Security, S.L.) – C:\Windows\System32\drivers\PSINDvct.sys
[2012/11/25 12:13:17 | 000,000,000 | R–D | C] – C:\Users\kendrabish.DOMAIN\Dropbox
[2012/11/25 12:10:52 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/11/25 12:09:44 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Dropbox
[2012/11/14 16:18:48 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2012/11/14 14:36:19 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Local\Apple Computer
[2012/11/14 14:33:55 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Apple Computer
[2012/11/14 14:33:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2012/11/14 14:33:19 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Local\Apple
[2012/11/14 14:33:18 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2012/11/14 14:33:12 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/11/14 14:33:04 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2012/11/14 14:33:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2012/11/14 14:17:56 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/11/14 03:01:32 | 000,047,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2012/11/14 03:01:32 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wdfres.dll
[2012/11/14 03:01:22 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2012/11/14 03:01:22 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2012/11/14 03:01:21 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2012/11/14 03:01:07 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/11/14 03:01:06 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/11/14 03:01:06 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/11/14 03:01:06 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/11/14 03:01:06 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/11/14 03:01:05 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/11/14 03:01:05 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/11/14 03:01:03 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/11/13 23:11:55 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncsi.dll
[2012/11/13 23:11:54 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcorehc.dll
[2012/11/13 23:11:54 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2012/11/13 23:11:53 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\synceng.dll
[2012/11/13 23:11:51 | 002,345,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/11/13 23:11:51 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcore6.dll
[2012/11/13 23:11:51 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2012/11/12 17:02:51 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Yammer
[2012/11/12 17:02:48 | 000,000,000 | —D | C] – C:\Program Files\Yammer
[2012/11/10 14:12:42 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Panda Security
[2012/11/10 14:12:14 | 000,000,000 | —D | C] – C:\ProgramData\Panda Security
[2012/11/10 14:12:14 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2012/11/10 14:02:38 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/11/10 14:02:38 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/11/10 14:02:38 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/11/09 19:09:40 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/11/09 19:08:55 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2012/11/05 15:07:17 | 000,000,000 | —D | C] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Malwarebytes
[2012/11/05 15:07:11 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/11/05 15:05:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/11/05 15:05:53 | 000,246,760 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2012/11/05 15:05:50 | 000,174,056 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2012/11/05 15:05:50 | 000,174,056 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2012/11/05 15:05:50 | 000,093,672 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll

========== Files - Modified Within 30 Days ==========

[2012/11/28 15:39:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/28 15:29:00 | 000,000,968 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1282305012-177568783-1305306242-3142UA.job
[2012/11/28 12:38:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\kendrabish.DOMAIN\Desktop\HiJackThis.exe
[2012/11/28 12:37:40 | 000,688,992 | —- | M] (Swearware) – C:\Users\kendrabish.DOMAIN\Desktop\dds.scr
[2012/11/28 12:36:30 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\kendrabish.DOMAIN\Desktop\OTL.exe
[2012/11/28 11:08:50 | 000,165,145 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\EleosMVA-specs.pdf
[2012/11/28 10:47:16 | 000,468,992 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\RSL Eleos.pdf
[2012/11/28 09:29:00 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1282305012-177568783-1305306242-3142Core.job
[2012/11/28 07:27:18 | 000,000,925 | —- | M] () – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Yammer.lnk
[2012/11/28 03:23:29 | 000,021,904 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/28 03:23:29 | 000,021,904 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/28 03:20:24 | 000,626,844 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/11/28 03:20:24 | 000,107,160 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/11/28 03:16:28 | 006,066,744 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/11/28 03:16:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/28 03:16:04 | 2616,696,832 | -HS- | M] () – C:\hiberfil.sys
[2012/11/27 07:31:09 | 000,001,034 | —- | M] () – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/11/27 07:31:01 | 000,001,048 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\Dropbox.lnk
[2012/11/26 16:06:29 | 000,000,064 | —- | M] () – C:\Windows\AdminIE.ini
[2012/11/26 10:25:22 | 000,000,132 | —- | M] () – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/11/21 10:44:55 | 000,081,308 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\thanksgiving.jpg
[2012/11/21 10:44:48 | 000,262,741 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\thanksgiving.psd
[2012/11/19 11:26:02 | 000,011,666 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\2013-Spousal-Impoverishment-Chart.pdf
[2012/11/19 07:53:22 | 000,127,488 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\Weekly Calendar.pub
[2012/11/14 14:19:53 | 000,312,104 | -H– | M] () – C:\Windows\System32\mlfcache.dat
[2012/11/14 12:39:20 | 000,127,032 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\Joint Marketing Needs.pdf
[2012/11/13 14:44:00 | 000,089,971 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\tax_issues4_pscs.pdf
[2012/11/13 14:09:12 | 000,121,293 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\LOI ELCO EXCEED LIFE.pdf
[2012/11/12 17:02:49 | 000,000,817 | —- | M] () – C:\Users\Public\Desktop\Yammer.lnk
[2012/11/12 13:28:11 | 000,078,639 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\FL 12-23 Medical Expense Consideration.pdf
[2012/11/09 20:07:03 | 000,002,030 | -H– | M] () – C:\Users\kendrabish.DOMAIN\Documents\Default.rdp
[2012/11/09 20:01:50 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/11/09 20:01:50 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/11/09 19:34:03 | 000,001,441 | —- | M] () – C:\scu.dat
[2012/11/06 11:26:06 | 000,002,888 | —- | M] () – C:\Users\kendrabish.DOMAIN\Desktop\HootSuite.lnk
[2012/11/05 15:05:46 | 000,746,984 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2012/11/05 15:05:46 | 000,246,760 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2012/11/05 15:05:46 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2012/11/05 15:05:46 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2012/11/05 15:05:46 | 000,093,672 | —- | M] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll

========== Files Created - No Company Name ==========

[2012/11/28 11:09:41 | 000,165,145 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\EleosMVA-specs.pdf
[2012/11/28 10:47:16 | 000,468,992 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\RSL Eleos.pdf
[2012/11/26 16:06:29 | 000,000,064 | —- | C] () – C:\Windows\AdminIE.ini
[2012/11/25 12:13:17 | 000,001,048 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\Dropbox.lnk
[2012/11/25 12:11:11 | 000,001,034 | —- | C] () – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/11/21 10:42:11 | 000,081,308 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\thanksgiving.jpg
[2012/11/21 10:42:01 | 000,262,741 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\thanksgiving.psd
[2012/11/19 11:26:02 | 000,011,666 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\2013-Spousal-Impoverishment-Chart.pdf
[2012/11/14 21:12:50 | 000,389,552 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\Individual_Examples.pdf
[2012/11/14 14:33:19 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/11/14 12:37:46 | 000,127,032 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\Joint Marketing Needs.pdf
[2012/11/14 03:01:33 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/14 03:01:21 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/13 14:44:00 | 000,089,971 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\tax_issues4_pscs.pdf
[2012/11/13 14:09:12 | 000,121,293 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\LOI ELCO EXCEED LIFE.pdf
[2012/11/12 17:02:54 | 000,000,925 | —- | C] () – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Yammer.lnk
[2012/11/12 17:02:49 | 000,000,829 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yammer.lnk
[2012/11/12 17:02:49 | 000,000,817 | —- | C] () – C:\Users\Public\Desktop\Yammer.lnk
[2012/11/12 13:28:11 | 000,078,639 | —- | C] () – C:\Users\kendrabish.DOMAIN\Desktop\FL 12-23 Medical Expense Consideration.pdf
[2012/11/10 14:02:38 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/11/10 14:02:38 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/11/10 14:02:38 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/11/10 14:02:38 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/11/10 14:02:38 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/11/09 19:12:15 | 000,001,441 | —- | C] () – C:\scu.dat
[2012/08/15 09:48:54 | 000,000,127 | —- | C] () – C:\Windows\System32\MRT.INI
[2012/04/04 14:14:51 | 000,312,104 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2012/03/14 06:32:50 | 000,000,132 | —- | C] () – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/03/09 17:12:09 | 000,000,530 | —- | C] () – C:\Windows\hpwmdl25.dat.temp
[2012/03/09 17:01:39 | 000,000,160 | —- | C] () – C:\Windows\WININIT.INI
[2012/02/27 08:52:02 | 000,183,416 | —- | C] () – C:\Windows\hpwins25.dat
[2012/02/27 08:52:02 | 000,000,530 | —- | C] () – C:\Windows\hpwmdl25.dat
[2012/02/24 11:04:23 | 000,005,178 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2012/02/24 11:01:56 | 000,000,158 | —- | C] () – C:\Windows\ricdb.ini
[2012/02/24 10:45:56 | 000,000,161 | —- | C] () – C:\Windows\DISPARAM.INI
[2012/02/24 10:03:46 | 000,704,512 | R— | C] () – C:\Windows\System32\cohelper.dll
[2012/02/24 10:03:46 | 000,005,940 | R— | C] () – C:\Windows\System32\drivers\nvphy.bin

========== ZeroAccess Check ==========

[2009/07/13 22:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 22:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 15:29:20 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 19:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/05/22 16:12:35 | 000,000,000 | —D | M] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Ad-Aware Antivirus
[2012/11/28 07:27:23 | 000,000,000 | —D | M] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Dropbox
[2012/11/28 14:18:26 | 000,000,000 | —D | M] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\FileZilla
[2012/03/13 05:58:44 | 000,000,000 | —D | M] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Fujitsu
[2012/11/10 14:12:42 | 000,000,000 | —D | M] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Panda Security
[2012/03/13 06:26:34 | 000,000,000 | —D | M] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\PFU
[2012/11/12 17:02:51 | 000,000,000 | —D | M] – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Yammer

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/04/18 09:20:39 | 000,022,492 | —- | M] () – C:\0x0409.ini
[2012/04/18 09:20:39 | 000,013,824 | —- | M] () – C:\1033.MST
[2011/04/14 09:28:27 | 000,000,832 | —- | M] () – C:\Attorney Shipping Label.LWL
[2009/06/10 15:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2012/11/14 14:18:26 | 000,019,669 | —- | M] () – C:\ComboFix.txt
[2009/06/10 15:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/11/28 03:16:04 | 2616,696,832 | -HS- | M] () – C:\hiberfil.sys
[2012/11/28 03:16:05 | 3488,931,840 | -HS- | M] () – C:\pagefile.sys
[2012/11/09 19:34:03 | 000,001,441 | —- | M] () – C:\scu.dat
[2012/04/18 09:20:41 | 009,415,680 | —- | M] () – C:\Splashtop Streamer.msi
[2012/10/03 10:11:50 | 000,133,746 | —- | M] () – C:\TDSSKiller.2.8.10.0_03.10.2012_11.11.36_log.txt
[2012/11/05 15:01:26 | 000,137,112 | —- | M] () – C:\TDSSKiller.2.8.13.0_05.11.2012_15.01.06_log.txt
[2012/11/05 15:01:33 | 000,000,358 | —- | M] () – C:\TDSSKiller.2.8.13.0_05.11.2012_15.01.31_log.txt
[2012/11/05 15:02:14 | 000,135,388 | —- | M] () – C:\TDSSKiller.2.8.15.0_05.11.2012_15.02.03_log.txt
[2012/11/28 15:36:09 | 000,139,218 | —- | M] () – C:\TDSSKiller.2.8.15.0_28.11.2012_15.35.58_log.txt

< %systemroot%\Fonts\*.com >
[2009/07/13 22:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/05/18 10:33:50 | 000,319,488 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpfpp02t.dll
[2009/07/13 19:15:26 | 000,280,064 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzppw71.dll
[2009/07/13 19:15:26 | 000,090,624 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPWN7.DLL
[2009/07/13 19:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 15:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 22:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2012/02/24 10:43:21 | 000,036,962 | RHS- | M] () – C:\Program Files\DLS8Uninstall.log

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/09 17:06:45 | 000,000,221 | -HS- | M] () – C:\Users\kendrabish.DOMAIN\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/11/28 12:38:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\kendrabish.DOMAIN\Desktop\HiJackThis.exe
[2012/11/28 12:36:30 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\kendrabish.DOMAIN\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-11-28 09:00:23

< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:57:04 PM, on 11/28/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Windows\SSDriver\fi5110\SsWiaChecker.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Panda Security\WAC\PSUAMain.exe
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe
C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe
C:\Users\kendrabish.DOMAIN\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Yammer\Yammer.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\WTablet\TabUserW.exe
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\AcroTray.exe
C:\Program Files\Panda Cloud Systems Management\Gui.exe
C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
C:\Windows\system32\rdpclip.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\kendrabish.DOMAIN\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:5555
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [ScanSnap WIA Service Checker] C:\Windows\SSDriver\fi5110\SsWiaChecker.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [PSUAMain] "C:\Program Files\Panda Security\WAC\PSUAMain.exe" /LaunchSysTray
O4 - HKLM\..\Run: [Panda Cloud Systems Management] C:\Program Files\Panda Cloud Systems Management\Gui.exe
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - Startup: Dropbox.lnk = C:\Users\kendrabish.DOMAIN\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Yammer.lnk = C:\Program Files\Yammer\Yammer.exe
O4 - Global Startup: CardMinder Viewer.lnk = ?
O4 - Global Startup: Conversion to PDF with ScanSnap Organizer.lnk = ?
O4 - Global Startup: ScanSnap Manager.lnk = C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DOMAIN.com
O17 - HKLM\Software\..\Telephony: DomainName = DOMAIN.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = DOMAIN.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = DOMAIN.com
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Panda Cloud Systems Management (CagService) - CentraStage - C:\Program Files\Panda Cloud Systems Management\CagService.exe
O23 - Service: DYMO PnP Service (DymoPnpService) - Sanford, L.P. - C:\Program Files\DYMO\DYMO Label Software\DymoPnpService.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Panda Endpoint Protection Service (NanoServiceMain) - Panda Security, S.L. - C:\Program Files\Panda Security\WAC\PSANHost.exe
O23 - Service: Panda Product Service (PSUAService) - Panda Security, S.L. - C:\Program Files\Panda Security\WAC\PSUAService.exe
O23 - Service: Splashtop® Remote Service (SplashtopRemoteService) - Splashtop Inc. - C:\Program Files\Splashtop\Splashtop Remote\Server\SRService.exe
O23 - Service: Splashtop Software Updater Service (SSUService) - Splashtop Inc. - C:\Program Files\Splashtop\Splashtop Software Updater\SSUService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\Windows\system32\Tablet.exe
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\Panda Cloud Systems Management\UltraVNC\winvnc.exe
O23 - Service: Panda Endpoint Administration Agent (WAHost) - Unknown owner - C:\Program Files\Panda Security\WaAgent\WAHost\WAHost.exe

–
End of file - 7666 bytesDDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 10.9.2
Run by [removed] at 15:47:10 on 2012-11-28
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3327.1155 [GMT -6:00]
.
AV: Panda Endpoint Protection *Enabled/Updated* {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
SP: Panda Endpoint Protection *Enabled/Updated* {8F3797EF-DB90-F073-3C72-40C753554CD1}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Panda Endpoint Protection Firewall *Disabled* {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\DYMO\DYMO Label Software\DymoPnpService.exe
C:\Program Files\Panda Security\WAC\PSANHost.exe
C:\Program Files\Panda Security\WAC\PSUAService.exe
C:\Program Files\Splashtop\Splashtop Remote\Server\SRService.exe
C:\Program Files\Splashtop\Splashtop Software Updater\SSUService.exe
C:\Windows\system32\Tablet.exe
C:\Program Files\Panda Security\WaAgent\WAHost\WAHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Windows\SSDriver\fi5110\SsWiaChecker.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Panda Security\WAC\PSUAMain.exe
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe
C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe
C:\Users\kendrabish.DOMAIN\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Yammer\Yammer.exe
C:\Program Files\Splashtop\Splashtop Remote\Server\SRServer.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Splashtop\Splashtop Remote\Server\SRFeature.exe
C:\Windows\system32\WTablet\TabUserW.exe
C:\Windows\system32\Tablet.exe
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Splashtop\Splashtop Remote\Server\DataProxy.exe
C:\Windows\system32\conhost.exe
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Users\kendrabish.DOMAIN\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\AcroTray.exe
C:\Program Files\Panda Cloud Systems Management\CagService.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Panda Cloud Systems Management\Gui.exe
C:\Program Files\Panda Cloud Systems Management\UltraVNC\winvnc.exe
C:\Program Files\Panda Cloud Systems Management\UltraVNC\winvnc.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k swprv
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/reader/view/?hl=en#overview-page
uProxyServer = 127.0.0.1:5555
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [iCloudServices] c:\program files\common files\apple\internet services\iCloudServices.exe
mRun: [HDAudDeck] c:\program files\via\viaudioi\vdeck\VDeck.exe -r
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [ScanSnap WIA Service Checker] c:\windows\ssdriver\fi5110\SsWiaChecker.exe
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [PSUAMain] "c:\program files\panda security\wac\PSUAMain.exe" /LaunchSysTray
mRun: [Panda Cloud Systems Management] c:\program files\panda cloud systems management\Gui.exe
StartupFolder: c:\users\kendra~1.med\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\kendrabish.DOMAIN\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\kendra~1.med\appdata\roaming\micros~1\windows\startm~1\programs\startup\yammer.lnk - c:\program files\yammer\Yammer.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cardmi~1.lnk - c:\program files\pfu\scansnap\cardminder\CardLauncher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\conver~1.lnk - c:\program files\pfu\scansnap\organizer\PfuSsOrgOcrChk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\scansn~1.lnk - c:\program files\pfu\scansnap\driver\PfuSsMon.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~1\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\micros~1\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
Trusted Zone: citrix
TCP: NameServer = 192.168.1.15
TCP: Interfaces\{238663BF-CCDA-4D9B-A751-CD2220CDD6C3} : DHCPNameServer = 192.168.1.15
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\kendrabish.DOMAIN\appdata\roaming\mozilla\firefox\profiles\nmd92tf2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.DOMAIN.com/Admin/UserAccounts/tabid/43/filter/Unauthorized/currentpage/1/Default.aspx|http://ui.benchmarkemail.com/Contacts/Add/Detail?4gcr%2FApPM0I%2BU2bszJyvrnAly0nRoqMZNyIeD9VsXLU%3D
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\progra~1\micros~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\adobe\oobe\pdapp\ccm\utilities\npAdobeAAMDetect32.dll
FF - plugin: c:\program files\common files\adobe\oobe\pdapp\ccm\utilities\npAdobeAAMDetect64.dll
FF - plugin: c:\program files\dymo\dymo label software\framework\npDYMOLabelFramework.dll
FF - plugin: c:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\users\kendrabish.DOMAIN\appdata\local\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_110.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PSINDvct;Device control Driver;c:\windows\system32\drivers\PSINDvct.sys [2012-11-27 42808]
R1 NNSALPC;NNSALPC;c:\windows\system32\drivers\NNSAlpc.sys [2012-8-7 82472]
R1 NNSHTTP;NNSHTTP;c:\windows\system32\drivers\NNSHttp.sys [2012-8-7 120744]
R1 NNSIDS;NNSIDS;c:\windows\system32\drivers\NNSIds.sys [2012-8-23 123688]
R1 NNSPICC;NNSPICC;c:\windows\system32\drivers\NNSpicc.sys [2012-8-7 93992]
R1 NNSPOP3;NNSPOP3;c:\windows\system32\drivers\NNSPop3.sys [2012-8-7 104104]
R1 NNSPROT;NNSPROT;c:\windows\system32\drivers\NNSProt.sys [2012-8-7 286376]
R1 NNSPRV;NNSPRV;c:\windows\system32\drivers\NNSPrv.sys [2012-8-7 155048]
R1 NNSSMTP;NNSSMTP;c:\windows\system32\drivers\NNSSmtp.sys [2012-8-7 106536]
R1 NNSSTRM;NNSSTRM;c:\windows\system32\drivers\NNSStrm.sys [2012-8-7 206632]
R1 NNSTLSC;NNSTLSC;c:\windows\system32\drivers\NNStlsc.sys [2012-8-7 92840]
R1 PSINKNC;PSINKNC;c:\windows\system32\drivers\PSINKNC.sys [2012-6-6 175144]
R2 CagService;Panda Cloud Systems Management;c:\program files\panda cloud systems management\CagService.exe [2012-10-14 7680]
R2 dvctprov;dvctprov;c:\windows\system32\drivers\dvctprov.sys [2012-6-4 95344]
R2 DymoPnpService;DYMO PnP Service;c:\program files\dymo\dymo label software\DymoPnpService.exe [2012-1-30 32336]
R2 NanoServiceMain;Panda Endpoint Protection Service;c:\program files\panda security\wac\PSANHost.exe [2012-8-27 140064]
R2 PSINAflt;PSINAflt;c:\windows\system32\drivers\PSINAflt.sys [2012-8-1 148520]
R2 PSINFile;PSINFile;c:\windows\system32\drivers\PSINFile.sys [2012-8-1 104488]
R2 PSINProc;PSINProc;c:\windows\system32\drivers\PSINProc.sys [2012-6-6 114728]
R2 PSINProt;PSINProt;c:\windows\system32\drivers\PSINProt.sys [2012-6-6 121384]
R2 PSUAService;Panda Product Service;c:\program files\panda security\wac\PSUAService.exe [2012-6-7 39200]
R2 SplashtopRemoteService;Splashtop® Remote Service;c:\program files\splashtop\splashtop remote\server\SRService.exe [2012-6-15 548264]
R2 SSUService;Splashtop Software Updater Service;c:\program files\splashtop\splashtop software updater\SSUService.exe [2012-3-14 370504]
R2 uvnc_service;uvnc_service;c:\program files\panda cloud systems management\ultravnc\winvnc.exe -service –> c:\program files\panda cloud systems management\ultravnc\winvnc.exe -service [?]
R2 WAHost;Panda Endpoint Administration Agent;c:\program files\panda security\waagent\wahost\WAHost.exe [2012-10-5 558368]
R3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.1.361.0\SeaPort.EXE [2012-2-10 240408]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2012-3-14 1108480]
S2 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.1.361.0\BBSvc.EXE [2012-2-10 193816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AMBFilt;AMBFilt;c:\windows\system32\drivers\Ambfilt.sys [2012-3-14 1656960]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-11 62464]
S3 NNSNAHS;Network Activity Hook Server Service;c:\windows\system32\drivers\NNSNAHS.sys [2012-7-16 38696]
S3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [2012-8-15 21992]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-2-24 1343400]
S4 Fitbit;Fitbit Data Uploader;c:\program files\fitbit\fitbit.exe [2012-8-15 770080]
S4 NNSPIHS;NNSPIHS;c:\windows\system32\drivers\NNSpihs.sys [2012-8-7 51496]
S4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-7-14 239648]
S4 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
.
=============== File Associations ===============
.
ShellExec: dreamweaver.exe: Open="c:\program files\adobe\adobe dreamweaver cs5.5\dreamweaver.exe", "%1"
.
=============== Created Last 30 ================
.
2012-11-28 17:07:39 ——– d—–w- c:\users\kendrabish.DOMAIN\appdata\local\CentraStage
2012-11-28 17:07:38 ——– d—–w- c:\programdata\CentraStage
2012-11-28 17:07:25 ——– d—–w- c:\program files\Panda Cloud Systems Management
2012-11-28 09:43:52 60872 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{552c2117-3b9d-447a-b27b-c0235758e4b3}\offreg.dll
2012-11-28 09:16:22 46280 —-a-w- c:\windows\system32\drivers\PSKMAD.sys
2012-11-27 13:28:09 42808 —-a-w- c:\windows\system32\drivers\PSINDvct.sys
2012-11-27 10:57:07 6812136 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{552c2117-3b9d-447a-b27b-c0235758e4b3}\mpengine.dll
2012-11-26 22:14:42 105692 —-a-w- c:\programdata\microsoft\windows defender\localcopy\{C9631808-5846-747F-D071-FEDA2ACF94E8}-Uninstall.exe
2012-11-25 18:13:17 ——– d—–r- c:\users\kendrabish.DOMAIN\Dropbox
2012-11-25 18:09:44 ——– d—–w- c:\users\kendrabish.DOMAIN\appdata\roaming\Dropbox
2012-11-14 22:18:48 ——– d—–w- c:\programdata\regid.1986-12.com.adobe
2012-11-14 20:36:19 ——– d—–w- c:\users\kendrabish.DOMAIN\appdata\local\Apple Computer
2012-11-14 20:33:19 ——– d—–w- c:\users\kendrabish.DOMAIN\appdata\local\Apple
2012-11-14 20:33:12 ——– d—–w- c:\program files\Bonjour
2012-11-14 20:17:56 ——– d-sh–w- C:\$RECYCLE.BIN
2012-11-14 05:11:55 156672 —-a-w- c:\windows\system32\ncsi.dll
2012-11-14 05:11:54 52224 —-a-w- c:\windows\system32\nlaapi.dll
2012-11-14 05:11:54 499712 —-a-w- c:\windows\system32\iphlpsvc.dll
2012-11-14 05:11:54 35328 —-a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-11-14 05:11:54 242176 —-a-w- c:\windows\system32\nlasvc.dll
2012-11-14 05:11:54 18944 —-a-w- c:\windows\system32\netevent.dll
2012-11-14 05:11:54 175104 —-a-w- c:\windows\system32\netcorehc.dll
2012-11-14 05:11:54 1293680 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-11-14 05:11:53 78336 —-a-w- c:\windows\system32\synceng.dll
2012-11-14 05:11:51 44032 —-a-w- c:\windows\system32\dhcpcsvc6.dll
2012-11-14 05:11:51 2345984 —-a-w- c:\windows\system32\win32k.sys
2012-11-14 05:11:51 193536 —-a-w- c:\windows\system32\dhcpcore6.dll
2012-11-12 23:02:51 ——– d—–w- c:\users\kendrabish.DOMAIN\appdata\roaming\Yammer
2012-11-12 23:02:48 ——– d—–w- c:\program files\Yammer
2012-11-10 20:12:42 ——– d—–w- c:\users\kendrabish.DOMAIN\appdata\roaming\Panda Security
2012-11-10 20:12:14 ——– d—–w- c:\programdata\Panda Security
2012-11-10 20:12:14 ——– d—–w- c:\program files\Panda Security
2012-11-10 20:02:38 98816 —-a-w- c:\windows\sed.exe
2012-11-10 20:02:38 256000 —-a-w- c:\windows\PEV.exe
2012-11-10 20:02:38 208896 —-a-w- c:\windows\MBR.exe
2012-11-10 01:09:40 ——– d—–w- c:\program files\ESET
2012-11-05 21:07:17 ——– d—–w- c:\users\kendrabish.DOMAIN\appdata\roaming\Malwarebytes
2012-11-05 21:07:11 ——– d—–w- c:\programdata\Malwarebytes
2012-11-05 21:05:50 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
.
==================== Find3M ====================
.
2012-11-10 02:01:50 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-10 02:01:50 697272 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-05 21:05:46 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-10-16 07:39:52 561664 —-a-w- c:\windows\apppatch\AcLayers.dll
2012-10-08 07:56:24 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-10-08 07:48:03 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-10-08 07:47:44 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-10-08 07:44:05 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-10-08 07:43:21 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-10-08 07:40:56 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-09-14 18:28:53 2048 —-a-w- c:\windows\system32\tzres.dll
2012-09-05 13:14:01 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-08-31 17:18:09 1211760 —-a-w- c:\windows\system32\drivers\ntfs.sys
.
============= FINISH: 15:47:21.37 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2/24/2012 9:46:00 AM
System Uptime: 11/28/2012 3:16:00 AM (12 hours ago)
.
Motherboard: ASRock | | N68C-S UCC
Processor: AMD Athlon™ II X2 260 Processor | CPUSocket | 3200/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 112 GiB total, 29.946 GiB free.
D: is CDROM ()
E: is CDROM ()
H: is NetworkDisk (NTFS) - 200 GiB total, 103.151 GiB free.
Y: is NetworkDisk (NTFS) - 200 GiB total, 85.218 GiB free.
Z: is NetworkDisk (NTFS) - 52 GiB total, 26.433 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: SBRE
Device ID: ROOT\LEGACY_SBRE\0000
Manufacturer:
Name: SBRE
PNP Device ID: ROOT\LEGACY_SBRE\0000
Service: SBRE
.
Class GUID:
Description:
Device ID: ROOT\HIDCLASS\0000
Manufacturer:
Name:
PNP Device ID: ROOT\HIDCLASS\0000
Service:
.
Class GUID:
Description:
Device ID: ROOT\HIDCLASS\0001
Manufacturer:
Name:
PNP Device ID: ROOT\HIDCLASS\0001
Service:
.
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: Hewlett-Packard
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
.
==== System Restore Points ===================
.
RP136: 11/14/2012 2:33:21 PM - Installed iCloud
RP137: 11/17/2012 1:00:09 AM - Windows Backup
RP138: 11/20/2012 5:29:53 AM - Windows Update
RP139: 11/24/2012 1:00:10 AM - Windows Backup
RP140: 11/26/2012 4:06:21 PM - Installed Panda Endpoint Agent.
RP141: 11/27/2012 4:57:00 AM - Windows Update
RP142: 11/28/2012 3:00:11 AM - Windows Update
RP143: 11/28/2012 3:41:53 PM - OTL Restore Point - 11/28/2012 3:41:52 PM
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
7000E809a_BasicWeb
7000E809a_Help_BasicWeb
ABBYY FineReader for ScanSnap ™ 4.1
Adobe Acrobat 9 Pro - English, Français, Deutsch
Adobe Acrobat X Pro - English, Français, Deutsch
Adobe After Effects CS4
Adobe After Effects CS4 Presets
Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color Video Profiles AE CS4
Adobe Community Help
Adobe Content Viewer
Adobe Creative Suite 4 Design Standard
Adobe Creative Suite 5.5 Design Premium
Adobe CS4 American English Speech Analysis Models
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Download Assistant
Adobe Dynamiclink Support
Adobe Encore CS4
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Fonts All
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Additional Exporter
Adobe Media Encoder CS4 Dolby
Adobe Media Player
Adobe MotionPicture Color Files CS4
Adobe OnLocation CS4
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Premiere Pro CS4
Adobe Premiere Pro CS4 Functional Content
Adobe Reader X
Adobe Reader X (10.1.4)
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe Widget Browser
Adobe XMP Panels CS4
Advisors Assistant
Apple Application Support
Apple Software Update
Bing Bar
Bonjour
BPDSoftware_Ini
CardMinder
CardMinder V4.1
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dropbox
DYMO Label v.8
ELCO SPWL-TI
ESET Online Scanner v3
FileZilla Client 3.6.0.1
Fitbit v2.1.0.8
Google Chrome
GoToMeeting 5.1.0.880
HiJackThis
HP Officejet 7000 E809a Series
iCloud
Japanese Fonts Support For Adobe Reader X
Java 7 Update 9
Java Auto Updater
join.me
menu.EXE
Microsoft .NET Framework 4 Client Profile
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Microsoft_VC90_MFCLOC_x86
Mozilla Firefox 16.0.2 (x86 en-US)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Network
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA Stereoscopic 3D Driver
Panda Cloud Systems Management
Panda Endpoint Agent
Panda Endpoint Protection
PDF Settings CS5
Photoshop Camera Raw
Pixel Bender Toolkit
Platform
PowerISO
Premiere Pro CS4 and After Effects CS4, 32-bit support for CS5
Presidential Life Insurance Desk
ScanSnap
ScanSnap Manager
ScanSnap Organizer
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589322) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB2553488) 32-Bit Edition
Splashtop Streamer
Suite Shared Configuration CS4
Tablet
taskmgr.exe
Toolbox
TweetDeck
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553272) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
Variable SPIA
VIA Platform Device Manager
WebReg
Windows Live ID Sign-in Assistant
WinRAR archiver
Yammer
.
==== Event Viewer Messages From Past Week ========
.
11/28/2012 3:16:58 AM, Error: Service Control Manager [7023] - The Superfetch service terminated with the following error: The system cannot find the file specified.
11/28/2012 3:16:25 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SBRE
11/27/2012 7:28:04 AM, Error: Service Control Manager [7030] - The Panda Endpoint Protection Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
11/25/2012 12:23:37 PM, Error: Microsoft-Windows-TerminalServices-Printers [1111] - Driver Send To Microsoft OneNote 2010 Driver required for printer Send To OneNote 2010 is unknown. Contact the administrator to install the driver before you log in again.
11/21/2012 7:37:51 PM, Error: TermDD [56] - The Terminal Server security layer detected an error in the protocol stream and has disconnected the client. Client IP: 72.133.47.178.
11/21/2012 7:37:51 PM, Error: NETLOGON [5719] - This computer was not able to set up a secure session with a domain controller in domain DOMAIN due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.
.
==== End Of File ===========================

Once more thanks so much!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI