This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need help removing svchost.exe trojan agent [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello WhatTheTech friends, Firstly - happy holidays and best wishes in the new year. My Windows7 Ultimate (64bit) started acting up resently. Slow to boot, and randomly crashing before Windows7 fully starts (it gets up to my desktop and then blue screens). I instead booted into safe mode and ran msconfig in order to shut down all non system startup services. I rebooted and was able to restart into a normal Windows7 session. I ran Malwarebytes and it found 2 infection files called Trojan.Agent - C:\Windows\svchost.exe. It can not be removes by Malwarebytes, as it just keeps coming back everytime I do another scan. Can you please help me remove this, and any other malware on my machine. I downloaded DDS and below is the copy/paste of the dds.txt Thank you in advance =============================================== DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2 Run by [removed] at 23:44:28 on 2012-12-21 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3327.922 [GMT -5:00] . AV: Spyware Doctor with AntiVirus *Enabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Spyware Doctor *Enabled/Outdated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Windows\SysWOW64\astsrv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation \\.\globalroot\systemroot\svchost.exe -netsvcs C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe C:\Program Files (x86)\PC Tools Security\pctsSvc.exe C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe C:\Program Files (x86)\PC Tools Security\pctsGui.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe C:\Program Files (x86)\VIA\RAID\vialogsv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k HPService C:\Program Files\Microsoft Security Client\NisSrv.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\SOUNDMAN.EXE C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files (x86)\Kensington\TrackballWorks\TbwHelper.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Windows\SysWOW64\RunDll32.exe C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files (x86)\Nero\Update\NASvc.exe C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe C:\Program Files (x86)\RocketDock\RocketDock.exe C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft Security Client\MpCmdRun.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uURLSearchHooks: {472734EA-242A-422b-ADF8-83D1E48CC825} - BHO: Octh Class: {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll BHO: SnagIt Toolbar Loader: {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItBHO.dll BHO: ContributeBHO Class: {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB: WOT: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll TB: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB: Contribute Toolbar: {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll TB: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll TB: SnagIt: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItIEAddin.dll TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - EB: : {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - EB: : {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - uRun: [Kensington TrackballWorks] "C:\Program Files (x86)\Kensington\TrackballWorks\TbwHelper.exe" mRun: [ISTray] "C:\Program Files (x86)\PC Tools Security\pctsGui.exe" /hideGUI mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [Adobe_ID0ENQBO] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" mRun: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide mRun: [Kensington TrackballWorks Helper] C:\Program Files (x86)\Kensington\TrackballWorks\TbwHelper.exe mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/201 IE: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/204 IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200 IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/202 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm DPF: {298BFFEE-662D-11D5-ADAF-00E0810232D7} - hxxps://simulcast.manheim.com/simulcast_docs/av/LiveSound.dll DPF: {7206EAAC-5CFA-43A3-9F61-E27E8E51E42F} - hxxp://adus1.liveblockauctions.com/container_repository/laiexec.cab DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://imageupload9.autorevo.com/Cabs/ImageUploader6.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=724 TCP: NameServer = 192.168.2.1 TCP: Interfaces\{94B18308-8489-4019-A093-568B88D4D8C3} : DHCPNameServer = 192.168.2.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll x64-BHO: SnagIt Toolbar Loader: {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\SnagIt 8\DLLx64\SnagItBHO64.dll x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll x64-TB: SnagIt: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\DLLx64\SnagItIEAddin64.dll x64-Run: [SoundMan] SOUNDMAN.EXE x64-Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe" x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey x64-Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - x64-Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Laurent Effen Rocks\AppData\Roaming\Mozilla\Firefox\Profiles\mkcyav34.default\ FF - prefs.js: browser.startup.homepage - google.com FF - plugin: C:\Program Files (x86)\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Laurent Effen Rocks\AppData\Local\Roblox\Versions\version-322083e762564446\NPRobloxProxy.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll . ============= SERVICES / DRIVERS =============== . R0 fltsrv;Acronis Storage Filter Management;C:\Windows\System32\drivers\fltsrv.sys [2012-1-24 133728] R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2012-8-30 228768] R0 PCTCore;PCTools KDS;C:\Windows\System32\drivers\PCTCore64.sys [2011-2-13 257232] R0 pctDS;PC Tools Data Store;C:\Windows\System32\drivers\pctDS64.sys [2011-2-13 452872] R0 pctEFA;PC Tools Extended File Attributes;C:\Windows\System32\drivers\pctEFA64.sys [2011-2-13 816016] R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-2-14 54480] R0 vidsflt61;Acronis Disk Storage Filter (61);C:\Windows\System32\drivers\vsflt61.sys [2012-1-24 142944] R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-12-8 375728] R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2010-9-17 15928] R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2011-2-13 72216] R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2009-10-7 191000] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-3-29 598312] R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2010-10-24 128456] R2 PassThru Service;Internet Pass-Through Service;C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-3-31 80896] R2 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe [2011-2-13 366840] R2 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\PC Tools Security\pctsSvc.exe [2011-2-13 1150936] R2 VRAID Log Service;VRAID Log Service;C:\Program Files (x86)\VIA\RAID\vialogsv.exe [2011-5-10 52888] R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE [2012-2-10 240408] R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2009-10-7 30232] R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-9-12 368896] R3 nvoclk64;NVIDIA Enthusiasts Platform KDM;C:\Windows\System32\drivers\nvoclk64.sys [2009-9-15 42088] R3 tbwkern;Kensington TrackballWorks driver;C:\Windows\System32\drivers\tbwkern.sys [2011-6-13 32848] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264] S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE [2012-2-10 193816] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944] S3 Adobe Version Cue CS4;Adobe Version Cue CS4;C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-8-15 284016] S3 btwampfl;Bluetooth AMP USB Filter;C:\Windows\System32\drivers\btwampfl.sys [2011-2-20 319016] S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-2-20 39464] S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2012-8-11 16776] S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2012-8-11 9096] S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-2-13 1038088] S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-2-13 48488] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352] S3 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2009-11-1 33736] S3 htcnprot;HTC NDIS Protocol Driver;C:\Windows\System32\drivers\htcnprot.sys [2010-6-25 36928] S3 lvpepf64;Volume Adapter;C:\Windows\System32\drivers\lv302a64.sys [2011-2-13 15896] S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2011-2-13 327576] S3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\System32\drivers\LVUSBS64.sys [2008-7-26 50072] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-12-14 19456] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-12-14 57856] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-2-7 1255736] . =============== File Associations =============== . ShellExec: dreamweaver.exe: Open="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS4\dreamweaver.exe", "%1" . =============== Created Last 30 ================ . 2012-12-22 01:59:12 ——– d—–w- C:\Windows\Microsoft Antimalware 2012-12-21 22:12:06 9125352 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{82298DE7-783B-4C23-8F4E-774E8E984B79}\mpengine.dll 2012-12-21 16:41:21 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2012-12-21 16:40:11 ——– d—–w- C:\Program Files\iPod 2012-12-21 16:40:10 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-21 16:40:10 ——– d—–w- C:\Program Files\iTunes 2012-12-21 16:40:10 ——– d—–w- C:\Program Files (x86)\iTunes 2012-12-21 16:34:36 ——– d—–w- C:\Program Files\Bonjour 2012-12-21 16:34:36 ——– d—–w- C:\Program Files (x86)\Bonjour 2012-12-21 16:09:54 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2012-12-21 16:09:54 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2012-12-21 16:09:54 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2012-12-21 16:09:54 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2012-12-21 16:09:54 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2012-12-21 16:09:54 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2012-12-21 16:09:54 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2012-12-21 15:48:20 9125352 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-12-21 01:16:58 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2012-12-21 01:16:57 46080 —-a-w- C:\Windows\System32\atmlib.dll 2012-12-21 01:16:56 367616 —-a-w- C:\Windows\System32\atmfd.dll 2012-12-21 01:16:55 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll 2012-12-15 05:09:16 99384 —-a-w- C:\Users\Laurent Effen Rocks\AppData\Roaming\inst.exe 2012-12-15 04:05:02 3584 —-a-w- C:\Windows\System32\drivers\es-ES\tsusbflt.sys.mui 2012-12-15 04:05:02 3072 —-a-w- C:\Windows\System32\drivers\en-US\tsusbflt.sys.mui 2012-12-15 04:05:01 15360 —-a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll 2012-12-15 04:05:01 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll 2012-12-15 04:05:01 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe 2012-12-15 04:03:36 458712 —-a-w- C:\Windows\System32\drivers\cng.sys 2012-12-15 04:03:36 340992 —-a-w- C:\Windows\System32\schannel.dll 2012-12-15 04:03:36 307200 —-a-w- C:\Windows\System32\ncrypt.dll 2012-12-15 04:03:36 247808 —-a-w- C:\Windows\SysWow64\schannel.dll 2012-12-15 04:03:36 154480 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys 2012-12-15 04:03:35 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll 2012-12-15 04:03:35 220160 —-a-w- C:\Windows\SysWow64\ncrypt.dll 2012-12-15 04:03:35 22016 —-a-w- C:\Windows\SysWow64\secur32.dll 2012-12-15 04:03:35 1448448 —-a-w- C:\Windows\System32\lsasrv.dll 2012-12-15 02:38:25 ——– d—–w- C:\Users\Laurent Effen Rocks\AppData\Local\LogMeIn Rescue Applet 2012-12-12 11:57:50 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2012-12-12 11:57:50 2048 —-a-w- C:\Windows\System32\tzres.dll 2012-12-12 11:57:17 3149824 —-a-w- C:\Windows\System32\win32k.sys 2012-12-12 11:55:33 478208 —-a-w- C:\Windows\System32\dpnet.dll 2012-12-12 11:55:33 376832 —-a-w- C:\Windows\SysWow64\dpnet.dll 2012-12-10 19:14:23 20480 —-a-w- C:\Windows\svchost.exe 2012-11-28 06:35:48 972264 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{7E43FE1A-E0BF-49C2-AEB1-3FDFDA8CAC0F}\gapaengine.dll . ==================== Find3M ==================== . 2012-12-19 01:52:12 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-19 01:52:12 697272 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-12-15 05:09:16 82816 —-a-w- C:\Users\Laurent Effen Rocks\AppData\Roaming\pcouffin.sys 2012-11-14 06:11:44 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2012-11-14 06:04:11 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-11-14 06:02:49 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-11-14 05:57:46 599040 —-a-w- C:\Windows\System32\vbscript.dll 2012-11-14 05:57:35 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-11-14 05:52:40 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-11-14 02:09:22 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-11-14 01:58:15 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-11-14 01:57:37 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-11-14 01:49:25 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-11-14 01:48:27 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll 2012-11-14 01:44:42 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-11-06 22:00:06 88008 —-a-w- C:\Windows\System32\LMIRfsClientNP.dll 2012-11-06 22:00:05 83880 —-a-w- C:\Windows\System32\LMIinit.dll 2012-11-06 22:00:05 35240 —-a-w- C:\Windows\System32\LMIport.dll 2012-10-25 08:12:26 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2012-10-25 08:12:26 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2012-10-16 08:38:37 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38:34 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39:52 561664 —-a-w- C:\Windows\apppatch\AcLayers.dll 2012-10-09 18:17:13 55296 —-a-w- C:\Windows\System32\dhcpcsvc6.dll 2012-10-09 18:17:13 226816 —-a-w- C:\Windows\System32\dhcpcore6.dll 2012-10-09 17:40:31 44032 —-a-w- C:\Windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40:31 193536 —-a-w- C:\Windows\SysWow64\dhcpcore6.dll 2012-10-04 17:46:16 362496 —-a-w- C:\Windows\System32\wow64win.dll 2012-10-04 17:46:15 243200 —-a-w- C:\Windows\System32\wow64.dll 2012-10-04 17:46:15 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2012-10-04 17:45:55 215040 —-a-w- C:\Windows\System32\winsrv.dll 2012-10-04 17:43:28 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2012-10-04 17:41:16 424960 —-a-w- C:\Windows\System32\KernelBase.dll 2012-10-04 16:47:41 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2012-10-04 16:47:41 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2012-10-04 15:21:55 338432 —-a-w- C:\Windows\System32\conhost.exe 2012-10-04 14:46:46 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2012-10-04 14:46:46 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2012-10-04 14:46:44 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2012-10-04 14:46:43 2048 —-a-w- C:\Windows\SysWow64\user.exe 2012-10-04 14:41:50 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2012-10-04 14:41:50 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2012-10-04 14:41:50 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2012-10-04 14:41:50 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2012-10-03 17:56:54 1914248 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2012-10-03 17:44:21 70656 —-a-w- C:\Windows\System32\nlaapi.dll 2012-10-03 17:44:21 303104 —-a-w- C:\Windows\System32\nlasvc.dll 2012-10-03 17:44:17 246272 —-a-w- C:\Windows\System32\netcorehc.dll 2012-10-03 17:44:17 18944 —-a-w- C:\Windows\System32\netevent.dll 2012-10-03 17:44:16 216576 —-a-w- C:\Windows\System32\ncsi.dll 2012-10-03 17:42:16 569344 —-a-w- C:\Windows\System32\iphlpsvc.dll 2012-10-03 16:42:24 18944 —-a-w- C:\Windows\SysWow64\netevent.dll 2012-10-03 16:42:24 175104 —-a-w- C:\Windows\SysWow64\netcorehc.dll 2012-10-03 16:42:23 156672 —-a-w- C:\Windows\SysWow64\ncsi.dll 2012-10-03 16:07:26 45568 —-a-w- C:\Windows\System32\drivers\tcpipreg.sys 2012-09-25 22:47:43 78336 —-a-w- C:\Windows\SysWow64\synceng.dll 2012-09-25 22:46:17 95744 —-a-w- C:\Windows\System32\synceng.dll 2012-09-25 03:16:33 95208 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll . ============= FINISH: 23:47:48.36 ===============
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Hello Jeff, Thank you for helping me with this. I greatly appreciate it. I ran the aswMBR scan, per your instructions. I beleive it also detected 2 files because they were highlighted in red. I couldn't make out the names becasue the string was too long and ran off the screen. Anyways, I attached the resulting logs. WTT only allowed me to upload the .txt file (but not the .dat file). I hope to hear back from you soon with further instructions. ggee
Hello Jeff, Thank you for helping me with this. I greatly appreciate it. I ran the aswMBR scan, per your instructions. I beleive it also detected 2 files because they were highlighted in red. I couldn't make out the names becasue the string was too long and ran off the screen. Anyways, I attached the resulting logs. WTT only allowed me to upload the .txt file (but not the .dat file). I hope to hear back from you soon with further instructions. ggee

Attachments:

FRST

Download the 64 bit version for your system of FRST and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

———-
Hi Jeff, I have an older mother board that does not support booting from a USB. I have an Asus A8V Deluxe. When I press F8, I instead get an option to select what drive to boot from. I do not get an option to run Repair Computer anywhere. If I try to boot using the install disk, I run into a road block when it says I am missing CD/DVD drivers, after selecting language (even though it works if I'm in Win7). We will probably need another option. Now I have to keep trying to start into Win7 again untilled I finally get in (and hope it doesn't crash on me). I'm replying via an android tablet. ggee
Ok….let's do this…

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Hi Jeff, Here is a recap of what my machine is doing: The bios boot is ok and completes fine. The os initial start up is also ok (the black screen with the microsoft logo). The aqua colored Win7 screen starts up, but takes long to complete (the aqua screen with the flower vines and the Windows7 Ultimate logo). I then get to my actual desktop screen, where it takes a long time to load (the rotating circle is spinning on and off). This is the point where my machine craches (blue screen), and starts the whole reboot process again (maybe 9 out of 10 times it crashes). On the times that it actually fully starts, it acts somewhat normal - but it may just randomly shuts down as well. As an alternative option, I can boot to safe mode with networking. From there I do msconfig and shut off all start-up services. In this way when I reboot to normal made, I can get to Win7 with less chance of crashing (which is what I just did now). I made sure to turn off all antivirus software. But my PC Tools Spyware Doctor gave me an "Illegal Operation Attempted On A Registry Key That Has Been Marked For Deletion". So I re-booted per your instructions. I double checked again to make sure any antivirus software was off. I downloaded ran Combofix per your instructions, but it said Spyware Doctor was running (even though I made sure it was off). So I let Combofix run anyways, even though there was a notice saying the results may not be fully accurate. I tought you should know for info purposes. Below is the copy/paste from the ComboFix log (I also attached it just in case you need it): =========================================== ComboFix 12-12-23.01 - Laurent Effen Rocks 12/23/2012 12:43:18.2.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3327.2168 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} AV: Spyware Doctor with AntiVirus *Enabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Kensington\TrackballWorks\TbwHelper.exe c:\users\Laurent Effen Rocks\g2mdlhlpx.exe c:\windows\security\Database\tmp.edb c:\windows\svchost.exe . . ((((((((((((((((((((((((( Files Created from 2012-11-23 to 2012-12-23 ))))))))))))))))))))))))))))))) . . 2012-12-23 17:58 . 2012-12-23 17:58 76232 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A27E0A6A-B61F-4C91-8387-903F76871DD8}\offreg.dll 2012-12-23 17:57 . 2012-12-23 17:57 35664 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A27E0A6A-B61F-4C91-8387-903F76871DD8}\MpKsl4db0bf7f.sys 2012-12-23 17:54 . 2012-12-23 17:54 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-12-23 17:54 . 2012-12-23 17:54 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-12-23 17:54 . 2012-12-23 17:54 ——– d—–w- c:\users\LogMeInRemoteUser\AppData\Local\temp 2012-12-23 17:54 . 2012-12-23 17:54 ——– d—–w- c:\users\Laurent\AppData\Local\temp 2012-12-23 17:54 . 2012-12-23 17:54 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-12-23 17:25 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A27E0A6A-B61F-4C91-8387-903F76871DD8}\mpengine.dll 2012-12-22 01:59 . 2012-12-22 01:59 ——– d—–w- c:\windows\Microsoft Antimalware 2012-12-21 22:12 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-12-21 16:41 . 2012-08-21 18:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-12-21 16:40 . 2012-12-21 16:40 ——– d—–w- c:\program files\iPod 2012-12-21 16:40 . 2012-12-21 16:41 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-21 16:40 . 2012-12-21 16:41 ——– d—–w- c:\program files\iTunes 2012-12-21 16:40 . 2012-12-21 16:41 ——– d—–w- c:\program files (x86)\iTunes 2012-12-21 16:34 . 2012-12-21 16:34 ——– d—–w- c:\program files\Bonjour 2012-12-21 16:34 . 2012-12-21 16:34 ——– d—–w- c:\program files (x86)\Bonjour 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2012-12-21 16:09 . 2012-12-21 16:09 ——– d—–w- c:\program files (x86)\QuickTime 2012-12-21 01:16 . 2012-12-16 14:13 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-21 01:16 . 2012-12-16 17:11 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-21 01:16 . 2012-12-16 14:45 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-21 01:16 . 2012-12-16 14:13 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-15 05:09 . 2012-12-15 05:09 99384 —-a-w- c:\users\Laurent Effen Rocks\AppData\Roaming\inst.exe 2012-12-15 04:05 . 2012-08-23 15:25 3584 —-a-w- c:\windows\system32\drivers\es-ES\tsusbflt.sys.mui 2012-12-15 04:05 . 2012-08-23 15:09 3072 —-a-w- c:\windows\system32\drivers\en-US\tsusbflt.sys.mui 2012-12-15 04:05 . 2012-08-23 13:41 13312 —-a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2012-12-15 04:05 . 2012-08-23 13:40 13312 —-a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2012-12-15 04:05 . 2012-08-23 13:24 15360 —-a-w- c:\windows\system32\RdpGroupPolicyExtension.dll 2012-12-15 04:03 . 2012-08-24 18:13 154480 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-12-15 04:03 . 2012-08-24 18:09 458712 —-a-w- c:\windows\system32\drivers\cng.sys 2012-12-15 04:03 . 2012-08-24 18:05 340992 —-a-w- c:\windows\system32\schannel.dll 2012-12-15 04:03 . 2012-08-24 18:04 307200 —-a-w- c:\windows\system32\ncrypt.dll 2012-12-15 04:03 . 2012-08-24 16:57 247808 —-a-w- c:\windows\SysWow64\schannel.dll 2012-12-15 04:03 . 2012-08-24 18:03 1448448 —-a-w- c:\windows\system32\lsasrv.dll 2012-12-15 04:03 . 2012-08-24 16:57 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2012-12-15 04:03 . 2012-08-24 16:57 220160 —-a-w- c:\windows\SysWow64\ncrypt.dll 2012-12-15 04:03 . 2012-08-24 16:53 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2012-12-15 02:38 . 2012-12-15 05:37 ——– d—–w- c:\users\Laurent Effen Rocks\AppData\Local\LogMeIn Rescue Applet 2012-12-12 11:57 . 2012-11-09 05:45 2048 —-a-w- c:\windows\system32\tzres.dll 2012-12-12 11:57 . 2012-11-09 04:42 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-12-12 11:57 . 2012-11-22 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2012-12-12 11:55 . 2012-11-02 05:59 478208 —-a-w- c:\windows\system32\dpnet.dll 2012-12-12 11:55 . 2012-11-02 05:11 376832 —-a-w- c:\windows\SysWow64\dpnet.dll 2012-11-28 06:35 . 2012-11-28 06:35 972264 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E43FE1A-E0BF-49C2-AEB1-3FDFDA8CAC0F}\gapaengine.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-19 01:52 . 2012-09-09 05:41 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-19 01:52 . 2012-09-09 05:41 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-15 05:09 . 2011-02-07 23:58 82816 —-a-w- c:\users\Laurent Effen Rocks\AppData\Roaming\pcouffin.sys 2012-12-13 08:07 . 2011-02-07 22:58 67413224 —-a-w- c:\windows\system32\MRT.exe 2012-11-06 22:00 . 2011-02-13 21:26 88008 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-11-06 22:00 . 2011-02-13 21:26 35240 —-a-w- c:\windows\system32\LMIport.dll 2012-11-06 22:00 . 2011-02-13 21:26 83880 —-a-w- c:\windows\system32\LMIinit.dll 2012-10-25 08:12 . 2012-10-25 08:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2012-10-25 08:12 . 2012-10-25 08:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts 2012-10-16 08:38 . 2012-11-28 07:49 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-11-28 07:49 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-11-28 07:49 561664 —-a-w- c:\windows\apppatch\AcLayers.dll 2012-10-09 18:17 . 2012-11-14 02:51 55296 —-a-w- c:\windows\system32\dhcpcsvc6.dll 2012-10-09 18:17 . 2012-11-14 02:51 226816 —-a-w- c:\windows\system32\dhcpcore6.dll 2012-10-09 17:40 . 2012-11-14 02:51 44032 —-a-w- c:\windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40 . 2012-11-14 02:51 193536 —-a-w- c:\windows\SysWow64\dhcpcore6.dll 2012-10-04 16:40 . 2012-12-12 11:56 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-10-03 17:56 . 2012-11-14 02:50 1914248 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-10-03 17:44 . 2012-11-14 02:50 303104 —-a-w- c:\windows\system32\nlasvc.dll 2012-10-03 17:44 . 2012-11-14 02:50 70656 —-a-w- c:\windows\system32\nlaapi.dll 2012-10-03 17:44 . 2012-11-14 02:50 246272 —-a-w- c:\windows\system32\netcorehc.dll 2012-10-03 17:44 . 2012-11-14 02:50 18944 —-a-w- c:\windows\system32\netevent.dll 2012-10-03 17:44 . 2012-11-14 02:50 216576 —-a-w- c:\windows\system32\ncsi.dll 2012-10-03 17:42 . 2012-11-14 02:50 569344 —-a-w- c:\windows\system32\iphlpsvc.dll 2012-10-03 16:42 . 2012-11-14 02:50 175104 —-a-w- c:\windows\SysWow64\netcorehc.dll 2012-10-03 16:42 . 2012-11-14 02:50 18944 —-a-w- c:\windows\SysWow64\netevent.dll 2012-10-03 16:42 . 2012-11-14 02:50 156672 —-a-w- c:\windows\SysWow64\ncsi.dll 2012-10-03 16:07 . 2012-11-14 02:50 45568 —-a-w- c:\windows\system32\drivers\tcpipreg.sys 2012-10-02 06:00 . 2011-03-25 06:44 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-09-25 22:47 . 2012-11-14 02:50 78336 —-a-w- c:\windows\SysWow64\synceng.dll 2012-09-25 22:46 . 2012-11-14 02:50 95744 —-a-w- c:\windows\system32\synceng.dll 2012-09-25 03:16 . 2012-10-20 19:47 95208 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-01-31 38840] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-11-30 1120032] HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016] R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408] R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2009-11-30 319016] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-11-18 39464] R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-07-29 16776] R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-07-29 9096] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-02-14 1038088] R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-01 33736] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928] R3 lvpepf64;Volume Adapter;c:\windows\system32\DRIVERS\lv302a64.sys [2009-04-30 15896] R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2009-04-30 327576] R3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\DRIVERS\LVUSBS64.sys [2008-07-26 50072] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896] R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2011-02-07 82816] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-07 1255736] R4 VRAID Log Service;VRAID Log Service;c:\program files (x86)\VIA\RAID\vialogsv.exe [2008-09-24 52888] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys [2012-01-25 133728] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [2010-11-25 257232] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [2010-06-29 452872] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [2010-07-16 816016] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-02-06 54480] S0 vidsflt61;Acronis Disk Storage Filter (61);c:\windows\system32\DRIVERS\vsflt61.sys [2012-01-25 142944] S1 MpKsl4db0bf7f;MpKsl4db0bf7f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A27E0A6A-B61F-4C91-8387-903F76871DD8}\MpKsl4db0bf7f.sys [2012-12-23 35664] S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-11-06 375728] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-09-17 15928] S2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-03-29 598312] S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-03-31 80896] S2 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2010-03-15 366840] S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232] S3 nvoclk64;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\DRIVERS\nvoclk64.sys [2009-09-15 42088] S3 tbwkern;Kensington TrackballWorks driver;c:\windows\system32\DRIVERS\tbwkern.sys [2011-06-13 32848] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264] . . — Other Services/Drivers In Memory — . *NewlyCreated* - MPKSL4DB0BF7F . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-12-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-09 01:52] . 2012-11-25 c:\windows\Tasks\AVSRegistryCleaner.job - c:\program files (x86)\AVS4YOU\AVSRegistryCleaner\AVSRegistryCleaner.exe [2011-08-31 18:15] . 2012-12-22 c:\windows\Tasks\Google Software Updater.job - c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-13 02:32] . 2012-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-21 01:08] . 2012-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-21 01:08] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704] "RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 1289704] "LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2010-09-17 57928] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: &Download by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/201 IE: &Grab video by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/204 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Do&wnload selected by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/202 IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.2.1 DPF: {7206EAAC-5CFA-43A3-9F61-E27E8E51E42F} - hxxp://adus1.liveblockauctions.com/container_repository/laiexec.cab DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://imageupload9.autorevo.com/Cabs/ImageUploader6.cab FF - ProfilePath - c:\users\Laurent Effen Rocks\AppData\Roaming\Mozilla\Firefox\Profiles\mkcyav34.default\ FF - prefs.js: browser.startup.homepage - google.com . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-Kensington TrackballWorks - c:\program files (x86)\Kensington\TrackballWorks\TbwHelper.exe Wow6432Node-HKLM-Run-Kensington TrackballWorks Helper - c:\program files (x86)\Kensington\TrackballWorks\TbwHelper.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90, 43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87 "{517BDDE4-E3A7-4570-B21E-2B52B6139FC7}"=hex:51,66,7a,6c,4c,1d,38,12,8a,de,68, 55,95,ad,1e,00,cd,08,68,12,b3,4d,db,d3 "{C55BBCD6-41AD-48AD-9953-3609C48EACC7}"=hex:51,66,7a,6c,4c,1d,38,12,b8,bf,48, c1,9f,0f,c3,0d,e6,45,75,49,c1,d0,e8,d3 "{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}"=hex:51,66,7a,6c,4c,1d,38,12,ed,e2,e6, 8b,ec,e5,85,03,cf,88,91,ea,bc,02,ef,f7 "{71576546-354D-41C9-AAE8-31F2EC22BF0D}"=hex:51,66,7a,6c,4c,1d,38,12,28,66,44, 75,7f,7b,a7,04,d5,fe,72,b2,e9,7c,fb,19 "{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8, 89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b "{000123B4-9B42-4900-B3F7-F4B073EFC214}"=hex:51,66,7a,6c,4c,1d,38,12,da,20,12, 04,70,d5,6e,0c,cc,e1,b7,f0,76,b1,86,00 "{00C6482D-C502-44C8-8409-FCE54AD9C208}"=hex:51,66,7a,6c,4c,1d,38,12,43,4b,d5, 04,30,8b,a6,01,fb,1f,bf,a5,4f,87,86,1c "{074C1DC5-9320-4A9A-947D-C042949C6216}"=hex:51,66,7a,6c,4c,1d,38,12,ab,1e,5f, 03,12,dd,f4,0f,eb,6b,83,02,91,c2,26,02 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce, 9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d "{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f, aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04 "{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"=hex:51,66,7a,6c,4c,1d,38,12,2d,dd,7a, ab,6a,33,56,03,c9,ec,8d,26,b0,f3,64,49 "{C920E44A-7F78-4E64-BDD7-A57026E7FEB7}"=hex:51,66,7a,6c,4c,1d,38,12,24,e7,33, cd,4a,31,0a,0b,c2,c1,e6,30,23,b9,ba,a3 "{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd, d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84, f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63 "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:ba,20,8f,9c,ab,e0,cd,01 . [HKEY_USERS\S-1-5-21-2704817108-4072845770-1665254088-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B36AE059-1A01-44D6-A7A1-7647FEBDE46E}*cal] @Allowed: (Read) (RestrictedCode) "AppName"="Roblox.exe" "Policy"=dword:00000003 "AppPath"="c:\\Users\\Laurent Effen Rocks\\AppData\\Local\\Roblox\\Versions\\version-09a201d8e5f247c7\\" . [HKEY_USERS\S-1-5-21-2704817108-4072845770-1665254088-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E97D1FF8-24C4-4617-A3FC-37D02D24846F}*cal*o 0] @Allowed: (Read) (RestrictedCode) "AppName"="RobloxApp.exe" "Policy"=dword:00000003 "AppPath"="c:\\Users\\Laurent Effen Rocks\\AppData\\Local\\Roblox\\Versions\\version-09a201d8e5f247c7\\" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version] "Version"=hex:1c,64,a5,36,a8,62,77,4b,6f,be,61,1e,19,a5,81,da,b2,92,81,b0,b7, b0,46,d4,27,69,09,0c,57,da,0b,a4,ca,b5,be,78,c2,23,a6,87,42,59,66,30,b2,e2,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version] "Version"=hex:1c,64,a5,36,a8,62,77,4b,6f,be,61,1e,19,a5,81,da,b2,92,81,b0,b7, b0,46,d4,27,69,09,0c,57,da,0b,a4,ca,b5,be,78,c2,23,a6,87,42,59,66,30,b2,e2,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Swearware\backup\winsock2\Parameters] @DACL=(02 0000) @SACL= "NameSpace_Callout"=expand:"%SystemRoot%\\System32\\fwpuclnt.dll" "WinSock_Registry_Version"="2.0" "AutodialDLL"="rasadhlp.dll" "Current_NameSpace_Catalog"="NameSpace_Catalog5" "Current_Protocol_Catalog"="Protocol_Catalog9" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\\.\globalroot\systemroot\svchost.exe c:\windows\SysWOW64\astsrv.exe c:\program files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe c:\windows\SOUNDMAN.EXE c:\windows\SysWOW64\RunDll32.exe . ************************************************************************** . Completion time: 2012-12-23 13:10:48 - machine was rebooted ComboFix-quarantined-files.txt 2012-12-23 18:10 . Pre-Run: 247,880,822,784 bytes free Post-Run: 247,724,150,784 bytes free . - - End Of File - - 883EC6300029F75AD84A7799EE17F76C

Attachments:

Thanks for letting me know about all of that. :)

Please go to: VirusTotal
On the page you'll find a "Choose File" button.
Click on the Choose File button.
In the Choose File to Upload window which opens, copy and paste this into the File Name box.

C:\Users\Laurent Effen Rocks\AppData\Roaming\inst.exe

Next, click the Open button.
Then click the "Scan It!" button just below.
This will scan the file. Please be patient.
If you get a message saying File has already been analyzed: click Reanalyze file now
Once scanned, copy and paste the link to the results page in your next reply.
———-
Hi Jeff, Sorry I was away for the holiday. I ran your instructions above regarding Virus Total. It did not find the path you had me copy into the filename box. Do you want me to run Combo Fix again?
Hi,

Sorry I was away for the holiday.

No need to apologize. I hope you had a great holiday!! :)

Please download SystemLook from one of the links below and save it to your Desktop.
Link 1
Link 2

  • Right-click and Run as Administrator SystemLook.exe to run it.
  • Copy the content within the following codebox into the main textfield:
    :file
    C:\Users\Laurent Effen Rocks\AppData\Roaming\inst.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hi Jeff, Please see the results of the log below: SystemLook 30.07.11 by jpshortstuff Log created at 00:15 on 27/12/2012 by Laurent Effen Rocks Administrator - Elevation successful ========== file ========== C:\Users\Laurent Effen Rocks\AppData\Roaming\inst.exe - Unable to find/read file. -= EOF =-
Hi Jeff, I though it would be a good idea to run Combo Fix again - just so you can see the log. As a side note - I think one of my antivirus programs may have removed/quarantined the virus (or another virus that may have also been a problem. That is also why I ran Combo Fix again. Please see the copy/paste of the log: ====================================== ComboFix 12-12-26.02 - Laurent Effen Rocks 12/27/2012 0:31.3.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3327.2039 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} AV: Spyware Doctor with AntiVirus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Kensington\TrackballWorks\TbwHelper.exe . . ((((((((((((((((((((((((( Files Created from 2012-11-27 to 2012-12-27 ))))))))))))))))))))))))))))))) . . 2012-12-27 05:42 . 2012-12-27 05:42 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-12-27 05:42 . 2012-12-27 05:42 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-12-27 05:42 . 2012-12-27 05:42 ——– d—–w- c:\users\LogMeInRemoteUser\AppData\Local\temp 2012-12-27 05:42 . 2012-12-27 05:42 ——– d—–w- c:\users\Laurent\AppData\Local\temp 2012-12-27 05:42 . 2012-12-27 05:42 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-12-27 03:05 . 2012-12-27 03:05 208216 —-a-w- c:\windows\system32\drivers\66749434.sys 2012-12-27 02:10 . 2012-12-27 02:10 ——– d—–w- C:\TDSSKiller_Quarantine 2012-12-27 01:59 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C862C626-F99B-4E02-B6A9-C43D7B7F6CF5}\mpengine.dll 2012-12-26 16:25 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-12-22 01:59 . 2012-12-22 01:59 ——– d—–w- c:\windows\Microsoft Antimalware 2012-12-21 16:41 . 2012-08-21 18:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-12-21 16:40 . 2012-12-21 16:40 ——– d—–w- c:\program files\iPod 2012-12-21 16:40 . 2012-12-21 16:41 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-21 16:40 . 2012-12-21 16:41 ——– d—–w- c:\program files\iTunes 2012-12-21 16:40 . 2012-12-21 16:41 ——– d—–w- c:\program files (x86)\iTunes 2012-12-21 16:34 . 2012-12-21 16:34 ——– d—–w- c:\program files\Bonjour 2012-12-21 16:34 . 2012-12-21 16:34 ——– d—–w- c:\program files (x86)\Bonjour 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2012-12-21 16:09 . 2012-12-21 16:09 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2012-12-21 16:09 . 2012-12-21 16:09 ——– d—–w- c:\program files (x86)\QuickTime 2012-12-21 01:16 . 2012-12-16 14:13 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-21 01:16 . 2012-12-16 17:11 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-21 01:16 . 2012-12-16 14:45 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-21 01:16 . 2012-12-16 14:13 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-15 04:05 . 2012-08-23 15:25 3584 —-a-w- c:\windows\system32\drivers\es-ES\tsusbflt.sys.mui 2012-12-15 04:05 . 2012-08-23 15:09 3072 —-a-w- c:\windows\system32\drivers\en-US\tsusbflt.sys.mui 2012-12-15 04:05 . 2012-08-23 13:41 13312 —-a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2012-12-15 04:05 . 2012-08-23 13:40 13312 —-a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2012-12-15 04:05 . 2012-08-23 13:24 15360 —-a-w- c:\windows\system32\RdpGroupPolicyExtension.dll 2012-12-15 04:03 . 2012-08-24 18:13 154480 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-12-15 04:03 . 2012-08-24 18:09 458712 —-a-w- c:\windows\system32\drivers\cng.sys 2012-12-15 04:03 . 2012-08-24 18:05 340992 —-a-w- c:\windows\system32\schannel.dll 2012-12-15 04:03 . 2012-08-24 18:04 307200 —-a-w- c:\windows\system32\ncrypt.dll 2012-12-15 04:03 . 2012-08-24 16:57 247808 —-a-w- c:\windows\SysWow64\schannel.dll 2012-12-15 04:03 . 2012-08-24 18:03 1448448 —-a-w- c:\windows\system32\lsasrv.dll 2012-12-15 04:03 . 2012-08-24 16:57 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2012-12-15 04:03 . 2012-08-24 16:57 220160 —-a-w- c:\windows\SysWow64\ncrypt.dll 2012-12-15 04:03 . 2012-08-24 16:53 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2012-12-15 02:38 . 2012-12-15 05:37 ——– d—–w- c:\users\Laurent Effen Rocks\AppData\Local\LogMeIn Rescue Applet 2012-12-12 11:57 . 2012-11-09 05:45 2048 —-a-w- c:\windows\system32\tzres.dll 2012-12-12 11:57 . 2012-11-09 04:42 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-12-12 11:57 . 2012-11-22 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2012-12-12 11:55 . 2012-11-02 05:59 478208 —-a-w- c:\windows\system32\dpnet.dll 2012-12-12 11:55 . 2012-11-02 05:11 376832 —-a-w- c:\windows\SysWow64\dpnet.dll 2012-11-28 06:35 . 2012-11-28 06:35 972264 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E43FE1A-E0BF-49C2-AEB1-3FDFDA8CAC0F}\gapaengine.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-19 01:52 . 2012-09-09 05:41 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-19 01:52 . 2012-09-09 05:41 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-15 05:09 . 2011-02-07 23:58 82816 —-a-w- c:\users\Laurent Effen Rocks\AppData\Roaming\pcouffin.sys 2012-12-13 08:07 . 2011-02-07 22:58 67413224 —-a-w- c:\windows\system32\MRT.exe 2012-11-06 22:00 . 2011-02-13 21:26 88008 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-11-06 22:00 . 2011-02-13 21:26 35240 —-a-w- c:\windows\system32\LMIport.dll 2012-11-06 22:00 . 2011-02-13 21:26 83880 —-a-w- c:\windows\system32\LMIinit.dll 2012-10-25 08:12 . 2012-10-25 08:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2012-10-25 08:12 . 2012-10-25 08:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts 2012-10-16 08:38 . 2012-11-28 07:49 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-11-28 07:49 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-11-28 07:49 561664 —-a-w- c:\windows\apppatch\AcLayers.dll 2012-10-09 18:17 . 2012-11-14 02:51 55296 —-a-w- c:\windows\system32\dhcpcsvc6.dll 2012-10-09 18:17 . 2012-11-14 02:51 226816 —-a-w- c:\windows\system32\dhcpcore6.dll 2012-10-09 17:40 . 2012-11-14 02:51 44032 —-a-w- c:\windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40 . 2012-11-14 02:51 193536 —-a-w- c:\windows\SysWow64\dhcpcore6.dll 2012-10-04 16:40 . 2012-12-12 11:56 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-10-03 17:56 . 2012-11-14 02:50 1914248 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-10-03 17:44 . 2012-11-14 02:50 303104 —-a-w- c:\windows\system32\nlasvc.dll 2012-10-03 17:44 . 2012-11-14 02:50 70656 —-a-w- c:\windows\system32\nlaapi.dll 2012-10-03 17:44 . 2012-11-14 02:50 246272 —-a-w- c:\windows\system32\netcorehc.dll 2012-10-03 17:44 . 2012-11-14 02:50 18944 —-a-w- c:\windows\system32\netevent.dll 2012-10-03 17:44 . 2012-11-14 02:50 216576 —-a-w- c:\windows\system32\ncsi.dll 2012-10-03 17:42 . 2012-11-14 02:50 569344 —-a-w- c:\windows\system32\iphlpsvc.dll 2012-10-03 16:42 . 2012-11-14 02:50 175104 —-a-w- c:\windows\SysWow64\netcorehc.dll 2012-10-03 16:42 . 2012-11-14 02:50 18944 —-a-w- c:\windows\SysWow64\netevent.dll 2012-10-03 16:42 . 2012-11-14 02:50 156672 —-a-w- c:\windows\SysWow64\ncsi.dll 2012-10-03 16:07 . 2012-11-14 02:50 45568 —-a-w- c:\windows\system32\drivers\tcpipreg.sys 2012-10-02 06:00 . 2011-03-25 06:44 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-09-28 15:32 . 2012-09-28 15:32 5989776 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-09-28 15:32 . 2012-09-28 15:32 53760 —-a-w- c:\windows\system32\drivers\usbaapl64.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Kensington TrackballWorks"="c:\program files (x86)\Kensington\TrackballWorks\TbwHelper.exe" [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-01-31 38840] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304] "Kensington TrackballWorks Helper"="c:\program files (x86)\Kensington\TrackballWorks\TbwHelper.exe" [BU] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-11-30 1120032] HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016] R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2009-11-30 319016] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-11-18 39464] R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-07-29 16776] R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-07-29 9096] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-02-14 1038088] R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-01 33736] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928] R3 lvpepf64;Volume Adapter;c:\windows\system32\DRIVERS\lv302a64.sys [2009-04-30 15896] R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2009-04-30 327576] R3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\DRIVERS\LVUSBS64.sys [2008-07-26 50072] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896] R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2011-02-07 82816] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2010-03-15 366840] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-07 1255736] R4 VRAID Log Service;VRAID Log Service;c:\program files (x86)\VIA\RAID\vialogsv.exe [2008-09-24 52888] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys [2012-01-25 133728] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [2010-11-25 257232] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [2010-06-29 452872] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [2010-07-16 816016] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-02-06 54480] S0 vidsflt61;Acronis Disk Storage Filter (61);c:\windows\system32\DRIVERS\vsflt61.sys [2012-01-25 142944] S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-11-06 375728] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-09-17 15928] S2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-03-29 598312] S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-03-31 80896] S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408] S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232] S3 nvoclk64;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\DRIVERS\nvoclk64.sys [2009-09-15 42088] S3 tbwkern;Kensington TrackballWorks driver;c:\windows\system32\DRIVERS\tbwkern.sys [2011-06-13 32848] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-12-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-09 01:52] . 2012-11-25 c:\windows\Tasks\AVSRegistryCleaner.job - c:\program files (x86)\AVS4YOU\AVSRegistryCleaner\AVSRegistryCleaner.exe [2011-08-31 18:15] . 2012-12-26 c:\windows\Tasks\Google Software Updater.job - c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-13 02:32] . 2012-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-21 01:08] . 2012-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-21 01:08] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704] "RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: &Download by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/201 IE: &Grab video by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/204 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Do&wnload selected by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/202 IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.2.1 DPF: {7206EAAC-5CFA-43A3-9F61-E27E8E51E42F} - hxxp://adus1.liveblockauctions.com/container_repository/laiexec.cab DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://imageupload9.autorevo.com/Cabs/ImageUploader6.cab FF - ProfilePath - c:\users\Laurent Effen Rocks\AppData\Roaming\Mozilla\Firefox\Profiles\mkcyav34.default\ FF - prefs.js: browser.startup.homepage - google.com . - - - - ORPHANS REMOVED - - - - . SafeBoot-02533126.sys . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90, 43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87 "{517BDDE4-E3A7-4570-B21E-2B52B6139FC7}"=hex:51,66,7a,6c,4c,1d,38,12,8a,de,68, 55,95,ad,1e,00,cd,08,68,12,b3,4d,db,d3 "{C55BBCD6-41AD-48AD-9953-3609C48EACC7}"=hex:51,66,7a,6c,4c,1d,38,12,b8,bf,48, c1,9f,0f,c3,0d,e6,45,75,49,c1,d0,e8,d3 "{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}"=hex:51,66,7a,6c,4c,1d,38,12,ed,e2,e6, 8b,ec,e5,85,03,cf,88,91,ea,bc,02,ef,f7 "{71576546-354D-41C9-AAE8-31F2EC22BF0D}"=hex:51,66,7a,6c,4c,1d,38,12,28,66,44, 75,7f,7b,a7,04,d5,fe,72,b2,e9,7c,fb,19 "{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8, 89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b "{000123B4-9B42-4900-B3F7-F4B073EFC214}"=hex:51,66,7a,6c,4c,1d,38,12,da,20,12, 04,70,d5,6e,0c,cc,e1,b7,f0,76,b1,86,00 "{00C6482D-C502-44C8-8409-FCE54AD9C208}"=hex:51,66,7a,6c,4c,1d,38,12,43,4b,d5, 04,30,8b,a6,01,fb,1f,bf,a5,4f,87,86,1c "{074C1DC5-9320-4A9A-947D-C042949C6216}"=hex:51,66,7a,6c,4c,1d,38,12,ab,1e,5f, 03,12,dd,f4,0f,eb,6b,83,02,91,c2,26,02 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce, 9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d "{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f, aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04 "{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"=hex:51,66,7a,6c,4c,1d,38,12,2d,dd,7a, ab,6a,33,56,03,c9,ec,8d,26,b0,f3,64,49 "{C920E44A-7F78-4E64-BDD7-A57026E7FEB7}"=hex:51,66,7a,6c,4c,1d,38,12,24,e7,33, cd,4a,31,0a,0b,c2,c1,e6,30,23,b9,ba,a3 "{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd, d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84, f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63 "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:ba,20,8f,9c,ab,e0,cd,01 . [HKEY_USERS\S-1-5-21-2704817108-4072845770-1665254088-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B36AE059-1A01-44D6-A7A1-7647FEBDE46E}*cal] @Allowed: (Read) (RestrictedCode) "AppName"="Roblox.exe" "Policy"=dword:00000003 "AppPath"="c:\\Users\\Laurent Effen Rocks\\AppData\\Local\\Roblox\\Versions\\version-09a201d8e5f247c7\\" . [HKEY_USERS\S-1-5-21-2704817108-4072845770-1665254088-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E97D1FF8-24C4-4617-A3FC-37D02D24846F}*cal*o 0] @Allowed: (Read) (RestrictedCode) "AppName"="RobloxApp.exe" "Policy"=dword:00000003 "AppPath"="c:\\Users\\Laurent Effen Rocks\\AppData\\Local\\Roblox\\Versions\\version-09a201d8e5f247c7\\" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version] "Version"=hex:1c,64,a5,36,a8,62,77,4b,6f,be,61,1e,19,a5,81,da,b2,92,81,b0,b7, b0,46,d4,27,69,09,0c,57,da,0b,a4,ca,b5,be,78,c2,23,a6,87,42,59,66,30,b2,e2,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version] "Version"=hex:1c,64,a5,36,a8,62,77,4b,6f,be,61,1e,19,a5,81,da,b2,92,81,b0,b7, b0,46,d4,27,69,09,0c,57,da,0b,a4,ca,b5,be,78,c2,23,a6,87,42,59,66,30,b2,e2,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Swearware\backup\winsock2\Parameters] @DACL=(02 0000) @SACL= "NameSpace_Callout"=expand:"%SystemRoot%\\System32\\fwpuclnt.dll" "WinSock_Registry_Version"="2.0" "AutodialDLL"="rasadhlp.dll" "Current_NameSpace_Catalog"="NameSpace_Catalog5" "Current_Protocol_Catalog"="Protocol_Catalog9" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-12-27 00:46:08 ComboFix-quarantined-files.txt 2012-12-27 05:46 ComboFix2.txt 2012-12-23 18:10 . Pre-Run: 248,361,115,648 bytes free Post-Run: 247,875,346,432 bytes free . - - End Of File - - 08448EC02F9E716E56ACEE85F498F3C9
I notice that you have both Microsoft Security Essentials and Spyware Doctor with AntiVirus running at the same time. Having more than one antivirus program running at the same time can seriously degrade the performance of your system. Please uninstall either Microsoft Security Essentials or Spyware Doctor with AntiVirus (which ever you prefer) using either the provided uninstall feature that is part of the antivirus program or through Add/Remove Programs (for Vista and Win 7 users to go to Programs and Features in the Control Panel). As a rule of thumb one should run one firewall, one antivirus program in memory, and one antispyware utility in memory. It's fine to have other security tools available on an as-needed or on-demand basis, but when multiple tools simultaneously perform the same function, you're asking for trouble.
———

Reboot your system and then let me know how your system is running now. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI